CVE Database

58263+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11080
4.3 MEDIUM

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamInfoController.java. Such manipulation of …

Sep 27, 2025
CVE-2025-11079
5.3 MEDIUM

A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation results in file …

Sep 27, 2025
CVE-2025-11078
6.3 MEDIUM

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/controller.php?action=photos. The manipulation …

Sep 27, 2025
CVE-2025-11073
4.7 MEDIUM

A vulnerability was detected in Keyfactor RG-EW5100BE EW_3.0B11P280_EW5100BE-PRO_12183019. The affected element is an unknown function of the file /cgi-bin/luci/api/cmd of the component HTTP POST Request …

Sep 27, 2025
CVE-2025-11071
4.7 MEDIUM

A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_cron.php of the component Cron Task Management Module. …

Sep 27, 2025
CVE-2025-11056
6.3 MEDIUM

A flaw has been found in ProjectsAndPrograms School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file owner_panel/fetch-data/select-students.php. This manipulation …

Sep 27, 2025
CVE-2025-11054
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/category/index.php?view=edit. The manipulation of …

Sep 27, 2025
CVE-2025-9944
4.3 MEDIUM

The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to …

Sep 27, 2025
CVE-2025-9899
6.1 MEDIUM

The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Sep 27, 2025
CVE-2025-9898
4.3 MEDIUM

The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. …

Sep 27, 2025
CVE-2025-9896
4.3 MEDIUM

The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.8. This is due to missing or …

Sep 27, 2025
CVE-2025-9894
4.3 MEDIUM

The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing …

Sep 27, 2025
CVE-2025-9893
4.3 MEDIUM

The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due …

Sep 27, 2025
CVE-2025-11051
4.3 MEDIUM

A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The …

Sep 27, 2025
CVE-2025-11050
6.3 MEDIUM

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lead to …

Sep 27, 2025
CVE-2025-10954
5.3 MEDIUM

Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause …

Sep 27, 2025
CVE-2025-11049
6.3 MEDIUM

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /unificacao-aluno. Performing manipulation results …

Sep 27, 2025
CVE-2025-10499
4.3 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Sep 27, 2025
CVE-2025-10498
4.3 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, …

Sep 27, 2025
CVE-2025-8440
6.4 MEDIUM

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in all versions up to, and …

Sep 27, 2025
CVE-2025-36239
6.1 MEDIUM

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the …

Sep 27, 2025
CVE-2024-43192
6.5 MEDIUM

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Sep 27, 2025
CVE-2025-59938
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from 3.8.0 to before 4.11.0, wazuh-analysisd is …

Sep 27, 2025
CVE-2025-11048
6.3 MEDIUM

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such …

Sep 26, 2025
CVE-2025-11047
6.3 MEDIUM

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument …

Sep 26, 2025
CVE-2025-57692
6.8 MEDIUM

PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another …

Sep 26, 2025
CVE-2025-11041
6.3 MEDIUM

A vulnerability has been found in itsourcecode Open Source Job Portal 1.0. Affected by this issue is some unknown functionality of the file /admin/user/index.php?view=edit. The …

Sep 26, 2025
CVE-2025-11038
6.3 MEDIUM

A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of the file /details.php?action=post. Executing manipulation of the …

Sep 26, 2025
CVE-2025-11035
6.3 MEDIUM

A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity …

Sep 26, 2025
CVE-2025-11034
4.3 MEDIUM

A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element is the function downloadImpTemplet of the file /common/dep/common_dep.action.jsp. The …

Sep 26, 2025
CVE-2025-26258
6.1 MEDIUM

Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.'

Sep 26, 2025
CVE-2025-11031
5.3 MEDIUM

A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/resources/examples.php. This manipulation of the …

Sep 26, 2025
CVE-2025-11029
4.3 MEDIUM

A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site request forgery. The …

Sep 26, 2025
CVE-2025-59843
5.3 MEDIUM

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its …

Sep 26, 2025
CVE-2025-59842
4.3 MEDIUM

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters …

Sep 26, 2025
CVE-2025-59362
4.0 MEDIUM

Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.

Sep 26, 2025
CVE-2025-56463
6.8 MEDIUM

Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.

Sep 26, 2025
CVE-2025-11028
5.3 MEDIUM

A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image Handler. Performing manipulation results …

Sep 26, 2025
CVE-2025-6396
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz Website Design Website Software allows Cross-Site Scripting (XSS).This issue affects …

Sep 26, 2025
CVE-2025-57292
6.1 MEDIUM

Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize …

Sep 26, 2025
CVE-2025-11018
5.3 MEDIUM

A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of the file /sysRole/index.do/../../generalReport/download.do;usrlogout.do.do. Executing manipulation of the …

Sep 26, 2025
CVE-2025-11016
4.3 MEDIUM

A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileOut of the file app/controller/explorer/index.class.php. Such manipulation …

Sep 26, 2025
CVE-2025-11015
5.3 MEDIUM

A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp. This manipulation causes mismatched memory …

Sep 26, 2025
CVE-2025-11060
5.7 MEDIUM

A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records …

Sep 26, 2025
CVE-2025-11025
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data.This issue …

Sep 26, 2025
CVE-2025-11014
5.3 MEDIUM

A security flaw has been discovered in OGRECave Ogre up to 14.4.1. This issue affects the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp of the component …

Sep 26, 2025
CVE-2025-11012
5.3 MEDIUM

A vulnerability was determined in BehaviorTree up to 4.7.0. This affects the function ParseScript of the file /src/script_parser.cpp of the component Diagnostic Message Handler. Executing …

Sep 26, 2025
CVE-2025-11010
5.3 MEDIUM

A vulnerability has been found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_include_common of the file /src/ucl_util.c. Such manipulation …

Sep 26, 2025
CVE-2025-11042
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an …

Sep 26, 2025
CVE-2025-7691
6.5 MEDIUM

A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior …

Sep 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.