CVE Database

58263+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-57351
6.5 MEDIUM

A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation of user-provided keys in the assign function allows attackers …

Sep 24, 2025
CVE-2025-57348
6.5 MEDIUM

The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties …

Sep 24, 2025
CVE-2025-55178
5.3 MEDIUM

Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.

Sep 24, 2025
CVE-2025-59524
6.1 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in the …

Sep 24, 2025
CVE-2025-57354
6.5 MEDIUM

A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user-controlled input in translation key processing. The affected …

Sep 24, 2025
CVE-2025-57353
5.3 MEDIUM

The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the …

Sep 24, 2025
CVE-2025-57352
5.3 MEDIUM

A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious …

Sep 24, 2025
CVE-2025-48867
4.8 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin …

Sep 24, 2025
CVE-2025-20338
6.0 MEDIUM

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root …

Sep 24, 2025
CVE-2025-20316
5.3 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an …

Sep 24, 2025
CVE-2025-20314
6.7 MEDIUM

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an …

Sep 24, 2025
CVE-2025-20313
6.7 MEDIUM

Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to …

Sep 24, 2025
CVE-2025-20293
5.3 MEDIUM

A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an …

Sep 24, 2025
CVE-2025-20240
6.1 MEDIUM

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack …

Sep 24, 2025
CVE-2025-20149
6.5 MEDIUM

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device …

Sep 24, 2025
CVE-2025-20365
4.3 MEDIUM

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 …

Sep 24, 2025
CVE-2025-20364
4.3 MEDIUM

A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless …

Sep 24, 2025
CVE-2025-20339
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass …

Sep 24, 2025
CVE-2025-27036
6.1 MEDIUM

Information disclosure when Video engine escape input data is less than expected minimum size.

Sep 24, 2025
CVE-2025-27033
6.1 MEDIUM

Information disclosure while running video usecase having rogue firmware.

Sep 24, 2025
CVE-2025-27030
6.1 MEDIUM

information disclosure while invoking calibration data from user space to update firmware size.

Sep 24, 2025
CVE-2025-23275
4.2 MEDIUM

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain …

Sep 24, 2025
CVE-2025-23274
4.5 MEDIUM

NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted input image with dimensions …

Sep 24, 2025
CVE-2025-23272
5.7 MEDIUM

NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially crafted JPEG file. A successful exploit …

Sep 24, 2025
CVE-2025-9353
6.4 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to …

Sep 24, 2025
CVE-2025-60020
6.4 MEDIUM

nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.

Sep 24, 2025
CVE-2025-39890
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_ready_ext_event Currently, in ath12k_service_ready_ext_event(), svc_rdy_ext.mac_phy_caps is not freed in …

Sep 24, 2025
CVE-2024-58241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregister_dev This make use of disable_work_* on hci_unregister_dev since the …

Sep 24, 2025
CVE-2025-58457
4.3 MEDIUM

Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 …

Sep 24, 2025
CVE-2025-9031
4.3 MEDIUM

Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing.This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.

Sep 24, 2025
CVE-2025-41716
5.3 MEDIUM

The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical …

Sep 24, 2025
CVE-2025-48459
5.3 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, …

Sep 24, 2025
CVE-2025-43819
6.5 MEDIUM

A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and …

Sep 24, 2025
CVE-2025-43779
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 …

Sep 24, 2025
CVE-2025-58473
5.9 MEDIUM

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated …

Sep 23, 2025
CVE-2025-57882
5.9 MEDIUM

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated …

Sep 23, 2025
CVE-2025-55038
6.8 MEDIUM

An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC …

Sep 23, 2025
CVE-2025-58069
5.3 MEDIUM

The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that …

Sep 23, 2025
CVE-2025-54855
4.2 MEDIUM

Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to …

Sep 23, 2025
CVE-2024-21935
5.0 MEDIUM

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local …

Sep 23, 2025
CVE-2024-21927
5.0 MEDIUM

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing …

Sep 23, 2025
CVE-2025-56311
6.5 MEDIUM

In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF vulnerability on the reboot endpoint (/boaform/admin/formReboot). An attacker can …

Sep 23, 2025
CVE-2025-57636
6.5 MEDIUM

OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP parameter "time".

Sep 23, 2025
CVE-2025-58674
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue …

Sep 23, 2025
CVE-2025-56146
5.3 MEDIUM

Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.

Sep 23, 2025
CVE-2025-54081
6.7 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If …

Sep 23, 2025
CVE-2025-45326
6.5 MEDIUM

An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.

Sep 23, 2025
CVE-2025-59821
6.5 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNN’s URL/path handling and template rendering …

Sep 23, 2025
CVE-2025-59548
6.1 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, specially crafted URLs to the FileBrowser …

Sep 23, 2025
CVE-2025-59547
5.3 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has …

Sep 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.