CVE Database

58263+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10774
4.7 MEDIUM

A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view/vpn/autovpn/sub_commit.php. This manipulation of the argument …

Sep 22, 2025
CVE-2025-10772
6.3 MEDIUM

A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown functionality of the file lerobot/common/robot_devices/robots/lekiwi_remote.py of the component …

Sep 22, 2025
CVE-2025-10771
6.3 MEDIUM

A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. …

Sep 21, 2025
CVE-2025-10770
6.3 MEDIUM

A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. …

Sep 21, 2025
CVE-2025-10767
4.5 MEDIUM

A vulnerability was detected in CosmodiumCS OnlyRAT up to 3.2. The affected element is the function connect/remote_upload/remote_download of the file main.py of the component Configuration …

Sep 21, 2025
CVE-2025-10769
6.3 MEDIUM

A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC …

Sep 21, 2025
CVE-2025-10768
6.3 MEDIUM

A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component …

Sep 21, 2025
CVE-2025-10766
4.3 MEDIUM

A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file EventViewerController.cs. Executing manipulation of the …

Sep 21, 2025
CVE-2025-10765
4.7 MEDIUM

A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Suggestions in the library cms-v4.3\wwwroot\Plugins\ZKEACMS.SEOSuggestions\ZKEACMS.SEOSuggestions.dll of the component …

Sep 21, 2025
CVE-2025-10764
6.3 MEDIUM

A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the component Event Action System. …

Sep 21, 2025
CVE-2025-10763
6.3 MEDIUM

A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by this issue is some unknown functionality of the file /edit-photo of the component …

Sep 21, 2025
CVE-2025-10762
6.3 MEDIUM

A vulnerability was found in kuaifan DooTask up to 1.2.49. Affected by this vulnerability is an unknown functionality of the file app/Http/Controllers/Api/UsersController.php. The manipulation of …

Sep 21, 2025
CVE-2025-10760
6.3 MEDIUM

A flaw has been found in Harness 3.3.0. This impacts the function LookupRepo of the file app/api/controller/gitspace/lookup_repo.go. Executing manipulation of the argument url can lead …

Sep 21, 2025
CVE-2025-10759
5.3 MEDIUM

A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the …

Sep 21, 2025
CVE-2025-10755
6.3 MEDIUM

A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component Content-Type Handler. The manipulation of the argument …

Sep 20, 2025
CVE-2025-10741
6.3 MEDIUM

A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile Picture Handler. …

Sep 20, 2025
CVE-2025-9887
4.3 MEDIUM

The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is …

Sep 20, 2025
CVE-2025-9883
6.1 MEDIUM

The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing …

Sep 20, 2025
CVE-2025-9882
6.1 MEDIUM

The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to …

Sep 20, 2025
CVE-2025-10658
6.5 MEDIUM

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. …

Sep 20, 2025
CVE-2025-9949
4.3 MEDIUM

The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to …

Sep 20, 2025
CVE-2025-10489
4.3 MEDIUM

The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of …

Sep 20, 2025
CVE-2025-10305
5.3 MEDIUM

The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_passkey() and passkeys_list() function in all …

Sep 20, 2025
CVE-2025-10181
6.4 MEDIUM

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6 …

Sep 20, 2025
CVE-2025-10002
4.9 MEDIUM

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via …

Sep 20, 2025
CVE-2025-10652
6.5 MEDIUM

The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore-netatmo shortcode in all versions up to, and …

Sep 20, 2025
CVE-2025-43808
5.3 MEDIUM

The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 …

Sep 19, 2025
CVE-2025-59689
6.1 MEDIUM KEV

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. …

Sep 19, 2025
CVE-2025-57396
6.5 MEDIUM

Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User …

Sep 19, 2025
CVE-2025-56762
6.1 MEDIUM

Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.

Sep 19, 2025
CVE-2025-43809
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 …

Sep 19, 2025
CVE-2025-43803
4.3 MEDIUM

Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2023.Q4.0 …

Sep 19, 2025
CVE-2025-26517
5.4 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege escalation vulnerability. Successful exploit could allow an unauthorized authenticated attacker …

Sep 19, 2025
CVE-2025-26516
5.3 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker …

Sep 19, 2025
CVE-2025-26514
6.4 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to …

Sep 19, 2025
CVE-2025-10722
5.3 MEDIUM

A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The …

Sep 19, 2025
CVE-2025-10721
5.3 MEDIUM

A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation causes …

Sep 19, 2025
CVE-2025-36248
6.1 MEDIUM

IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI …

Sep 19, 2025
CVE-2025-57296
6.5 MEDIUM

Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the …

Sep 19, 2025
CVE-2025-56869
5.3 MEDIUM

Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in …

Sep 19, 2025
CVE-2025-55910
6.3 MEDIUM

CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php.

Sep 19, 2025
CVE-2025-39865
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tee: fix NULL pointer dereference in tee_shm_put tee_shm_put have NULL pointer dereference: __optee_disable_shm_cache --> shm …

Sep 19, 2025
CVE-2025-39858
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eth: mlx4: Fix IS_ERR() vs NULL check bug in mlx4_en_create_rx_ring Replace NULL check with IS_ERR() …

Sep 19, 2025
CVE-2025-39857
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() BUG: kernel NULL pointer dereference, address: 00000000000002ec …

Sep 19, 2025
CVE-2025-39856
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix null pointer dereference for ndev In the TX completion packet …

Sep 19, 2025
CVE-2025-39852
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/tcp: Fix socket memory leak in TCP-AO failure handling for IPv6 When tcp_ao_copy_all_matching() fails in …

Sep 19, 2025
CVE-2025-39851
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix NPD when refreshing an FDB entry with a nexthop object VXLAN FDB entries …

Sep 19, 2025
CVE-2025-39850
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects When the "proxy" option is enabled …

Sep 19, 2025
CVE-2025-39848
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ax25: properly unshare skbs in ax25_kiss_rcv() Bernard Pidoux reported a regression apparently caused by commit …

Sep 19, 2025
CVE-2025-39847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ppp: fix memory leak in pad_compress_skb If alloc_skb() fails in pad_compress_skb(), it returns NULL without …

Sep 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.