CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9441
6.5 MEDIUM

The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all versions up to, and including, 1.2 …

Aug 29, 2025
CVE-2025-9374
4.3 MEDIUM

The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due …

Aug 29, 2025
CVE-2025-8619
6.4 MEDIUM

The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map Block URL in all versions up …

Aug 29, 2025
CVE-2025-8290
6.4 MEDIUM

The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.0.6 due …

Aug 29, 2025
CVE-2025-8147
4.3 MEDIUM

The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscache_activatePlugin() function in all versions up to, …

Aug 29, 2025
CVE-2025-53507
6.5 MEDIUM

Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration information, such as admin password, may be disclosed. …

Aug 29, 2025
CVE-2025-9619
5.3 MEDIUM

A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of the file /basico/webservice/imprimir-danfe/id/. Performing manipulation …

Aug 29, 2025
CVE-2025-9609
6.3 MEDIUM

A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulation results in improper authorization. …

Aug 29, 2025
CVE-2025-9608
6.3 MEDIUM

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/view of the component Formula de …

Aug 29, 2025
CVE-2025-9607
6.3 MEDIUM

A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/TabelaArredondamento/view of the …

Aug 29, 2025
CVE-2025-9606
6.3 MEDIUM

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing manipulation of …

Aug 29, 2025
CVE-2025-39246
5.3 MEDIUM

There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via …

Aug 29, 2025
CVE-2025-39245
4.7 MEDIUM

There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.

Aug 29, 2025
CVE-2025-9603
6.3 MEDIUM

A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname …

Aug 29, 2025
CVE-2025-9602
6.3 MEDIUM

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. …

Aug 29, 2025
CVE-2025-54142
4.0 MEDIUM

Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within …

Aug 29, 2025
CVE-2025-43284
5.5 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app …

Aug 29, 2025
CVE-2024-54568
4.3 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may lead to an …

Aug 29, 2025
CVE-2024-54554
5.5 MEDIUM

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive …

Aug 29, 2025
CVE-2025-9595
4.3 MEDIUM

A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of …

Aug 29, 2025
CVE-2025-58061
5.5 MEDIUM

OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, persistent volume data is world …

Aug 28, 2025
CVE-2025-58058
5.3 MEDIUM

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of …

Aug 28, 2025
CVE-2025-9586
6.3 MEDIUM

A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads …

Aug 28, 2025
CVE-2025-9585
6.3 MEDIUM

A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of the argument portal_delete_picname causes command …

Aug 28, 2025
CVE-2025-9584
6.3 MEDIUM

A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of the argument …

Aug 28, 2025
CVE-2025-9583
6.3 MEDIUM

A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to …

Aug 28, 2025
CVE-2025-9582
6.3 MEDIUM

A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can …

Aug 28, 2025
CVE-2025-9581
6.3 MEDIUM

A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in …

Aug 28, 2025
CVE-2025-9580
6.3 MEDIUM

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such …

Aug 28, 2025
CVE-2025-9579
6.3 MEDIUM

A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the component HTTP Handler. …

Aug 28, 2025
CVE-2025-57220
5.3 MEDIUM

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.

Aug 28, 2025
CVE-2025-57219
5.3 MEDIUM

Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted …

Aug 28, 2025
CVE-2025-9575
6.3 MEDIUM

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing …

Aug 28, 2025
CVE-2025-9195
4.4 MEDIUM

Improper input validation in firmware of some Solidigm DC Products may allow an attacker with local access to cause a Denial of Service

Aug 28, 2025
CVE-2025-58049
5.8 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 …

Aug 28, 2025
CVE-2025-57218
5.3 MEDIUM

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C.

Aug 28, 2025
CVE-2025-57217
5.3 MEDIUM

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter in the function R7WebsSecurityHandler.

Aug 28, 2025
CVE-2025-31971
5.1 MEDIUM

AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability. The issue may allow attackers to launch a server-side request forgery (SSRF) attack …

Aug 28, 2025
CVE-2025-58335
5.5 MEDIUM

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function

Aug 28, 2025
CVE-2025-57759
4.3 MEDIUM

Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be …

Aug 28, 2025
CVE-2025-57758
4.3 MEDIUM

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end …

Aug 28, 2025
CVE-2025-57757
5.3 MEDIUM

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, …

Aug 28, 2025
CVE-2025-57756
5.3 MEDIUM

Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as …

Aug 28, 2025
CVE-2025-31979
5.4 MEDIUM

A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during …

Aug 28, 2025
CVE-2025-31977
5.3 MEDIUM

HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms. An attacker with network access could exploit this weakness to …

Aug 28, 2025
CVE-2025-31972
6.5 MEDIUM

HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized …

Aug 28, 2025
CVE-2025-29364
6.5 MEDIUM

spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in the READ_SYSCALL and WRITE_SYSCALL system calls. The application verifies the legitimacy of the starting …

Aug 28, 2025
CVE-2025-25010
6.5 MEDIUM

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.

Aug 28, 2025
CVE-2025-56236
6.1 MEDIUM

FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are …

Aug 28, 2025
CVE-2025-54995
6.5 MEDIUM

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak …

Aug 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.