CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20295
6.0 MEDIUM

A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to read or create a file …

Aug 27, 2025
CVE-2025-20294
6.5 MEDIUM

Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with administrative privileges to perform …

Aug 27, 2025
CVE-2025-20292
4.4 MEDIUM

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command injection attack on the underlying operating …

Aug 27, 2025
CVE-2025-20290
5.5 MEDIUM

A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, …

Aug 27, 2025
CVE-2025-20262
5.0 MEDIUM

A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone …

Aug 27, 2025
CVE-2025-54598
6.5 MEDIUM

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.

Aug 27, 2025
CVE-2025-50984
5.3 MEDIUM

diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsanitized user input in POST parameters such …

Aug 27, 2025
CVE-2025-50978
6.1 MEDIUM

In Gitblit v1.7.1, a reflected cross-site scripting (XSS) vulnerability exists in the way repository path names are handled. By injecting a specially crafted path payload …

Aug 27, 2025
CVE-2025-50986
5.6 MEDIUM

diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields such as ES_HOST, ES_INDEXREFRESH, ES_PORT, …

Aug 27, 2025
CVE-2025-50985
5.6 MEDIUM

diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, …

Aug 27, 2025
CVE-2025-9532
6.3 MEDIUM

A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/view. Executing manipulation of the argument …

Aug 27, 2025
CVE-2025-9531
6.3 MEDIUM

A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Module. Performing …

Aug 27, 2025
CVE-2025-9528
4.7 MEDIUM

A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can …

Aug 27, 2025
CVE-2025-56694
5.8 MEDIUM

Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to view password-protected photo albums.

Aug 27, 2025
CVE-2021-4459
6.5 MEDIUM

An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.

Aug 27, 2025
CVE-2025-48081
5.3 MEDIUM

Path Traversal: '.../...//' vulnerability in Printeers Printeers Print & Ship allows Path Traversal.This issue affects Printeers Print & Ship: from n/a through 1.17.0.

Aug 27, 2025
CVE-2025-49040
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery.This issue affects Backup Bolt: from n/a through <= 1.5.0.

Aug 27, 2025
CVE-2025-49039
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View link-view allows Stored XSS.This issue affects Link View: from n/a …

Aug 27, 2025
CVE-2025-49035
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin Menu Groups admin-menu-groups allows Stored XSS.This issue affects Admin Menu Groups: …

Aug 27, 2025
CVE-2025-7732
6.4 MEDIUM

The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers in all versions up to, and including, …

Aug 27, 2025
CVE-2025-8490
4.4 MEDIUM

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, …

Aug 27, 2025
CVE-2025-9277
6.4 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_replace expression in all versions up to, and …

Aug 26, 2025
CVE-2025-35113
5.9 MEDIUM

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by …

Aug 26, 2025
CVE-2025-35112
4.1 MEDIUM

Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and …

Aug 26, 2025
CVE-2025-26417
4.0 MEDIUM

In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could …

Aug 26, 2025
CVE-2025-22413
4.0 MEDIUM

In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local information …

Aug 26, 2025
CVE-2025-22407
5.5 MEDIUM

In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local information …

Aug 26, 2025
CVE-2025-0092
6.5 MEDIUM

In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with …

Aug 26, 2025
CVE-2025-0086
6.2 MEDIUM

In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to local information …

Aug 26, 2025
CVE-2025-0083
4.0 MEDIUM

In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information …

Aug 26, 2025
CVE-2025-0082
5.5 MEDIUM

In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confused deputy. This could lead …

Aug 26, 2025
CVE-2024-49740
5.5 MEDIUM

In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution …

Aug 26, 2025
CVE-2024-47192
5.3 MEDIUM

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that …

Aug 26, 2025
CVE-2024-35203
6.1 MEDIUM

Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via …

Aug 26, 2025
CVE-2025-50975
5.4 MEDIUM

IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr, allowing …

Aug 26, 2025
CVE-2025-57818
6.3 MEDIUM

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to version 2.0.1, a server-side request forgery (SSRF) vulnerability was discovered in Firecrawl's webhook …

Aug 26, 2025
CVE-2025-50976
6.1 MEDIUM

IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query parameters, resulting in a reflected cross-site …

Aug 26, 2025
CVE-2025-57425
6.1 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated attacker to inject malicious JavaScript into the 'question' and 'answer' …

Aug 26, 2025
CVE-2025-52184
6.1 MEDIUM

Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion.

Aug 26, 2025
CVE-2025-50974
6.5 MEDIUM

The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell command. An unauthenticated …

Aug 26, 2025
CVE-2025-1494
6.1 MEDIUM

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to …

Aug 26, 2025
CVE-2025-57813
5.9 MEDIUM

traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, such as OAuth tokens, …

Aug 26, 2025
CVE-2025-56432
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in …

Aug 26, 2025
CVE-2025-52219
6.5 MEDIUM

SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arbitrary external links via HTML …

Aug 26, 2025
CVE-2025-52217
5.4 MEDIUM

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.

Aug 26, 2025
CVE-2025-52037
6.1 MEDIUM

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=sites. The manipulation of the title of …

Aug 26, 2025
CVE-2025-52036
6.1 MEDIUM

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=categories. The manipulation of the title of …

Aug 26, 2025
CVE-2025-52035
6.1 MEDIUM

A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. …

Aug 26, 2025
CVE-2025-25737
6.8 MEDIUM

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User …

Aug 26, 2025
CVE-2025-25736
6.8 MEDIUM

Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-installed (/mnt/c3platpersistent/opt/platform-tools/adb) and enabled by default, allowing unauthenticated …

Aug 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.