CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64725
9.8 CRITICAL

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version …

Dec 15, 2025
CVE-2025-59947
9.0 CRITICAL

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both …

Dec 15, 2025
CVE-2025-55895
9.1 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).

Dec 15, 2025
CVE-2023-53877
9.8 CRITICAL

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, …

Dec 15, 2025
CVE-2023-53874
9.8 CRITICAL

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite …

Dec 15, 2025
CVE-2023-53871
9.8 CRITICAL

Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. Attackers can exploit …

Dec 15, 2025
CVE-2025-65213
9.8 CRITICAL

MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_single_op() and nan_inf_track_for_single_op() functions use pickle.load() on user-controlled file paths without validation, …

Dec 15, 2025
CVE-2025-66844
9.1 CRITICAL

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration …

Dec 15, 2025
CVE-2025-13888
9.1 CRITICAL

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in …

Dec 15, 2025
CVE-2025-14156
9.8 CRITICAL

The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is …

Dec 15, 2025
CVE-2025-14709
9.8 CRITICAL

A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the …

Dec 15, 2025
CVE-2025-14708
9.8 CRITICAL

A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component …

Dec 15, 2025
CVE-2025-14707
9.8 CRITICAL

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. …

Dec 15, 2025
CVE-2025-14706
9.8 CRITICAL

A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the component NETREBOOT Interface. Such manipulation …

Dec 15, 2025
CVE-2025-14705
9.8 CRITICAL

A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulation of the argument params …

Dec 15, 2025
CVE-2025-14665
9.8 CRITICAL

A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. …

Dec 14, 2025
CVE-2025-36753
9.8 CRITICAL

The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and …

Dec 13, 2025
CVE-2025-36752
9.8 CRITICAL

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker …

Dec 13, 2025
CVE-2025-36747
9.8 CRITICAL

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the …

Dec 13, 2025
CVE-2025-14440
9.8 CRITICAL

The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect …

Dec 13, 2025
CVE-2025-11693
9.8 CRITICAL

The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Dec 13, 2025
CVE-2025-10738
9.8 CRITICAL

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ parameter in all versions up to, and including, …

Dec 13, 2025
CVE-2025-14611
9.8 CRITICAL KEV

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints …

Dec 12, 2025
CVE-2024-58311
9.8 CRITICAL

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can …

Dec 12, 2025
CVE-2024-58299
9.8 CRITICAL

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a …

Dec 12, 2025
CVE-2024-14010
9.8 CRITICAL

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands …

Dec 12, 2025
CVE-2025-66430
9.1 CRITICAL

Plesk 18.0 has Incorrect Access Control.

Dec 12, 2025
CVE-2025-65854
9.8 CRITICAL

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.

Dec 12, 2025
CVE-2025-54947
9.8 CRITICAL

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, …

Dec 12, 2025
CVE-2025-58130
9.1 CRITICAL

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to …

Dec 12, 2025
CVE-2025-67728
9.8 CRITICAL

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, …

Dec 12, 2025
CVE-2025-67727
9.8 CRITICAL

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI …

Dec 12, 2025
CVE-2025-14344
9.8 CRITICAL

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function …

Dec 12, 2025
CVE-2025-12963
9.8 CRITICAL

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in …

Dec 12, 2025
CVE-2025-64721
10.0 CRITICAL

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the SYSTEM-level service SbieSvc.exe exposes SbieIniServer::RC4Crypt …

Dec 11, 2025
CVE-2024-58309
9.8 CRITICAL

xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malicious SQL code through the msgid parameter. …

Dec 11, 2025
CVE-2024-58308
9.8 CRITICAL

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL …

Dec 11, 2025
CVE-2025-66590
9.8 CRITICAL

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Write vulnerability can be exploited by an attacker to cause the program to write data past …

Dec 11, 2025
CVE-2025-66589
9.1 CRITICAL

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past …

Dec 11, 2025
CVE-2025-66588
9.8 CRITICAL

In AzeoTech DAQFactory release 20.7 (Build 2555), an Access of Uninitialized Pointer vulnerability can be exploited by an attacker which can lead to arbitrary code …

Dec 11, 2025
CVE-2025-36937
9.8 CRITICAL

In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution …

Dec 11, 2025
CVE-2025-14535
9.8 CRITICAL

A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument …

Dec 11, 2025
CVE-2025-14534
9.8 CRITICAL

A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endpoint. Executing …

Dec 11, 2025
CVE-2025-13780
9.1 CRITICAL

pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from …

Dec 11, 2025
CVE-2025-66048
9.8 CRITICAL

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to …

Dec 11, 2025
CVE-2025-66047
9.8 CRITICAL

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to …

Dec 11, 2025
CVE-2025-66046
9.8 CRITICAL

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to …

Dec 11, 2025
CVE-2025-66045
9.8 CRITICAL

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to …

Dec 11, 2025
CVE-2025-66044
9.8 CRITICAL

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to …

Dec 11, 2025
CVE-2025-66043
9.8 CRITICAL

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to …

Dec 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.