CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-67846
4.9 MEDIUM

The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the …

Dec 19, 2025
CVE-2025-67845
6.4 MEDIUM

A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML …

Dec 19, 2025
CVE-2025-67844
5.0 MEDIUM

The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields. It …

Dec 19, 2025
CVE-2025-67843
8.3 HIGH

A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inline …

Dec 19, 2025
CVE-2025-67842
6.4 MEDIUM

The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any …

Dec 19, 2025
CVE-2025-52692
8.8 HIGH

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without …

Dec 19, 2025
CVE-2025-14910
4.3 MEDIUM

A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation results in path traversal. …

Dec 19, 2025
CVE-2025-14909
4.3 MEDIUM

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead …

Dec 19, 2025
CVE-2025-13941
8.8 HIGH

A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used …

Dec 19, 2025
CVE-2025-14908
6.3 MEDIUM

A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the component …

Dec 19, 2025
CVE-2025-14900
4.7 MEDIUM

A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /admin/userdelete.php of the component …

Dec 19, 2025
CVE-2025-14899
4.7 MEDIUM

A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /admin/stateadd.php of the component Administrator …

Dec 19, 2025
CVE-2025-14733
9.8 CRITICAL KEV

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User …

Dec 19, 2025
CVE-2025-11774
8.2 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as "keypad function") …

Dec 19, 2025
CVE-2025-64675
8.3 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.

Dec 19, 2025
CVE-2025-14898
4.7 MEDIUM

A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component …

Dec 19, 2025
CVE-2025-14897
4.7 MEDIUM

A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component …

Dec 19, 2025
CVE-2025-68422
4.3 MEDIUM

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP …

Dec 18, 2025
CVE-2025-68398
9.1 CRITICAL

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its …

Dec 18, 2025
CVE-2025-68390
4.9 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of …

Dec 18, 2025
CVE-2025-68389
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and …

Dec 18, 2025
CVE-2025-68387
6.1 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be …

Dec 18, 2025
CVE-2025-68386
4.3 MEDIUM

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even …

Dec 18, 2025
CVE-2025-68385
7.2 HIGH

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be …

Dec 18, 2025
CVE-2025-68279
7.7 HIGH

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using …

Dec 18, 2025
CVE-2025-68388
5.3 MEDIUM

Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration …

Dec 18, 2025
CVE-2025-68384
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial …

Dec 18, 2025
CVE-2025-68383
6.5 MEDIUM

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to …

Dec 18, 2025
CVE-2025-68382
6.5 MEDIUM

Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through …

Dec 18, 2025
CVE-2025-68381
6.5 MEDIUM

Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause …

Dec 18, 2025
CVE-2025-65046
3.1 LOW

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Dec 18, 2025
CVE-2025-65041
10.0 CRITICAL

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Dec 18, 2025
CVE-2025-65037
10.0 CRITICAL

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Dec 18, 2025
CVE-2025-64677
8.2 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.

Dec 18, 2025
CVE-2025-64676
7.2 HIGH

'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

Dec 18, 2025
CVE-2025-64663
9.9 CRITICAL

Custom Question Answering Elevation of Privilege Vulnerability

Dec 18, 2025
CVE-2025-34452

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow …

Dec 18, 2025
CVE-2025-34451
7.8 HIGH

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. …

Dec 18, 2025
CVE-2025-34450
7.8 HIGH

merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vulnerability in the function parse_rfraw() located in src/rfraw.c. …

Dec 18, 2025
CVE-2025-34449
9.1 CRITICAL

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send …

Dec 18, 2025
CVE-2025-13427

An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact with restricted chat agents, gaining access to the agents' knowledge …

Dec 18, 2025
CVE-2025-68161
4.8 MEDIUM

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName …

Dec 18, 2025
CVE-2025-67653
4.3 MEDIUM

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Dec 18, 2025
CVE-2025-63951
7.5 HIGH

An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that …

Dec 18, 2025
CVE-2025-63950
7.5 HIGH

An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that …

Dec 18, 2025
CVE-2025-63949
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' …

Dec 18, 2025
CVE-2025-63948
5.4 MEDIUM

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially …

Dec 18, 2025
CVE-2025-63947
5.4 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via …

Dec 18, 2025
CVE-2025-62004
7.5 HIGH

BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before …

Dec 18, 2025
CVE-2025-62003
7.5 HIGH

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during …

Dec 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.