CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62002
4.3 MEDIUM

BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection …

Dec 18, 2025
CVE-2025-62001
8.8 HIGH

BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated …

Dec 18, 2025
CVE-2025-62000
7.1 HIGH

BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection method that evaluates file content based on header …

Dec 18, 2025
CVE-2025-59529
5.5 MEDIUM

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the …

Dec 18, 2025
CVE-2025-53710
7.5 HIGH

Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This …

Dec 18, 2025
CVE-2025-46268
6.3 MEDIUM

Advantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

Dec 18, 2025
CVE-2025-14850
8.1 HIGH

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

Dec 18, 2025
CVE-2025-14849
8.8 HIGH

Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

Dec 18, 2025
CVE-2025-14848
4.3 MEDIUM

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Dec 18, 2025
CVE-2025-13911
6.4 MEDIUM

The vulnerability affects Ignition SCADA applications where Python scripting is utilized for automation purposes. The vulnerability arises from the absence of proper security controls that …

Dec 18, 2025
CVE-2025-67163
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload …

Dec 18, 2025
CVE-2025-65566
7.5 HIGH

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Session Report Response that is missing …

Dec 18, 2025
CVE-2025-64400
4.1 MEDIUM

Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that …

Dec 18, 2025
CVE-2025-14889
5.4 MEDIUM

A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/voters_edit.php of …

Dec 18, 2025
CVE-2024-58323
5.4 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute …

Dec 18, 2025
CVE-2024-58322
5.4 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of …

Dec 18, 2025
CVE-2024-58321
5.4 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to …

Dec 18, 2025
CVE-2024-58320
5.3 MEDIUM

An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration …

Dec 18, 2025
CVE-2024-58319
6.1 MEDIUM

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. Attackers can exploit this …

Dec 18, 2025
CVE-2024-58318
6.1 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. …

Dec 18, 2025
CVE-2024-58317
5.3 MEDIUM

A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework …

Dec 18, 2025
CVE-2023-53944
6.5 MEDIUM

EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager …

Dec 18, 2025
CVE-2023-53943
5.3 MEDIUM

GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email …

Dec 18, 2025
CVE-2023-53942
8.8 HIGH

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can …

Dec 18, 2025
CVE-2023-53941
9.8 CRITICAL

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control …

Dec 18, 2025
CVE-2023-53940
7.8 HIGH

Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can …

Dec 18, 2025
CVE-2023-53939
5.4 MEDIUM

TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album …

Dec 18, 2025
CVE-2023-53938
5.4 MEDIUM

RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple unencoded input parameters. Attackers can exploit the vulnerability …

Dec 18, 2025
CVE-2023-53937
7.8 HIGH

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate …

Dec 18, 2025
CVE-2023-53936
4.8 MEDIUM

Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with …

Dec 18, 2025
CVE-2023-53935
5.4 MEDIUM

WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject …

Dec 18, 2025
CVE-2023-53934
7.5 HIGH

A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation …

Dec 18, 2025
CVE-2023-53738
5.4 MEDIUM

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to …

Dec 18, 2025
CVE-2023-53737
4.8 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could …

Dec 18, 2025
CVE-2023-53736
5.4 MEDIUM

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to …

Dec 18, 2025
CVE-2022-50686
7.5 HIGH

An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages …

Dec 18, 2025
CVE-2022-50685
5.4 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers …

Dec 18, 2025
CVE-2022-50684
6.1 MEDIUM

An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values …

Dec 18, 2025
CVE-2022-50683
5.4 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form redirect URL configuration. This allows malicious scripts to execute …

Dec 18, 2025
CVE-2022-50682
6.5 MEDIUM

A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable …

Dec 18, 2025
CVE-2022-50681
6.1 MEDIUM

A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via administration input fields in the Rich text editor component. Attackers …

Dec 18, 2025
CVE-2022-50680
4.8 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows administration users to inject malicious scripts via email marketing templates. Attackers can exploit this vulnerability to …

Dec 18, 2025
CVE-2021-47712
7.5 HIGH

A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through existing hashing mechanisms. The hotfix introduces an additional security layer …

Dec 18, 2025
CVE-2021-47711
8.8 HIGH

A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database …

Dec 18, 2025
CVE-2020-36891
5.4 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit …

Dec 18, 2025
CVE-2020-36890
7.2 HIGH

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator …

Dec 18, 2025
CVE-2020-36889
5.4 MEDIUM

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious …

Dec 18, 2025
CVE-2019-25230
4.3 MEDIUM

An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit …

Dec 18, 2025
CVE-2019-25229
8.8 HIGH

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader …

Dec 18, 2025
CVE-2019-25228
5.3 MEDIUM

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. …

Dec 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.