CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13390
10.0 CRITICAL

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of …

Dec 3, 2025
CVE-2025-13342
9.8 CRITICAL

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. …

Dec 3, 2025
CVE-2025-13486
9.8 CRITICAL

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is …

Dec 3, 2025
CVE-2025-13542
9.8 CRITICAL

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' …

Dec 2, 2025
CVE-2025-66409
9.1 CRITICAL

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving …

Dec 2, 2025
CVE-2025-65896
9.8 CRITICAL

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

Dec 2, 2025
CVE-2025-60736
9.8 CRITICAL

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

Dec 2, 2025
CVE-2025-60854
9.8 CRITICAL

A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the …

Dec 2, 2025
CVE-2025-58386
9.8 CRITICAL

In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can …

Dec 2, 2025
CVE-2025-65656
9.8 CRITICAL

dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

Dec 2, 2025
CVE-2025-65358
9.8 CRITICAL

Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

Dec 2, 2025
CVE-2025-59703
9.1 CRITICAL

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal components of the …

Dec 2, 2025
CVE-2025-59695
9.8 CRITICAL

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the …

Dec 2, 2025
CVE-2025-59693
9.8 CRITICAL

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to obtain …

Dec 2, 2025
CVE-2025-41013
9.8 CRITICAL

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a …

Dec 2, 2025
CVE-2025-11788
9.8 CRITICAL

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer …

Dec 2, 2025
CVE-2025-11786
9.8 CRITICAL

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' …

Dec 2, 2025
CVE-2025-11785
9.8 CRITICAL

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fixed-size buffer …

Dec 2, 2025
CVE-2025-11784
9.8 CRITICAL

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer …

Dec 2, 2025
CVE-2025-11783
9.8 CRITICAL

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size …

Dec 2, 2025
CVE-2025-11782
9.8 CRITICAL

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in …

Dec 2, 2025
CVE-2025-11780
9.8 CRITICAL

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer …

Dec 2, 2025
CVE-2025-11779
9.8 CRITICAL

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by …

Dec 2, 2025
CVE-2025-11778
9.8 CRITICAL

Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' function of the TACACSPLUS implementation.

Dec 2, 2025
CVE-2025-41744
9.1 CRITICAL

Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.

Dec 2, 2025
CVE-2025-41742
9.8 CRITICAL

Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the …

Dec 2, 2025
CVE-2025-13872
9.1 CRITICAL

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to …

Dec 2, 2025
CVE-2025-66410
9.1 CRITICAL

Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, …

Dec 1, 2025
CVE-2025-66405
9.8 CRITICAL

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in …

Dec 1, 2025
CVE-2025-66401
9.8 CRITICAL

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical Command Injection …

Dec 1, 2025
CVE-2025-66301
9.6 CRITICAL

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an …

Dec 1, 2025
CVE-2025-65836
9.1 CRITICAL

PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

Dec 1, 2025
CVE-2025-51683
9.8 CRITICAL

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server …

Dec 1, 2025
CVE-2025-51682
9.8 CRITICAL

mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to administrative features. Additionally, they …

Dec 1, 2025
CVE-2025-8351
9.0 CRITICAL

Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avast Antivirus on MacOS when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of …

Dec 1, 2025
CVE-2025-63535
9.6 CRITICAL

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in …

Dec 1, 2025
CVE-2025-63532
9.6 CRITICAL

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in …

Dec 1, 2025
CVE-2025-3500
9.0 CRITICAL

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

Dec 1, 2025
CVE-2025-63531
10.0 CRITICAL

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in …

Dec 1, 2025
CVE-2025-63525
9.6 CRITICAL

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.

Dec 1, 2025
CVE-2025-12106
9.1 CRITICAL

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

Dec 1, 2025
CVE-2025-35028
9.1 CRITICAL

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, …

Nov 30, 2025
CVE-2025-13615
9.8 CRITICAL

The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the …

Nov 30, 2025
CVE-2025-66216
9.8 CRITICAL

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message class of AIS-catcher. This …

Nov 29, 2025
CVE-2025-66219
9.8 CRITICAL

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in …

Nov 29, 2025
CVE-2025-65112
9.4 CRITICAL

PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as …

Nov 29, 2025
CVE-2025-64314
9.3 CRITICAL

Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability may affect confidentiality.

Nov 28, 2025
CVE-2025-12421
9.9 CRITICAL

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code …

Nov 27, 2025
CVE-2025-12419
9.9 CRITICAL

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication …

Nov 27, 2025
CVE-2025-13675
9.8 CRITICAL

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.php' file …

Nov 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.