CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-47372
9.0 CRITICAL

Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.

Dec 18, 2025
CVE-2025-47350
7.8 HIGH

Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.

Dec 18, 2025
CVE-2025-47325
6.5 MEDIUM

Information disclosure while processing system calls with invalid parameters.

Dec 18, 2025
CVE-2025-47323
7.8 HIGH

Memory corruption while routing GPR packets between user and root when handling large data packet.

Dec 18, 2025
CVE-2025-47322
7.8 HIGH

Memory corruption while handling IOCTL calls to set mode.

Dec 18, 2025
CVE-2025-47321
7.8 HIGH

Memory corruption while copying packets received from unix clients.

Dec 18, 2025
CVE-2025-47320
7.8 HIGH

Memory corruption while processing MFC channel configuration during music playback.

Dec 18, 2025
CVE-2025-47319
6.7 MEDIUM

Information disclosure while exposing internal TA-to-TA communication APIs to HLOS

Dec 18, 2025
CVE-2025-27063
7.8 HIGH

Memory corruption during video playback when video session open fails with time out error.

Dec 18, 2025
CVE-2025-68461
7.2 HIGH KEV

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Dec 18, 2025
CVE-2025-68460
7.2 HIGH

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

Dec 18, 2025
CVE-2025-12885
6.4 MEDIUM

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function …

Dec 18, 2025
CVE-2025-14856
6.3 MEDIUM

A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation …

Dec 18, 2025
CVE-2025-14841
3.3 LOW

A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component …

Dec 18, 2025
CVE-2025-14837
4.7 MEDIUM

A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Backend Website …

Dec 18, 2025
CVE-2025-14202

A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG file with JavaScript content. When …

Dec 18, 2025
CVE-2025-68435
9.1 CRITICAL

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied …

Dec 17, 2025
CVE-2025-68434
8.8 HIGH

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and …

Dec 17, 2025
CVE-2025-68433
7.7 HIGH

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from …

Dec 17, 2025
CVE-2025-68432
7.7 HIGH

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) configurations from …

Dec 17, 2025
CVE-2025-68429
7.3 HIGH

Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions …

Dec 17, 2025
CVE-2025-68147
8.1 HIGH

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and …

Dec 17, 2025
CVE-2025-68145
9.1 CRITICAL

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did …

Dec 17, 2025
CVE-2025-68144
7.1 HIGH

In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., `--output=/path/to/file` …

Dec 17, 2025
CVE-2025-68143
8.8 HIGH

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool …

Dec 17, 2025
CVE-2025-66029
7.6 HIGH

Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. …

Dec 17, 2025
CVE-2025-14836
2.7 LOW

A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data …

Dec 17, 2025
CVE-2025-14834
6.3 MEDIUM

A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing a manipulation of the …

Dec 17, 2025
CVE-2025-14833
7.3 HIGH

A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /admin/deletemanagerclinic.php. Performing …

Dec 17, 2025
CVE-2025-14319

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 17, 2025
CVE-2025-14268

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 17, 2025
CVE-2023-53933
8.8 HIGH

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with …

Dec 17, 2025
CVE-2023-53932
5.4 MEDIUM

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with …

Dec 17, 2025
CVE-2023-53931
6.1 MEDIUM

Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a …

Dec 17, 2025
CVE-2023-53930
7.5 HIGH

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can …

Dec 17, 2025
CVE-2023-53929
8.8 HIGH

phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attackers can modify their user profile …

Dec 17, 2025
CVE-2023-53928
5.4 MEDIUM

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can …

Dec 17, 2025
CVE-2023-53927
5.4 MEDIUM

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create …

Dec 17, 2025
CVE-2023-53926
9.8 CRITICAL

PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted …

Dec 17, 2025
CVE-2023-53925
6.1 MEDIUM

UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files …

Dec 17, 2025
CVE-2023-53924
8.8 HIGH

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can …

Dec 17, 2025
CVE-2023-53923
9.8 CRITICAL

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST …

Dec 17, 2025
CVE-2023-53922
9.8 CRITICAL

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload …

Dec 17, 2025
CVE-2023-53921
9.8 CRITICAL

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar …

Dec 17, 2025
CVE-2023-53920
5.4 MEDIUM

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into …

Dec 17, 2025
CVE-2023-53919
5.4 MEDIUM

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into …

Dec 17, 2025
CVE-2023-53918
6.1 MEDIUM

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into …

Dec 17, 2025
CVE-2023-53917
6.5 MEDIUM

Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the …

Dec 17, 2025
CVE-2023-53916
4.6 MEDIUM

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported …

Dec 17, 2025
CVE-2023-53915
4.6 MEDIUM

Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can …

Dec 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.