CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43533
5.7 MEDIUM

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia …

Dec 17, 2025
CVE-2025-43531
3.1 LOW

A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS …

Dec 17, 2025
CVE-2025-43529
8.8 HIGH KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS …

Dec 17, 2025
CVE-2025-43526
9.8 CRITICAL

This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, …

Dec 17, 2025
CVE-2025-43514
5.5 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected …

Dec 17, 2025
CVE-2025-43501
4.3 MEDIUM

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and …

Dec 17, 2025
CVE-2025-43475
5.5 MEDIUM

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may be able to …

Dec 17, 2025
CVE-2025-43428
9.8 CRITICAL

A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Photos in …

Dec 17, 2025
CVE-2025-14764
5.3 MEDIUM

Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce …

Dec 17, 2025
CVE-2025-14763
5.3 MEDIUM

Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to introduce …

Dec 17, 2025
CVE-2025-14762
5.3 MEDIUM

Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new …

Dec 17, 2025
CVE-2025-14761
5.3 MEDIUM

Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to introduce a new …

Dec 17, 2025
CVE-2025-67787
9.6 CRITICAL

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.

Dec 17, 2025
CVE-2025-67781
9.9 CRITICAL

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain …

Dec 17, 2025
CVE-2025-67074
6.5 MEDIUM

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code …

Dec 17, 2025
CVE-2025-67073
9.8 CRITICAL

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code …

Dec 17, 2025
CVE-2025-66646
7.5 HIGH

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A vulnerability was …

Dec 17, 2025
CVE-2025-66397
8.3 HIGH

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in the Kiosk Manager feature suffers from …

Dec 17, 2025
CVE-2025-66396
7.2 HIGH

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/UserEditor.php` file. When an administrator saves a …

Dec 17, 2025
CVE-2025-65233
6.1 MEDIUM

Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript …

Dec 17, 2025
CVE-2025-34442
7.5 HIGH

AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to media files, revealing underlying …

Dec 17, 2025
CVE-2025-34441
7.5 HIGH

AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, …

Dec 17, 2025
CVE-2025-34440
6.1 MEDIUM

AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can redirect users …

Dec 17, 2025
CVE-2025-34439
6.1 MEDIUM

AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker …

Dec 17, 2025
CVE-2025-34438
8.1 HIGH

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. …

Dec 17, 2025
CVE-2025-34437
8.8 HIGH

AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits …

Dec 17, 2025
CVE-2025-34436
8.8 HIGH

AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. …

Dec 17, 2025
CVE-2025-34435
6.5 MEDIUM

AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to …

Dec 17, 2025
CVE-2025-34434
9.1 CRITICAL

AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints responsible for managing gallery images …

Dec 17, 2025
CVE-2025-14760
5.3 MEDIUM

Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to introduce a new …

Dec 17, 2025
CVE-2025-14759
5.3 MEDIUM

Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to introduce …

Dec 17, 2025
CVE-2025-67174
7.5 HIGH

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file …

Dec 17, 2025
CVE-2025-67173
6.8 MEDIUM

A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafted POST request.

Dec 17, 2025
CVE-2025-67171
7.5 HIGH

Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

Dec 17, 2025
CVE-2025-67170
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser via a crafted …

Dec 17, 2025
CVE-2025-67168
5.3 MEDIUM

RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

Dec 17, 2025
CVE-2025-66953
8.8 HIGH

CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interface and …

Dec 17, 2025
CVE-2025-66395
8.8 HIGH

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. When filtering events by type, …

Dec 17, 2025
CVE-2025-62521
10.0 CRITICAL

ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to …

Dec 17, 2025
CVE-2025-14081
4.3 MEDIUM

The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to …

Dec 17, 2025
CVE-2025-13537
6.4 MEDIUM

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scripting vulnerabilities via DOM manipulation in all versions …

Dec 17, 2025
CVE-2025-13326
3.9 LOW

Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an …

Dec 17, 2025
CVE-2025-13324
3.7 LOW

Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol …

Dec 17, 2025
CVE-2025-13321
3.3 LOW

Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access …

Dec 17, 2025
CVE-2025-13217
6.4 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Dec 17, 2025
CVE-2025-12689
6.5 MEDIUM

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to …

Dec 17, 2025
CVE-2024-46062
7.8 HIGH

Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and …

Dec 17, 2025
CVE-2024-46060
7.8 HIGH

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and …

Dec 17, 2025
CVE-2025-67172
7.2 HIGH

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

Dec 17, 2025
CVE-2025-66924
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or …

Dec 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.