CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11009
5.1 MEDIUM

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows …

Dec 17, 2025
CVE-2025-53524
7.8 HIGH

Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project file, which may allow an attacker to execute arbitrary …

Dec 17, 2025
CVE-2025-14701
7.1 HIGH

An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.

Dec 17, 2025
CVE-2025-14700
9.9 CRITICAL

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side …

Dec 17, 2025
CVE-2025-34288
6.7 MEDIUM

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A …

Dec 16, 2025
CVE-2025-14766
8.8 HIGH

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a …

Dec 16, 2025
CVE-2025-14765
8.8 HIGH

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Dec 16, 2025
CVE-2025-68274
7.5 HIGH

SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alpha-1, a nil pointer dereference …

Dec 16, 2025
CVE-2025-64520
6.5 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API …

Dec 16, 2025
CVE-2025-53619
7.4 HIGH

An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An …

Dec 16, 2025
CVE-2025-53618
7.4 HIGH

An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An …

Dec 16, 2025
CVE-2025-52582
7.4 HIGH

An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An …

Dec 16, 2025
CVE-2025-48429
7.4 HIGH

An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An …

Dec 16, 2025
CVE-2025-14466
5.3 MEDIUM

A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with network access to send …

Dec 16, 2025
CVE-2025-0852

Rejected reason: Voluntarily withdrawn

Dec 16, 2025
CVE-2025-8872
6.5 MEDIUM

On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may …

Dec 16, 2025
CVE-2025-65834
9.8 CRITICAL

Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulated width and height parameters. By …

Dec 16, 2025
CVE-2025-13532
6.2 MEDIUM

Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This …

Dec 16, 2025
CVE-2025-68270
9.9 CRITICAL

The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are able to access and edit courses in studio if …

Dec 16, 2025
CVE-2025-68156
7.5 HIGH

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and …

Dec 16, 2025
CVE-2025-68155
7.5 HIGH

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development …

Dec 16, 2025
CVE-2025-68154
8.1 HIGH

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command …

Dec 16, 2025
CVE-2025-68150
6.5 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the …

Dec 16, 2025
CVE-2025-68146
6.3 MEDIUM

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate …

Dec 16, 2025
CVE-2025-65593
8.8 HIGH

nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.

Dec 16, 2025
CVE-2025-65592
6.1 MEDIUM

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields …

Dec 16, 2025
CVE-2025-65591
5.4 MEDIUM

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.

Dec 16, 2025
CVE-2025-65590
5.4 MEDIUM

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area.

Dec 16, 2025
CVE-2025-14553

Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo cameras, allowing attackers to brute force …

Dec 16, 2025
CVE-2025-68142
5.3 MEDIUM

PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption …

Dec 16, 2025
CVE-2025-65589
6.1 MEDIUM

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.

Dec 16, 2025
CVE-2025-65581
5.3 MEDIUM

An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in …

Dec 16, 2025
CVE-2025-62864
9.8 CRITICAL

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM …

Dec 16, 2025
CVE-2025-62863
9.8 CRITICAL

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM …

Dec 16, 2025
CVE-2025-52196
7.5 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce the server to make arbitrary HTTP requests via a crafted …

Dec 16, 2025
CVE-2025-46296
5.4 MEDIUM

An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and …

Dec 16, 2025
CVE-2025-46295
9.8 CRITICAL

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some …

Dec 16, 2025
CVE-2025-46294
5.3 MEDIUM

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. …

Dec 16, 2025
CVE-2025-33235
7.8 HIGH

NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a race condition. A successful exploit of this …

Dec 16, 2025
CVE-2025-33226
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful exploit of …

Dec 16, 2025
CVE-2025-33225
8.4 HIGH

NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names. A successful exploit of this vulnerability …

Dec 16, 2025
CVE-2025-33212
7.3 HIGH

NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a user loads a maliciously …

Dec 16, 2025
CVE-2025-33210
9.0 CRITICAL

NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution.

Dec 16, 2025
CVE-2023-53900
8.8 HIGH

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking …

Dec 16, 2025
CVE-2023-53896
7.5 HIGH

D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit …

Dec 16, 2025
CVE-2025-68130

tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and …

Dec 16, 2025
CVE-2025-68116
8.9 HIGH

FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling …

Dec 16, 2025
CVE-2025-63414
10.0 CRITICAL

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP …

Dec 16, 2025
CVE-2025-62862
4.6 MEDIUM

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM …

Dec 16, 2025
CVE-2025-59935
6.5 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an …

Dec 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.