CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62849
9.8 CRITICAL

An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized …

Dec 16, 2025
CVE-2025-62848
7.5 HIGH

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch …

Dec 16, 2025
CVE-2025-62847
7.5 HIGH

An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then …

Dec 16, 2025
CVE-2025-59385
9.8 CRITICAL

An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to …

Dec 16, 2025
CVE-2025-14749
6.3 MEDIUM

A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVIF PTZ Control Interface. The …

Dec 16, 2025
CVE-2025-14748
5.4 MEDIUM

A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVIF Device Management Service. Executing …

Dec 16, 2025
CVE-2025-14747
4.3 MEDIUM

A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTSP Service. Performing manipulation results in denial …

Dec 16, 2025
CVE-2025-14746
4.3 MEDIUM

A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endpoint. Such …

Dec 16, 2025
CVE-2025-68115
6.1 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, …

Dec 16, 2025
CVE-2025-68113
6.5 MEDIUM

ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay …

Dec 16, 2025
CVE-2025-67874
6.5 MEDIUM

ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This …

Dec 16, 2025
CVE-2025-67751
7.2 HIGH

ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the `EventEditor.php` file. When creating a new event …

Dec 16, 2025
CVE-2025-67748
7.8 HIGH

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of …

Dec 16, 2025
CVE-2025-67747
7.8 HIGH

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` from the block list of unsafe module …

Dec 16, 2025
CVE-2025-67744
9.6 CRITICAL

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerability exists in the Mermaid …

Dec 16, 2025
CVE-2025-67736
7.2 HIGH

The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to 16.0.5 and 17.0.5 …

Dec 16, 2025
CVE-2025-67735
6.5 MEDIUM

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI …

Dec 16, 2025
CVE-2025-67722
7.8 HIGH

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local …

Dec 16, 2025
CVE-2025-67715
4.3 MEDIUM

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via …

Dec 16, 2025
CVE-2025-67492
5.3 MEDIUM

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted …

Dec 16, 2025
CVE-2025-66449
8.8 HIGH

ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, …

Dec 16, 2025
CVE-2025-14758
6.5 MEDIUM

Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows an on-path attacker to read database contents, potentially including …

Dec 16, 2025
CVE-2025-9460
7.8 HIGH

A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-9459
7.8 HIGH

A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-9457
7.8 HIGH

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-9456
7.8 HIGH

A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-9455
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-9454
7.8 HIGH

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-9453
7.8 HIGH

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-9452
7.8 HIGH

A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-66482
6.5 MEDIUM

Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can …

Dec 16, 2025
CVE-2025-66407
5.0 MEDIUM

Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a …

Dec 16, 2025
CVE-2025-66402
6.5 MEDIUM

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission …

Dec 16, 2025
CVE-2025-58173
8.8 HIGH

FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to …

Dec 16, 2025
CVE-2025-14731
6.3 MEDIUM

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component …

Dec 16, 2025
CVE-2025-14593
7.8 HIGH

A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10900
7.8 HIGH

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10899
7.8 HIGH

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10898
7.8 HIGH

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10889
7.8 HIGH

A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10888
7.8 HIGH

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10887
7.8 HIGH

A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10886
7.8 HIGH

A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10884
7.8 HIGH

AA maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10883
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10882
7.8 HIGH

AA maliciously crafted X_T file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Dec 16, 2025
CVE-2025-10881
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to …

Dec 16, 2025
CVE-2025-9122
5.3 MEDIUM

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when …

Dec 15, 2025
CVE-2025-9121
8.8 HIGH

Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to …

Dec 15, 2025
CVE-2025-14730
4.7 MEDIUM

A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php …

Dec 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.