CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-14038
7.0 HIGH

EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially …

Dec 15, 2025
CVE-2025-66435
4.3 MEDIUM

An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (contract_terms) using frappe.render_template() …

Dec 15, 2025
CVE-2025-66434
8.8 HIGH

An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() …

Dec 15, 2025
CVE-2025-65742
8.2 HIGH

An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via …

Dec 15, 2025
CVE-2025-55901
6.5 MEDIUM

TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.

Dec 15, 2025
CVE-2025-55893
6.5 MEDIUM

TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.

Dec 15, 2025
CVE-2025-11393
8.7 HIGH

A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials …

Dec 15, 2025
CVE-2025-66963
5.5 MEDIUM

An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html

Dec 15, 2025
CVE-2025-66844
9.1 CRITICAL

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration …

Dec 15, 2025
CVE-2025-66843
5.4 MEDIUM

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content …

Dec 15, 2025
CVE-2025-60786
8.8 HIGH

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted …

Dec 15, 2025
CVE-2025-14387
6.4 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to …

Dec 15, 2025
CVE-2025-13888
9.1 CRITICAL

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in …

Dec 15, 2025
CVE-2025-13824

A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED …

Dec 15, 2025
CVE-2025-13823

A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The …

Dec 15, 2025
CVE-2024-44599
8.3 HIGH

FNT Command 13.4.0 is vulnerable to Directory Traversal.

Dec 15, 2025
CVE-2024-44598
8.8 HIGH

FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.

Dec 15, 2025
CVE-2025-34412

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulnerability in a SaaS product that …

Dec 15, 2025
CVE-2025-34411

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulnerability in a SaaS product that …

Dec 15, 2025
CVE-2025-34181

NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can …

Dec 15, 2025
CVE-2025-34180

NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a …

Dec 15, 2025
CVE-2025-34179

NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized …

Dec 15, 2025
CVE-2025-14383
7.5 HIGH

The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 …

Dec 15, 2025
CVE-2025-14156
9.8 CRITICAL

The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is …

Dec 15, 2025
CVE-2025-14003
4.3 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Dec 15, 2025
CVE-2025-13950
5.3 MEDIUM

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings …

Dec 15, 2025
CVE-2025-13728
6.4 MEDIUM

The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fluent_auth_reset_password` shortcode …

Dec 15, 2025
CVE-2025-13610
6.4 MEDIUM

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RM_Forms' …

Dec 15, 2025
CVE-2025-13608
6.4 MEDIUM

The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in all versions up to, and including, 2.0.0. …

Dec 15, 2025
CVE-2025-13367
6.4 MEDIUM

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to …

Dec 15, 2025
CVE-2025-12900
4.3 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, …

Dec 15, 2025
CVE-2025-65782
6.5 MEDIUM

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling …

Dec 15, 2025
CVE-2025-65781
8.2 HIGH

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization …

Dec 15, 2025
CVE-2025-65780
8.8 HIGH

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire …

Dec 15, 2025
CVE-2025-65779
7.5 HIGH

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's …

Dec 15, 2025
CVE-2025-65778
8.1 HIGH

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with …

Dec 15, 2025
CVE-2025-65431
5.4 MEDIUM

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may …

Dec 15, 2025
CVE-2025-65430
5.4 MEDIUM

An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was …

Dec 15, 2025
CVE-2025-66388
6.5 MEDIUM

A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing …

Dec 15, 2025
CVE-2025-37732
5.4 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the …

Dec 15, 2025
CVE-2025-37731
6.8 MEDIUM

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a …

Dec 15, 2025
CVE-2025-14714
6.5 MEDIUM

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user …

Dec 15, 2025
CVE-2025-11670
6.4 MEDIUM

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as …

Dec 15, 2025
CVE-2025-14711
7.3 HIGH

A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulation of the …

Dec 15, 2025
CVE-2025-14710
7.3 HIGH

A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument …

Dec 15, 2025
CVE-2025-14709
9.8 CRITICAL

A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the …

Dec 15, 2025
CVE-2025-14708
9.8 CRITICAL

A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component …

Dec 15, 2025
CVE-2025-14023
3.1 LOW

LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could …

Dec 15, 2025
CVE-2025-14022
7.7 HIGH

LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with …

Dec 15, 2025
CVE-2025-14021
4.3 MEDIUM

The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious …

Dec 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.