CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-14020
5.4 MEDIUM

LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not …

Dec 15, 2025
CVE-2025-14019
3.4 LOW

LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the …

Dec 15, 2025
CVE-2025-14712
7.5 HIGH

Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific …

Dec 15, 2025
CVE-2025-14707
9.8 CRITICAL

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. …

Dec 15, 2025
CVE-2025-14706
9.8 CRITICAL

A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the component NETREBOOT Interface. Such manipulation …

Dec 15, 2025
CVE-2025-14549
8.1 HIGH

In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) …

Dec 15, 2025
CVE-2025-13355
7.1 HIGH

The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Dec 15, 2025
CVE-2025-12684
7.1 HIGH

The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected …

Dec 15, 2025
CVE-2025-11363
5.3 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.

Dec 15, 2025
CVE-2025-14705
9.8 CRITICAL

A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulation of the argument params …

Dec 15, 2025
CVE-2025-14704
7.3 HIGH

A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The …

Dec 15, 2025
CVE-2025-67907

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-67906. Reason: This candidate is a reservation duplicate of CVE-2025-67906. Notes: All CVE users should reference …

Dec 15, 2025
CVE-2025-67906
5.4 MEDIUM

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

Dec 15, 2025
CVE-2025-14703
5.3 MEDIUM

A vulnerability has been found in Shiguangwu sgwbox N3 2.0.25. The affected element is an unknown function of the file /fsnotify of the component POST …

Dec 15, 2025
CVE-2025-14702
4.4 MEDIUM

A flaw has been found in Smartbit CommV Smartschool App up to 10.4.4. Impacted is an unknown function of the component be.smartschool.mobile.SplashActivity. Executing manipulation can …

Dec 15, 2025
CVE-2025-13740
6.4 MEDIUM

The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweight-accordion` shortcode in all versions up to, and including, 1.5.20 …

Dec 15, 2025
CVE-2025-14699
5.3 MEDIUM

A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp.app. Such manipulation leads …

Dec 15, 2025
CVE-2025-14698
4.4 MEDIUM

A weakness has been identified in atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. This affects an unknown part of the component gallery.photogallery.pictures.vault.album. This …

Dec 15, 2025
CVE-2025-14697
3.7 LOW

A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this issue is some unknown functionality …

Dec 15, 2025
CVE-2025-14696
5.3 MEDIUM

A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the …

Dec 15, 2025
CVE-2025-14695
6.3 MEDIUM

A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing …

Dec 15, 2025
CVE-2025-14694
4.7 MEDIUM

A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/postil/readAllPostil. Performing a manipulation of the argument …

Dec 15, 2025
CVE-2025-14693
6.2 MEDIUM

A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads to …

Dec 15, 2025
CVE-2025-67901
5.3 MEDIUM

openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEGV by specifying a length …

Dec 15, 2025
CVE-2025-14692
4.3 MEDIUM

A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes …

Dec 15, 2025
CVE-2025-67900
8.1 HIGH

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Dec 14, 2025
CVE-2025-67899
2.9 LOW

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Dec 14, 2025
CVE-2025-14691
4.3 MEDIUM

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in …

Dec 14, 2025
CVE-2025-67898
4.5 MEDIUM

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an …

Dec 14, 2025
CVE-2025-13281
5.8 MEDIUM

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary …

Dec 14, 2025
CVE-2025-14674
6.3 MEDIUM

A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java. The manipulation results …

Dec 14, 2025
CVE-2025-14673
7.3 HIGH

A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to heap-based …

Dec 14, 2025
CVE-2025-14672
7.3 HIGH

A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead …

Dec 14, 2025
CVE-2025-14668
7.3 HIGH

A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the …

Dec 14, 2025
CVE-2025-14667
7.3 HIGH

A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/?page=system_info. Such manipulation …

Dec 14, 2025
CVE-2025-14666
7.3 HIGH

A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. This manipulation of …

Dec 14, 2025
CVE-2025-14665
9.8 CRITICAL

A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. …

Dec 14, 2025
CVE-2025-14664
7.3 HIGH

A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.php. The manipulation of the argument …

Dec 14, 2025
CVE-2025-14663
2.4 LOW

A vulnerability was determined in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/update_student.php. Executing manipulation can lead to …

Dec 14, 2025
CVE-2025-14662
2.4 LOW

A vulnerability was found in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php of the component Update User …

Dec 14, 2025
CVE-2025-14661
7.3 HIGH

A vulnerability has been found in itsourcecode Student Managemen System 1.0. Affected by this issue is some unknown functionality of the file /advisers.php. Such manipulation …

Dec 14, 2025
CVE-2025-14660
5.6 MEDIUM

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the …

Dec 14, 2025
CVE-2025-14659
8.8 HIGH

A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation of the argument …

Dec 14, 2025
CVE-2025-14656
8.8 HIGH

A weakness has been identified in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedWifi. Executing a manipulation of the argument schedStartTime/schedEndTime …

Dec 14, 2025
CVE-2025-14655
8.8 HIGH

A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd. …

Dec 14, 2025
CVE-2025-14654
8.8 HIGH

A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component httpd. Such manipulation …

Dec 14, 2025
CVE-2025-14653
7.3 HIGH

A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /addrecord.php. This manipulation of the argument ID …

Dec 14, 2025
CVE-2025-14652
7.3 HIGH

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?action=edit. The manipulation of the …

Dec 14, 2025
CVE-2025-14651
3.7 LOW

A vulnerability has been found in MartialBE one-hub up to 0.14.27. This vulnerability affects unknown code of the file docker-compose.yml. The manipulation of the argument …

Dec 14, 2025
CVE-2025-14650
7.3 HIGH

A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing manipulation of the …

Dec 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.