CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-41734
9.8 CRITICAL

An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.

Nov 18, 2025
CVE-2025-41733
9.8 CRITICAL

The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to …

Nov 18, 2025
CVE-2025-41347
9.8 CRITICAL

Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending …

Nov 18, 2025
CVE-2025-41346
9.8 CRITICAL

Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning …

Nov 18, 2025
CVE-2025-40549
9.1 CRITICAL

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute …

Nov 18, 2025
CVE-2025-40548
9.1 CRITICAL

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. …

Nov 18, 2025
CVE-2025-40547
9.1 CRITICAL

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. …

Nov 18, 2025
CVE-2024-44659
9.8 CRITICAL

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

Nov 17, 2025
CVE-2025-63747
9.8 CRITICAL

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the …

Nov 17, 2025
CVE-2025-9501
9.0 CRITICAL

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by …

Nov 17, 2025
CVE-2025-13284
9.8 CRITICAL

ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

Nov 17, 2025
CVE-2025-58083
10.0 CRITICAL

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

Nov 15, 2025
CVE-2025-13188
9.8 CRITICAL

A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument …

Nov 14, 2025
CVE-2025-54343
9.6 CRITICAL

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

Nov 14, 2025
CVE-2025-54339
10.0 CRITICAL

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

Nov 14, 2025
CVE-2025-64446
9.8 CRITICAL KEV

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 …

Nov 14, 2025
CVE-2025-36251
9.6 CRITICAL

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due …

Nov 13, 2025
CVE-2025-36250
10.0 CRITICAL

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker …

Nov 13, 2025
CVE-2025-36096
9.0 CRITICAL

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is …

Nov 13, 2025
CVE-2025-64709
9.6 CRITICAL

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) …

Nov 13, 2025
CVE-2025-64717
9.8 CRITICAL

ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation …

Nov 13, 2025
CVE-2025-12762
9.1 CRITICAL

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from …

Nov 13, 2025
CVE-2025-59367
9.8 CRITICAL

An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer …

Nov 13, 2025
CVE-2025-46608
9.1 CRITICAL

Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, …

Nov 12, 2025
CVE-2025-56385
9.8 CRITICAL

A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is …

Nov 12, 2025
CVE-2025-64281
9.8 CRITICAL

An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials.

Nov 12, 2025
CVE-2025-64280
9.8 CRITICAL

A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field.

Nov 12, 2025
CVE-2025-63353
9.8 CRITICAL

A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The …

Nov 12, 2025
CVE-2025-63289
9.1 CRITICAL

Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file

Nov 12, 2025
CVE-2025-11367
9.8 CRITICAL

The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization

Nov 12, 2025
CVE-2025-11366
9.8 CRITICAL

N-central < 2025.4 is vulnerable to authentication bypass via path traversal

Nov 12, 2025
CVE-2025-63666
9.8 CRITICAL

Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session …

Nov 12, 2025
CVE-2025-12871
9.8 CRITICAL

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the …

Nov 12, 2025
CVE-2025-12870
9.8 CRITICAL

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use …

Nov 12, 2025
CVE-2025-60724
9.8 CRITICAL

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Nov 11, 2025
CVE-2025-13032
9.9 CRITICAL

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overflow.

Nov 11, 2025
CVE-2025-13026
9.8 CRITICAL

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Nov 11, 2025
CVE-2025-13024
9.8 CRITICAL

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Nov 11, 2025
CVE-2025-13023
9.8 CRITICAL

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Nov 11, 2025
CVE-2025-13022
9.8 CRITICAL

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Nov 11, 2025
CVE-2025-13021
9.8 CRITICAL

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Nov 11, 2025
CVE-2025-8324
9.8 CRITICAL

Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.

Nov 11, 2025
CVE-2025-12539
10.0 CRITICAL

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due …

Nov 11, 2025
CVE-2017-20210
9.8 CRITICAL

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.

Nov 11, 2025
CVE-2025-12813
9.8 CRITICAL

The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' …

Nov 11, 2025
CVE-2025-11457
9.8 CRITICAL

The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.8.2. This is …

Nov 11, 2025
CVE-2025-11170
9.8 CRITICAL

The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Import_Controller::import function in all …

Nov 11, 2025
CVE-2025-42890
10.0 CRITICAL

SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code …

Nov 11, 2025
CVE-2025-42887
9.9 CRITICAL

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide …

Nov 11, 2025
CVE-2025-64522
9.1 CRITICAL

Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, …

Nov 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.