CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13124
7.6 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Netiket Information Technologies Ltd. Co. ApplyLogic allows Exploitation of Trusted Identifiers.This issue affects ApplyLogic: through 01.12.2025.

Dec 11, 2025
CVE-2024-40593
6.0 MEDIUM

A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 …

Dec 11, 2025
CVE-2025-14517
5.3 MEDIUM

A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity of the file AndroidManifest.xml. Executing manipulation can lead to improper export of …

Dec 11, 2025
CVE-2025-14516
6.3 MEDIUM

A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is the function downloadFile of the file com.yalantis.ucrop.task.BitmapLoadTask.java of the component URL Handler. …

Dec 11, 2025
CVE-2025-14523
8.2 HIGH

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies …

Dec 11, 2025
CVE-2025-14515
7.3 HIGH

A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_unit.php. Such manipulation …

Dec 11, 2025
CVE-2025-13003
7.6 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Trusted Identifiers.This issue affects AxOnboard: from 3.2.0 before …

Dec 11, 2025
CVE-2025-64995
6.5 MEDIUM

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path …

Dec 11, 2025
CVE-2025-64994
6.5 MEDIUM

A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search …

Dec 11, 2025
CVE-2025-64993
6.8 MEDIUM

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner …

Dec 11, 2025
CVE-2025-64992
6.8 MEDIUM

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers …

Dec 11, 2025
CVE-2025-64991
6.8 MEDIUM

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers …

Dec 11, 2025
CVE-2025-64990
6.8 MEDIUM

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers …

Dec 11, 2025
CVE-2025-64989
7.2 HIGH

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authenticated attackers …

Dec 11, 2025
CVE-2025-64988
7.2 HIGH

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attackers …

Dec 11, 2025
CVE-2025-64987
7.2 HIGH

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner …

Dec 11, 2025
CVE-2025-64986
7.2 HIGH

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attackers …

Dec 11, 2025
CVE-2025-46266
4.3 MEDIUM

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the …

Dec 11, 2025
CVE-2025-44016
8.8 HIGH

A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file …

Dec 11, 2025
CVE-2025-14514
7.3 HIGH

A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of the argument …

Dec 11, 2025
CVE-2025-12687
6.5 MEDIUM

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to cause a …

Dec 11, 2025
CVE-2025-64701
7.8 HIGH

QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the …

Dec 11, 2025
CVE-2025-12734
3.5 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have …

Dec 11, 2025
CVE-2025-12029
8.0 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, …

Dec 11, 2025
CVE-2025-67738
8.5 HIGH

squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and …

Dec 11, 2025
CVE-2025-14512
6.5 MEDIUM

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) …

Dec 11, 2025
CVE-2025-8405
7.7 HIGH

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could …

Dec 11, 2025
CVE-2025-4097
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have …

Dec 11, 2025
CVE-2025-11984
6.8 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have …

Dec 11, 2025
CVE-2025-11247
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have …

Dec 11, 2025
CVE-2025-9436
6.4 MEDIUM

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trustindex` shortcode in all versions up to, and …

Dec 11, 2025
CVE-2025-67694

Rejected reason: Not used

Dec 11, 2025
CVE-2025-67693

Rejected reason: Not used

Dec 11, 2025
CVE-2025-67692

Rejected reason: Not used

Dec 11, 2025
CVE-2025-67691

Rejected reason: Not used

Dec 11, 2025
CVE-2025-67690

Rejected reason: Not used

Dec 11, 2025
CVE-2025-67689

Rejected reason: Not used

Dec 11, 2025
CVE-2025-67688

Rejected reason: Not used

Dec 11, 2025
CVE-2025-67687

Rejected reason: Not used

Dec 11, 2025
CVE-2025-67686

Rejected reason: Not used

Dec 11, 2025
CVE-2025-14157
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have …

Dec 11, 2025
CVE-2025-13978
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have …

Dec 11, 2025
CVE-2025-12716
8.7 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain …

Dec 11, 2025
CVE-2025-12562
7.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have …

Dec 11, 2025
CVE-2025-10163
6.5 MEDIUM

The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter of the catlist shortcode in all versions up …

Dec 11, 2025
CVE-2025-14485
5.0 MEDIUM

A weakness has been identified in EFM ipTIME A3004T 14.19.0. This vulnerability affects the function show_debug_screen of the file /sess-bin/timepro.cgi of the component Administrator Password …

Dec 11, 2025
CVE-2025-13764
9.8 CRITICAL

The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16. This is due to the 'WP_CarDealer_User::process_register' …

Dec 11, 2025
CVE-2025-11467
5.8 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request …

Dec 11, 2025
CVE-2025-67720
6.5 MEDIUM

Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messages in the download_media method …

Dec 11, 2025
CVE-2025-67719

Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 …

Dec 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.