CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-67718

Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling …

Dec 11, 2025
CVE-2025-67717
4.3 MEDIUM

ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 disclose the total number of instance users to authenticated users, …

Dec 11, 2025
CVE-2025-67716
5.7 MEDIUM

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-validation flaw in the returnTo …

Dec 11, 2025
CVE-2025-67713
6.1 MEDIUM

Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. …

Dec 11, 2025
CVE-2025-67648
7.1 HIGH

Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from …

Dec 11, 2025
CVE-2025-67646
3.5 LOW

TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token validation in the REST API. …

Dec 11, 2025
CVE-2025-67644
7.3 HIGH

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.0 and below are vulnerable …

Dec 11, 2025
CVE-2025-67514

Rejected reason: Vulnerability is dependency-based.

Dec 11, 2025
CVE-2025-67512

Rejected reason: The vulnerability is dependency-based.

Dec 11, 2025
CVE-2025-67511
9.6 CRITICAL

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection …

Dec 11, 2025
CVE-2025-67513

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default …

Dec 10, 2025
CVE-2025-67510
9.4 CRITICAL

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller …

Dec 10, 2025
CVE-2025-67509
8.2 HIGH

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is …

Dec 10, 2025
CVE-2025-67505
8.4 HIGH

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the …

Dec 10, 2025
CVE-2025-67490
5.4 MEDIUM

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on …

Dec 10, 2025
CVE-2025-13923

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 10, 2025
CVE-2025-12731

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 10, 2025
CVE-2025-66628
7.5 HIGH

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains …

Dec 10, 2025
CVE-2025-66474
8.8 HIGH

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions …

Dec 10, 2025
CVE-2025-66473
7.5 HIGH

XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce …

Dec 10, 2025
CVE-2025-66472
6.1 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 …

Dec 10, 2025
CVE-2025-66033
5.3 MEDIUM

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads …

Dec 10, 2025
CVE-2025-65297
7.5 HIGH

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this …

Dec 10, 2025
CVE-2025-65296
6.5 MEDIUM

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed …

Dec 10, 2025
CVE-2025-65295
8.1 HIGH

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to …

Dec 10, 2025
CVE-2025-65294
9.8 CRITICAL

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command …

Dec 10, 2025
CVE-2025-65293
6.6 MEDIUM

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup …

Dec 10, 2025
CVE-2025-65292
7.3 HIGH

Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands …

Dec 10, 2025
CVE-2025-65291
7.4 HIGH

Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services …

Dec 10, 2025
CVE-2025-65290
7.4 HIGH

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing …

Dec 10, 2025
CVE-2024-58285
5.4 MEDIUM

Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the …

Dec 10, 2025
CVE-2024-58284
7.2 HIGH

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can …

Dec 10, 2025
CVE-2024-58283
8.8 HIGH

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers …

Dec 10, 2025
CVE-2024-58282
7.2 HIGH

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit …

Dec 10, 2025
CVE-2024-58281
8.8 HIGH

Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit …

Dec 10, 2025
CVE-2024-58280
8.8 HIGH

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' …

Dec 10, 2025
CVE-2024-58279
8.8 HIGH

appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers …

Dec 10, 2025
CVE-2023-53776
8.8 HIGH

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identifiers. Attackers can issue …

Dec 10, 2025
CVE-2023-53775
6.5 MEDIUM

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse …

Dec 10, 2025
CVE-2025-67461
5.0 MEDIUM

External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of …

Dec 10, 2025
CVE-2025-67460
7.8 HIGH

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via …

Dec 10, 2025
CVE-2025-65950
8.8 HIGH

WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify …

Dec 10, 2025
CVE-2025-65832
4.6 MEDIUM

The mobile application insecurely handles information stored within memory. By performing a memory dump on the application after a user has logged out and terminated …

Dec 10, 2025
CVE-2025-65831
7.5 HIGH

The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hashes, either through exploiting cloud services, …

Dec 10, 2025
CVE-2025-65830
9.1 CRITICAL

Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstream" can decrypt …

Dec 10, 2025
CVE-2025-65829
6.8 MEDIUM

The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that …

Dec 10, 2025
CVE-2025-65828
6.5 MEDIUM

An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in …

Dec 10, 2025
CVE-2025-65827
9.1 CRITICAL

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an …

Dec 10, 2025
CVE-2025-65826
9.8 CRITICAL

The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retrieved this, and found the physical …

Dec 10, 2025
CVE-2025-65825
4.6 MEDIUM

The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble the device, connect …

Dec 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.