CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-34428
7.8 HIGH

MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores …

Dec 10, 2025
CVE-2025-34427
7.8 HIGH

MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores …

Dec 10, 2025
CVE-2025-65754
6.1 MEDIUM

Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.

Dec 10, 2025
CVE-2025-63094
7.5 HIGH

XiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackers to access sensitive information via side-channel …

Dec 10, 2025
CVE-2025-5467
3.3 LOW

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information …

Dec 10, 2025
CVE-2025-13607
9.4 CRITICAL

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

Dec 10, 2025
CVE-2025-67643
4.3 MEDIUM

Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to …

Dec 10, 2025
CVE-2025-67642
4.3 MEDIUM

Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and …

Dec 10, 2025
CVE-2025-67641
5.4 MEDIUM

Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through …

Dec 10, 2025
CVE-2025-67640
5.0 MEDIUM

Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a …

Dec 10, 2025
CVE-2025-67639
3.5 LOW

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the …

Dec 10, 2025
CVE-2025-67638
4.3 MEDIUM

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers …

Dec 10, 2025
CVE-2025-67637
4.3 MEDIUM

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be …

Dec 10, 2025
CVE-2025-67636
4.3 MEDIUM

A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.

Dec 10, 2025
CVE-2025-67635
7.5 HIGH

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to …

Dec 10, 2025
CVE-2025-65815
6.5 MEDIUM

A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory …

Dec 10, 2025
CVE-2025-65814
6.5 MEDIUM

A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal.

Dec 10, 2025
CVE-2025-65792
9.1 CRITICAL

DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.

Dec 10, 2025
CVE-2025-52493
6.5 MEDIUM

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the …

Dec 10, 2025
CVE-2025-65807
8.4 HIGH

An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.

Dec 10, 2025
CVE-2025-65803
6.5 MEDIUM

An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Dec 10, 2025
CVE-2025-34424
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34423
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34422
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34421
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34420
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34419
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34418
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34417
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34416
7.8 HIGH

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to …

Dec 10, 2025
CVE-2025-34410
7.1 HIGH

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel). The endpoint …

Dec 10, 2025
CVE-2025-34395
7.5 HIGH

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can …

Dec 10, 2025
CVE-2025-34394
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization …

Dec 10, 2025
CVE-2025-34393
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, …

Dec 10, 2025
CVE-2025-34392
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that …

Dec 10, 2025
CVE-2025-13155
7.8 HIGH

An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.

Dec 10, 2025
CVE-2025-13152
7.8 HIGH

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute …

Dec 10, 2025
CVE-2025-13125
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers.This …

Dec 10, 2025
CVE-2025-12046
7.8 HIGH

A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code …

Dec 10, 2025
CVE-2025-8110
8.8 HIGH KEV

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

Dec 10, 2025
CVE-2025-13127
3.5 LOW

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site …

Dec 10, 2025
CVE-2025-13184
9.8 CRITICAL

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions …

Dec 10, 2025
CVE-2024-2105
6.5 MEDIUM

An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.

Dec 10, 2025
CVE-2024-2104
8.8 HIGH

Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile …

Dec 10, 2025
CVE-2025-41358

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' …

Dec 10, 2025
CVE-2025-13953

Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method. Authentication is performed through …

Dec 10, 2025
CVE-2025-41732
9.8 CRITICAL

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full …

Dec 10, 2025
CVE-2025-41730
9.8 CRITICAL

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full …

Dec 10, 2025
CVE-2025-7073
7.8 HIGH

A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting …

Dec 10, 2025
CVE-2025-66675
8.2 HIGH

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, …

Dec 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.