CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13835
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Stored XSS.This issue affects Arconix Shortcodes: from n/a …

Dec 1, 2025
CVE-2025-13653
4.3 MEDIUM

In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use …

Dec 1, 2025
CVE-2025-7007
7.5 HIGH

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to …

Dec 1, 2025
CVE-2025-65794

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Dec 1, 2025
CVE-2025-65793

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Dec 1, 2025
CVE-2025-65408
6.5 MEDIUM

A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a …

Dec 1, 2025
CVE-2025-65406
6.5 MEDIUM

A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Dec 1, 2025
CVE-2025-8351
9.0 CRITICAL

Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avast Antivirus on MacOS when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of …

Dec 1, 2025
CVE-2025-65405
6.5 MEDIUM

A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC …

Dec 1, 2025
CVE-2025-65404
6.5 MEDIUM

A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 …

Dec 1, 2025
CVE-2025-65403
6.5 MEDIUM

A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Dec 1, 2025
CVE-2025-64775
7.5 HIGH

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, …

Dec 1, 2025
CVE-2025-63535
9.6 CRITICAL

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in …

Dec 1, 2025
CVE-2025-63534
8.5 HIGH

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component. The application fails to properly sanitize or encode …

Dec 1, 2025
CVE-2025-63533
8.5 HIGH

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and rprofile.php components. The application fails to properly sanitize …

Dec 1, 2025
CVE-2025-63532
9.6 CRITICAL

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in …

Dec 1, 2025
CVE-2025-63095
6.5 MEDIUM

Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Dec 1, 2025
CVE-2025-61229
7.8 HIGH

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script …

Dec 1, 2025
CVE-2025-61228
7.8 HIGH

An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanism

Dec 1, 2025
CVE-2025-57489
8.1 HIGH

Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of …

Dec 1, 2025
CVE-2025-55222
8.6 HIGH

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A …

Dec 1, 2025
CVE-2025-55221
8.6 HIGH

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A …

Dec 1, 2025
CVE-2025-54851
7.5 HIGH

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted …

Dec 1, 2025
CVE-2025-54850
7.5 HIGH

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted …

Dec 1, 2025
CVE-2025-54849
7.5 HIGH

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted …

Dec 1, 2025
CVE-2025-54848
7.5 HIGH

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted …

Dec 1, 2025
CVE-2025-3500
9.0 CRITICAL

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

Dec 1, 2025
CVE-2025-26858
8.6 HIGH

A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted set of network packets can lead …

Dec 1, 2025
CVE-2025-23417
8.6 HIGH

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can …

Dec 1, 2025
CVE-2025-20085
7.2 HIGH

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can …

Dec 1, 2025
CVE-2025-13829

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * …

Dec 1, 2025
CVE-2025-11699
7.1 HIGH

nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid …

Dec 1, 2025
CVE-2025-10101
8.1 HIGH

Heap-based Buffer Overflow, Out-of-bounds Write vulnerability in Avast Antivirus on MacOS of a crafted Mach-O file may allow Local Execution of Code or Denial of …

Dec 1, 2025
CVE-2024-53684
7.5 HIGH

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to …

Dec 1, 2025
CVE-2024-49572
7.2 HIGH

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to …

Dec 1, 2025
CVE-2024-48894
5.9 MEDIUM

A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to a disclosure …

Dec 1, 2025
CVE-2024-48882
8.6 HIGH

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to …

Dec 1, 2025
CVE-2024-45370
7.3 HIGH

An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System 2.6.1.0. A specially crafted database record can lead to …

Dec 1, 2025
CVE-2024-39148
8.1 HIGH

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as …

Dec 1, 2025
CVE-2024-32388
5.3 MEDIUM

Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the …

Dec 1, 2025
CVE-2024-32384
6.8 MEDIUM

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows …

Dec 1, 2025
CVE-2025-64030
5.4 MEDIUM

Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter …

Dec 1, 2025
CVE-2025-63531
10.0 CRITICAL

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in …

Dec 1, 2025
CVE-2025-63529
6.1 MEDIUM

A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier …

Dec 1, 2025
CVE-2025-63528
8.5 HIGH

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php component. The application fails to properly sanitize or encode …

Dec 1, 2025
CVE-2025-63527
8.5 HIGH

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and hprofile.php components. The application fails to properly sanitize …

Dec 1, 2025
CVE-2025-63526
8.5 HIGH

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The application fails to properly sanitize or encode user-supplied …

Dec 1, 2025
CVE-2025-63525
9.6 CRITICAL

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.

Dec 1, 2025
CVE-2025-63523
6.5 MEDIUM

FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the …

Dec 1, 2025
CVE-2025-63522
4.6 MEDIUM

Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function

Dec 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.