CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-35028
9.1 CRITICAL

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, …

Nov 30, 2025
CVE-2025-13793
4.3 MEDIUM

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the …

Nov 30, 2025
CVE-2025-13792
7.3 HIGH

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a …

Nov 30, 2025
CVE-2025-13791
6.3 MEDIUM

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation …

Nov 30, 2025
CVE-2025-13790
4.3 MEDIUM

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated …

Nov 30, 2025
CVE-2025-13789
6.3 MEDIUM

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results …

Nov 30, 2025
CVE-2025-13788
7.3 HIGH

A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. The manipulation of …

Nov 30, 2025
CVE-2025-13787
5.4 MEDIUM

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File …

Nov 30, 2025
CVE-2025-13786
7.3 HIGH

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content …

Nov 30, 2025
CVE-2025-13785
4.3 MEDIUM

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile …

Nov 30, 2025
CVE-2025-13784
2.4 LOW

A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the …

Nov 30, 2025
CVE-2025-13783
6.3 MEDIUM

A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/CommentadminController.class.php of the component CommentadminController. …

Nov 30, 2025
CVE-2025-66433
4.2 MEDIUM

HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed …

Nov 30, 2025
CVE-2025-66432
5.0 MEDIUM

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

Nov 30, 2025
CVE-2025-13782
7.3 HIGH

A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controller/SlideController.class.php of the component …

Nov 30, 2025
CVE-2025-66424
6.5 MEDIUM

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Nov 30, 2025
CVE-2025-66423
7.1 HIGH

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and …

Nov 30, 2025
CVE-2025-66422
4.3 MEDIUM

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Nov 30, 2025
CVE-2025-66421
5.4 MEDIUM

Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.69.

Nov 30, 2025
CVE-2025-66420
5.4 MEDIUM

Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and 6.0.67.

Nov 30, 2025
CVE-2025-13615
9.8 CRITICAL

The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the …

Nov 30, 2025
CVE-2025-6666
2.0 LOW

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. …

Nov 29, 2025
CVE-2025-66291
4.3 MEDIUM

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files …

Nov 29, 2025
CVE-2025-66290
4.3 MEDIUM

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required …

Nov 29, 2025
CVE-2025-66289
8.8 HIGH

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is …

Nov 29, 2025
CVE-2025-66225
8.8 HIGH

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted …

Nov 29, 2025
CVE-2025-66224
8.8 HIGH

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw in its mail configuration and …

Nov 29, 2025
CVE-2025-65892
6.1 MEDIUM

Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted …

Nov 29, 2025
CVE-2025-65540
6.1 MEDIUM

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are …

Nov 29, 2025
CVE-2025-66223

OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user …

Nov 29, 2025
CVE-2025-66221
5.3 MEDIUM

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there …

Nov 29, 2025
CVE-2025-66217
7.5 HIGH

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows …

Nov 29, 2025
CVE-2025-66216
9.8 CRITICAL

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message class of AIS-catcher. This …

Nov 29, 2025
CVE-2025-61915
6.0 MEDIUM

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group …

Nov 29, 2025
CVE-2025-58436
5.1 MEDIUM

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd …

Nov 29, 2025
CVE-2025-53939
6.3 MEDIUM

Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly …

Nov 29, 2025
CVE-2025-53900
6.5 MEDIUM

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could …

Nov 29, 2025
CVE-2025-53899
7.2 HIGH

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a …

Nov 29, 2025
CVE-2025-53897
6.8 MEDIUM

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from …

Nov 29, 2025
CVE-2025-53896
7.1 HIGH

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active …

Nov 29, 2025
CVE-2025-66219
9.8 CRITICAL

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in …

Nov 29, 2025
CVE-2025-66201
8.1 HIGH

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by passing specially crafted OpenAPI …

Nov 29, 2025
CVE-2025-66036
6.1 MEDIUM

Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cross-site scripting (XSS) in the input …

Nov 29, 2025
CVE-2025-66034
6.3 MEDIUM

fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script …

Nov 29, 2025
CVE-2025-66027
6.5 MEDIUM

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through …

Nov 29, 2025
CVE-2025-65113
6.5 MEDIUM

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging system allows …

Nov 29, 2025
CVE-2025-65112
9.4 CRITICAL

PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as …

Nov 29, 2025
CVE-2025-64715
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference …

Nov 29, 2025
CVE-2025-13683
6.5 MEDIUM

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

Nov 28, 2025
CVE-2025-12183

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

Nov 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.