CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11624
9.8 CRITICAL

Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or …

Oct 21, 2025
CVE-2025-10640
9.8 CRITICAL

An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side authentication checks to bypass the login prompt in …

Oct 21, 2025
CVE-2025-10916
9.1 CRITICAL

The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers …

Oct 21, 2025
CVE-2025-7851
9.8 CRITICAL

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

Oct 21, 2025
CVE-2025-6542
9.8 CRITICAL

An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

Oct 21, 2025
CVE-2025-61303
9.8 CRITICAL

Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a …

Oct 20, 2025
CVE-2025-8053
9.1 CRITICAL

Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low privilege user …

Oct 20, 2025
CVE-2025-55086
9.8 CRITICAL

In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server …

Oct 20, 2025
CVE-2025-9574
10.0 CRITICAL

Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects . All firmware versions with the Serial Number from 2000 …

Oct 20, 2025
CVE-2025-54957
9.8 CRITICAL

An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+ bitstream is …

Oct 20, 2025
CVE-2025-61455
9.8 CRITICAL

SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorporates unsanitized user inputs into SQL queries, allowing unauthenticated …

Oct 20, 2025
CVE-2025-61932
9.8 CRITICAL KEV

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code …

Oct 20, 2025
CVE-2025-11948
9.8 CRITICAL

Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby …

Oct 20, 2025
CVE-2025-11391
9.8 CRITICAL

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Oct 18, 2025
CVE-2017-20208
9.8 CRITICAL

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Oct 18, 2025
CVE-2017-20207
9.8 CRITICAL

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from …

Oct 18, 2025
CVE-2017-20206
9.8 CRITICAL

The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the …

Oct 18, 2025
CVE-2025-62645
9.9 CRITICAL

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform …

Oct 17, 2025
CVE-2025-62515
9.8 CRITICAL

pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() to deserialize …

Oct 17, 2025
CVE-2025-56316
9.8 CRITICAL

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized …

Oct 17, 2025
CVE-2025-56221
9.8 CRITICAL

A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.

Oct 17, 2025
CVE-2025-56218
9.8 CRITICAL

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Oct 17, 2025
CVE-2025-34282
9.1 CRITICAL

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG …

Oct 17, 2025
CVE-2025-62168
10.0 CRITICAL

Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows …

Oct 17, 2025
CVE-2025-62353
9.8 CRITICAL

A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside …

Oct 17, 2025
CVE-2025-60279
9.6 CRITICAL

A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users to send arbitrary requests to internal services via the API. …

Oct 17, 2025
CVE-2025-57567
9.1 CRITICAL

A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). …

Oct 17, 2025
CVE-2025-49655
9.8 CRITICAL

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded …

Oct 17, 2025
CVE-2023-28815
9.8 CRITICAL

Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges …

Oct 17, 2025
CVE-2023-28814
9.8 CRITICAL

Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers …

Oct 17, 2025
CVE-2025-55100
9.1 CRITICAL

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio10_sam_parse_func() when parsing …

Oct 17, 2025
CVE-2025-11849
9.3 CRITICAL

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth …

Oct 17, 2025
CVE-2025-11900
9.8 CRITICAL

The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the …

Oct 17, 2025
CVE-2025-11492
9.6 CRITICAL

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle …

Oct 16, 2025
CVE-2025-62586
9.8 CRITICAL

OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.

Oct 16, 2025
CVE-2025-61922
9.1 CRITICAL

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation …

Oct 16, 2025
CVE-2025-34516
9.8 CRITICAL

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia …

Oct 16, 2025
CVE-2025-34515
9.8 CRITICAL

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to …

Oct 16, 2025
CVE-2025-34513
9.8 CRITICAL

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. …

Oct 16, 2025
CVE-2025-9804
9.6 CRITICAL

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. …

Oct 16, 2025
CVE-2025-9152
9.8 CRITICAL

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. …

Oct 16, 2025
CVE-2025-10611
9.8 CRITICAL

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to …

Oct 16, 2025
CVE-2025-54539
9.8 CRITICAL

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up …

Oct 16, 2025
CVE-2025-41018
9.8 CRITICAL

SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' parameter in '/public.php'.

Oct 16, 2025
CVE-2025-62583
9.8 CRITICAL

Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

Oct 16, 2025
CVE-2025-55089
9.8 CRITICAL

In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in the FileX RAM disk driver. It …

Oct 16, 2025
CVE-2025-10850
9.8 CRITICAL

The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password …

Oct 16, 2025
CVE-2025-10742
9.8 CRITICAL

The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6. This is due to the …

Oct 16, 2025
CVE-2025-11832
9.8 CRITICAL

Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Flooding.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: …

Oct 15, 2025
CVE-2025-56749
9.4 CRITICAL

Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid …

Oct 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.