CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53521
9.8 CRITICAL KEV

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions …

Oct 15, 2025
CVE-2025-55081
9.1 CRITICAL

In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the …

Oct 15, 2025
CVE-2025-9967
9.8 CRITICAL

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This …

Oct 15, 2025
CVE-2025-10294
9.8 CRITICAL

The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the …

Oct 15, 2025
CVE-2025-10041
9.8 CRITICAL

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db() function in all …

Oct 15, 2025
CVE-2025-49553
9.3 CRITICAL

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious …

Oct 14, 2025
CVE-2025-34267
9.9 CRITICAL

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to …

Oct 14, 2025
CVE-2025-59287
9.8 CRITICAL KEV

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Oct 14, 2025
CVE-2025-55315
9.9 CRITICAL

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

Oct 14, 2025
CVE-2025-49708
9.9 CRITICAL

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

Oct 14, 2025
CVE-2025-9064
9.1 CRITICAL

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file …

Oct 14, 2025
CVE-2025-9063
9.8 CRITICAL

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView …

Oct 14, 2025
CVE-2025-7328
9.8 CRITICAL

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result …

Oct 14, 2025
CVE-2025-11721
9.8 CRITICAL

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this …

Oct 14, 2025
CVE-2025-11719
9.8 CRITICAL

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. …

Oct 14, 2025
CVE-2025-11717
9.1 CRITICAL

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last …

Oct 14, 2025
CVE-2025-11710
9.8 CRITICAL

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. …

Oct 14, 2025
CVE-2025-11709
9.8 CRITICAL

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability …

Oct 14, 2025
CVE-2025-11708
9.8 CRITICAL

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

Oct 14, 2025
CVE-2025-10610
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure allows …

Oct 14, 2025
CVE-2025-40771
9.8 CRITICAL

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP …

Oct 14, 2025
CVE-2025-40765
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This …

Oct 14, 2025
CVE-2025-46581
9.8 CRITICAL

ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

Oct 14, 2025
CVE-2025-42937
9.8 CRITICAL

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system …

Oct 14, 2025
CVE-2025-42910
9.0 CRITICAL

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include …

Oct 14, 2025
CVE-2025-37729
9.1 CRITICAL

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating …

Oct 13, 2025
CVE-2025-6919
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development Technologies Aykome License Tracking System allows …

Oct 13, 2025
CVE-2025-9976
9.0 CRITICAL

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to …

Oct 13, 2025
CVE-2025-27258
9.8 CRITICAL

Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

Oct 13, 2025
CVE-2025-6439
9.8 CRITICAL

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion …

Oct 11, 2025
CVE-2025-6553
9.8 CRITICAL

The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout() function in all …

Oct 11, 2025
CVE-2025-11533
9.8 CRITICAL

The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_register() …

Oct 11, 2025
CVE-2025-61929
9.6 CRITICAL

Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation …

Oct 10, 2025
CVE-2025-60306
9.9 CRITICAL

code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.

Oct 10, 2025
CVE-2025-60269
9.4 CRITICAL

JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.

Oct 10, 2025
CVE-2025-60307
9.8 CRITICAL

code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass …

Oct 10, 2025
CVE-2025-59286
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

Oct 9, 2025
CVE-2025-59272
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

Oct 9, 2025
CVE-2025-59252
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

Oct 9, 2025
CVE-2025-59246
9.8 CRITICAL

Azure Entra ID Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-59218
9.6 CRITICAL

Azure Entra ID Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-55321
9.3 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.

Oct 9, 2025
CVE-2025-35051
9.8 CRITICAL

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with …

Oct 9, 2025
CVE-2025-35050
9.8 CRITICAL

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. …

Oct 9, 2025
CVE-2025-60316
9.4 CRITICAL

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.

Oct 9, 2025
CVE-2025-59978
9.0 CRITICAL

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly …

Oct 9, 2025
CVE-2025-10284
9.6 CRITICAL

BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code …

Oct 9, 2025
CVE-2025-10283
9.6 CRITICAL

BBOT's gitdumper module could be abused to execute commands through a malicious git repository.

Oct 9, 2025
CVE-2025-56683
9.6 CRITICAL

A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to execute arbitrary code via injecting arbitrary Javascript into a crafted …

Oct 9, 2025
CVE-2025-11539
9.9 CRITICAL

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv …

Oct 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.