CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13425

A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in …

Nov 20, 2025
CVE-2024-31405

Rejected reason: Voluntarily withdrawn

Nov 20, 2025
CVE-2025-65226
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.

Nov 20, 2025
CVE-2025-65223
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.

Nov 20, 2025
CVE-2025-65222
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.

Nov 20, 2025
CVE-2025-65221
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.

Nov 20, 2025
CVE-2025-65220
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.

Nov 20, 2025
CVE-2025-64984
6.1 MEDIUM

Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux …

Nov 20, 2025
CVE-2025-62346
6.8 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious …

Nov 20, 2025
CVE-2025-60799
6.1 MEDIUM

phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting …

Nov 20, 2025
CVE-2025-60798
6.5 MEDIUM

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery …

Nov 20, 2025
CVE-2025-60797
6.5 MEDIUM

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter …

Nov 20, 2025
CVE-2025-60796
6.1 MEDIUM

phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper …

Nov 20, 2025
CVE-2025-60794
6.5 MEDIUM

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates …

Nov 20, 2025
CVE-2025-5092
6.4 MEDIUM

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to …

Nov 20, 2025
CVE-2025-41076
6.5 MEDIUM

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of …

Nov 20, 2025
CVE-2025-41075
7.5 HIGH

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation …

Nov 20, 2025
CVE-2025-41074
7.5 HIGH

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation …

Nov 20, 2025
CVE-2025-40605
5.3 MEDIUM

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences …

Nov 20, 2025
CVE-2025-40604
9.8 CRITICAL

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or …

Nov 20, 2025
CVE-2025-40601
7.5 HIGH

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an …

Nov 20, 2025
CVE-2025-13469
2.4 LOW

A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the …

Nov 20, 2025
CVE-2025-13468
5.4 MEDIUM

A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete …

Nov 20, 2025
CVE-2025-13451
7.3 HIGH

A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the …

Nov 20, 2025
CVE-2025-13450
3.5 LOW

A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipulation of the argument f_name …

Nov 20, 2025
CVE-2025-13449
7.3 HIGH

A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument …

Nov 20, 2025
CVE-2025-13446
8.8 HIGH

A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone/time leads …

Nov 20, 2025
CVE-2025-13445
8.8 HIGH

A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executing a manipulation of the argument list …

Nov 20, 2025
CVE-2025-13443
5.4 MEDIUM

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of …

Nov 20, 2025
CVE-2025-13442
7.3 HIGH

A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. …

Nov 20, 2025
CVE-2025-13435
5.6 MEDIUM

A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of the file /resty-httpclient/src/main/java/cn/dreampie/client/HttpClient.java of the component HttpClient …

Nov 20, 2025
CVE-2025-13434
5.3 MEDIUM

A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file Hush\hush-lib\hush\Util.php of the component HTTP …

Nov 20, 2025
CVE-2025-13433
7.0 HIGH

A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the file C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe of the …

Nov 20, 2025
CVE-2025-12778
5.3 MEDIUM

The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability …

Nov 20, 2025
CVE-2025-12502
6.8 MEDIUM

The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users such …

Nov 20, 2025
CVE-2025-12414

An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were …

Nov 20, 2025
CVE-2025-11676

Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated adjacent attackers to perform DoS attack. This issue affects TL-WR940N …

Nov 20, 2025
CVE-2025-0645
7.2 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Accessing Functionality Not Properly Constrained …

Nov 20, 2025
CVE-2025-0643
7.2 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows …

Nov 20, 2025
CVE-2025-13424
4.7 MEDIUM

A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_product.php. The manipulation of the argument …

Nov 20, 2025
CVE-2025-13423
4.7 MEDIUM

A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing …

Nov 20, 2025
CVE-2025-13422
7.3 HIGH

A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown function of the file /dashboard/admin/change_s_pwd.php. Performing manipulation of …

Nov 20, 2025
CVE-2025-4042

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 19, 2025
CVE-2025-13421
7.3 HIGH

A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown function of the file /src/store/NoticeStore.php. Such manipulation of …

Nov 19, 2025
CVE-2025-13420
7.3 HIGH

A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of …

Nov 19, 2025
CVE-2025-13415
3.5 LOW

A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image Handler. …

Nov 19, 2025
CVE-2025-11884

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uCMDB allows Stored XSS. The vulnerability could allow an attacker …

Nov 19, 2025
CVE-2025-11001
7.8 HIGH

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction …

Nov 19, 2025
CVE-2025-63719
7.3 HIGH

Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username.

Nov 19, 2025
CVE-2025-63371
7.5 HIGH

Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting …

Nov 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.