CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64756
7.5 HIGH

Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command …

Nov 17, 2025
CVE-2025-64342

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it receives a connection request containing an …

Nov 17, 2025
CVE-2025-58407
7.4 HIGH

Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger …

Nov 17, 2025
CVE-2025-55059
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Nov 17, 2025
CVE-2025-55058
4.5 MEDIUM

CWE-20 Improper Input Validation

Nov 17, 2025
CVE-2025-55057
4.5 MEDIUM

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

Nov 17, 2025
CVE-2025-55056
4.8 MEDIUM

Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Nov 17, 2025
CVE-2025-55055
6.8 MEDIUM

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Nov 17, 2025
CVE-2025-34323
7.8 HIGH

Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The …

Nov 17, 2025
CVE-2025-34322
7.2 HIGH

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, …

Nov 17, 2025
CVE-2025-13297
7.3 HIGH

A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impacted element is an unknown function of the file /course/controller.php. …

Nov 17, 2025
CVE-2024-44657
6.5 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php.

Nov 17, 2025
CVE-2024-44653
6.5 MEDIUM

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.

Nov 17, 2025
CVE-2024-44651
6.5 MEDIUM

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.

Nov 17, 2025
CVE-2025-63918
6.2 MEDIUM

PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations.

Nov 17, 2025
CVE-2025-63917
7.1 HIGH

PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external …

Nov 17, 2025
CVE-2025-62519
7.2 HIGH

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in the main configuration update functionality of phpMyFAQ …

Nov 17, 2025
CVE-2025-58410
7.5 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This …

Nov 17, 2025
CVE-2025-13319
8.8 HIGH

An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via …

Nov 17, 2025
CVE-2025-13291
7.3 HIGH

A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the argument …

Nov 17, 2025
CVE-2025-13290
6.3 MEDIUM

A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /saveorder.php. Such …

Nov 17, 2025
CVE-2025-13193
5.5 MEDIUM

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect …

Nov 17, 2025
CVE-2024-46336
6.1 MEDIUM

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.

Nov 17, 2025
CVE-2024-46334
6.1 MEDIUM

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.

Nov 17, 2025
CVE-2024-44652
6.5 MEDIUM

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.

Nov 17, 2025
CVE-2024-44648
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.

Nov 17, 2025
CVE-2024-44647
6.1 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.

Nov 17, 2025
CVE-2024-44644
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.

Nov 17, 2025
CVE-2024-44641
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.

Nov 17, 2025
CVE-2025-65083
3.2 LOW

GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSign Desktop user selects …

Nov 17, 2025
CVE-2025-64046
6.1 MEDIUM

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.

Nov 17, 2025
CVE-2025-63916
8.1 HIGH

MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supplied file paths before passing …

Nov 17, 2025
CVE-2025-63748
8.8 HIGH

QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file …

Nov 17, 2025
CVE-2025-63747
9.8 CRITICAL

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the …

Nov 17, 2025
CVE-2025-63708
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows remote attackers to execute arbitrary JavaScript in victims' browsers. The vulnerability …

Nov 17, 2025
CVE-2025-13289
6.3 MEDIUM

A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The …

Nov 17, 2025
CVE-2025-13288
8.8 HIGH

A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno …

Nov 17, 2025
CVE-2025-4321

In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device …

Nov 17, 2025
CVE-2025-13287
6.3 MEDIUM

A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /index.php?page=categories. Executing manipulation of the argument …

Nov 17, 2025
CVE-2025-13286
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation …

Nov 17, 2025
CVE-2025-13285
7.3 HIGH

A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the …

Nov 17, 2025
CVE-2025-13280
7.3 HIGH

A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. …

Nov 17, 2025
CVE-2025-13279
6.3 MEDIUM

A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of …

Nov 17, 2025
CVE-2025-13278
6.3 MEDIUM

A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowed_book_search.php. Such manipulation of the …

Nov 17, 2025
CVE-2025-40936
7.8 HIGH

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Solid Edge (All versions < V226.00 Update 03). The affected applications …

Nov 17, 2025
CVE-2025-40834
5.7 MEDIUM

A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not properly neutralize the input. This could allow …

Nov 17, 2025
CVE-2025-13277
7.3 HIGH

A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of …

Nov 17, 2025
CVE-2025-11681
6.5 MEDIUM

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver …

Nov 17, 2025
CVE-2025-13276
7.3 HIGH

A vulnerability was detected in g33kyrash Online-Banking-System up to 12dbfa690e5af649fb72d2e5d3674e88d6743455. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument Username …

Nov 17, 2025
CVE-2025-13275
4.7 MEDIUM

A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This affects an unknown part of the file /admin/about.php. The manipulation leads to …

Nov 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.