CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2020-36852
9.1 CRITICAL

The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a …

Oct 1, 2025
CVE-2025-10659
9.8 CRITICAL

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs …

Sep 30, 2025
CVE-2025-56513
9.8 CRITICAL

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the …

Sep 30, 2025
CVE-2025-10725
9.9 CRITICAL

A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist …

Sep 30, 2025
CVE-2025-7493
9.1 CRITICAL

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the …

Sep 30, 2025
CVE-2025-34217
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and …

Sep 30, 2025
CVE-2025-9762
9.8 CRITICAL

The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the save_attachments function in all …

Sep 30, 2025
CVE-2025-8625
9.8 CRITICAL

The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function in versions 1.1 to 1.2. The plugin falls back …

Sep 30, 2025
CVE-2025-8120
9.8 CRITICAL

Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files of any type and extension without …

Sep 30, 2025
CVE-2025-7065
9.8 CRITICAL

Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without …

Sep 30, 2025
CVE-2025-7063
9.8 CRITICAL

Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without …

Sep 30, 2025
CVE-2025-59954
9.8 CRITICAL

Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext …

Sep 30, 2025
CVE-2025-11148
9.8 CRITICAL

All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted with locally, or via CI, to …

Sep 30, 2025
CVE-2024-58040
9.1 CRITICAL

Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.

Sep 30, 2025
CVE-2025-59937
9.1 CRITICAL

go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of the mail.Address values when a …

Sep 29, 2025
CVE-2025-54875
9.8 CRITICAL

FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker can create a new admin user when registration …

Sep 29, 2025
CVE-2025-54592
9.8 CRITICAL

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the …

Sep 29, 2025
CVE-2025-57266
9.8 CRITICAL

An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys …

Sep 29, 2025
CVE-2025-34224
9.1 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose a set of PHP scripts …

Sep 29, 2025
CVE-2025-34223
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) contain a default admin account and …

Sep 29, 2025
CVE-2025-34222
9.1 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose four admin routes – /admin/hp/cert_upload, …

Sep 29, 2025
CVE-2025-34221
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version 25.2.1518 (VA/SaaS deployments) expose every internal Docker container to …

Sep 29, 2025
CVE-2025-34218
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose internal Docker containers through the …

Sep 29, 2025
CVE-2025-34216
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated …

Sep 29, 2025
CVE-2025-34215
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (only VA deployments) expose an unauthenticated firmware-upload flow: …

Sep 29, 2025
CVE-2025-34212
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments) possess CI/CD weaknesses: the build pulls …

Sep 29, 2025
CVE-2025-34207
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.1049 and Application prior to 20.0.2786 (VA and SaaS deployments) configure the SSH client within Docker …

Sep 29, 2025
CVE-2025-34196
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for …

Sep 29, 2025
CVE-2025-56795
9.0 CRITICAL

Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields …

Sep 29, 2025
CVE-2024-13150
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software and Consulting Services fayton.Pro ERP allows SQL Injection.This issue …

Sep 29, 2025
CVE-2025-8868
9.8 CRITICAL

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the …

Sep 29, 2025
CVE-2025-48006
9.1 CRITICAL

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on …

Sep 29, 2025
CVE-2025-11126
9.8 CRITICAL

A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The manipulation results in hard-coded credentials. …

Sep 29, 2025
CVE-2025-59936
9.4 CRITICAL

get-jwks contains fetch utils for JWKS keys. In versions prior to 11.0.2, a vulnerability in get-jwks can lead to cache poisoning in the JWKS key-fetching …

Sep 27, 2025
CVE-2025-59934
9.4 CRITICAL

Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine …

Sep 26, 2025
CVE-2025-58384
10.0 CRITICAL

In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library in the Watchdoc administration interface.

Sep 26, 2025
CVE-2025-55187
9.9 CRITICAL

In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.

Sep 26, 2025
CVE-2025-60219
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allows Upload a Web Shell to a Web Server.This issue affects …

Sep 26, 2025
CVE-2025-60156
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: …

Sep 26, 2025
CVE-2025-11005
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through …

Sep 25, 2025
CVE-2025-59841
9.8 CRITICAL

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated …

Sep 25, 2025
CVE-2025-20363
9.0 CRITICAL

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, …

Sep 25, 2025
CVE-2025-20333
9.9 CRITICAL KEV

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could …

Sep 25, 2025
CVE-2025-59832
9.9 CRITICAL

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket …

Sep 25, 2025
CVE-2025-59823
9.9 CRITICAL

Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers …

Sep 25, 2025
CVE-2025-40836
9.8 CRITICAL

Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.

Sep 25, 2025
CVE-2025-10542
9.8 CRITICAL

iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these …

Sep 25, 2025
CVE-2025-59834
9.8 CRITICAL

ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server …

Sep 25, 2025
CVE-2025-27261
9.8 CRITICAL

Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.

Sep 25, 2025
CVE-2025-10894
9.6 CRITICAL

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via …

Sep 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.