CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8870
4.9 MEDIUM

On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153

Nov 14, 2025
CVE-2025-64446
9.8 CRITICAL KEV

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 …

Nov 14, 2025
CVE-2025-13170
7.3 HIGH

A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation …

Nov 14, 2025
CVE-2025-13169
7.3 HIGH

A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation …

Nov 14, 2025
CVE-2024-55016
6.5 MEDIUM

PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

Nov 14, 2025
CVE-2024-44640
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.

Nov 14, 2025
CVE-2024-44639
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php.

Nov 14, 2025
CVE-2024-44636
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.

Nov 14, 2025
CVE-2024-44635
6.1 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.

Nov 14, 2025
CVE-2024-44633
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.

Nov 14, 2025
CVE-2024-44632
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.

Nov 14, 2025
CVE-2024-44630
6.5 MEDIUM

Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, …

Nov 14, 2025
CVE-2024-42749
6.1 MEDIUM

Cross Site Scripting vulnerability in Alto CMS v.1.1.13 allows a local attacker to execute arbitrary code via a crafted script.

Nov 14, 2025
CVE-2025-13168
6.3 MEDIUM

A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py. This manipulation of the argument …

Nov 14, 2025
CVE-2024-21635
7.5 HIGH

Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of …

Nov 14, 2025
CVE-2025-9982
7.5 HIGH

A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers …

Nov 14, 2025
CVE-2025-12149

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, …

Nov 14, 2025
CVE-2025-11918
7.3 HIGH

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to …

Nov 14, 2025
CVE-2025-10018
4.8 MEDIUM

QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, …

Nov 14, 2025
CVE-2025-8855
8.1 HIGH

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting …

Nov 14, 2025
CVE-2025-11981
4.9 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, …

Nov 14, 2025
CVE-2025-11794
4.9 MEDIUM

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and …

Nov 14, 2025
CVE-2025-55073
5.4 MEDIUM

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin …

Nov 14, 2025
CVE-2025-55070
6.5 MEDIUM

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

Nov 14, 2025
CVE-2025-41436
3.1 LOW

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and …

Nov 14, 2025
CVE-2025-11776
4.3 MEDIUM

Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` …

Nov 14, 2025
CVE-2025-64444
7.2 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker …

Nov 14, 2025
CVE-2025-10686
7.2 HIGH

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and …

Nov 14, 2025
CVE-2025-13161
7.5 HIGH

IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system …

Nov 14, 2025
CVE-2025-13160
5.3 MEDIUM

IQ-Support developed by IQ Service International has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access specific APIs to obtain sensitive information …

Nov 14, 2025
CVE-2025-9479
4.3 MEDIUM

Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Nov 14, 2025
CVE-2025-13107
4.3 MEDIUM

Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Nov 14, 2025
CVE-2025-13102
4.3 MEDIUM

Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML …

Nov 14, 2025
CVE-2025-13097
5.4 MEDIUM

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Nov 14, 2025
CVE-2025-12904
7.2 HIGH

The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0.4.17 …

Nov 14, 2025
CVE-2024-9126
7.5 HIGH

Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific …

Nov 14, 2025
CVE-2024-7021
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Nov 14, 2025
CVE-2024-7017
7.5 HIGH

Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Nov 14, 2025
CVE-2024-13983
6.3 MEDIUM

Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. …

Nov 14, 2025
CVE-2024-13178
4.3 MEDIUM

Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Nov 14, 2025
CVE-2024-11920
4.3 MEDIUM

Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a …

Nov 14, 2025
CVE-2024-11919
4.3 MEDIUM

Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Nov 14, 2025
CVE-2025-64530
7.5 HIGH

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, …

Nov 13, 2025
CVE-2025-64754

Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window …

Nov 13, 2025
CVE-2025-64753
5.3 MEDIUM

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing …

Nov 13, 2025
CVE-2025-64752
6.8 MEDIUM

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature …

Nov 13, 2025
CVE-2025-64749
4.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST …

Nov 13, 2025
CVE-2025-64748
6.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search …

Nov 13, 2025
CVE-2025-64747
5.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 11.13.0 …

Nov 13, 2025
CVE-2025-47913
7.5 HIGH

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.

Nov 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.