CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60691
8.8 HIGH

A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from …

Nov 13, 2025
CVE-2025-60690
8.8 HIGH

A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to …

Nov 13, 2025
CVE-2025-20355
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a …

Nov 13, 2025
CVE-2025-20353
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against …

Nov 13, 2025
CVE-2025-20349
6.3 MEDIUM

A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container as …

Nov 13, 2025
CVE-2025-20346
4.3 MEDIUM

A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should require Administrator privileges. The attacker would need valid …

Nov 13, 2025
CVE-2025-20341
8.8 HIGH

A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability …

Nov 13, 2025
CVE-2025-13121
7.3 HIGH

A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/StoreController.php of the component API Endpoint. Such …

Nov 13, 2025
CVE-2025-11538
6.8 MEDIUM

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to …

Nov 13, 2025
CVE-2025-64718
5.3 MEDIUM

js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the …

Nov 13, 2025
CVE-2025-64717
9.8 CRITICAL

ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation …

Nov 13, 2025
CVE-2025-64714
5.8 MEDIUM

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated …

Nov 13, 2025
CVE-2025-64703
6.3 MEDIUM

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations by Python code in tool module, …

Nov 13, 2025
CVE-2025-64525
6.5 MEDIUM

Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, …

Nov 13, 2025
CVE-2025-64511
7.4 HIGH

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python …

Nov 13, 2025
CVE-2025-62484
8.1 HIGH

Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network …

Nov 13, 2025
CVE-2025-60689
5.4 MEDIUM

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because …

Nov 13, 2025
CVE-2025-60688
6.5 MEDIUM

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads …

Nov 13, 2025
CVE-2025-60687
6.5 MEDIUM

An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter …

Nov 13, 2025
CVE-2025-60686
5.1 MEDIUM

A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs …

Nov 13, 2025
CVE-2025-60685
5.1 MEDIUM

A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using …

Nov 13, 2025
CVE-2025-60684
6.5 MEDIUM

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface …

Nov 13, 2025
CVE-2025-60683
6.5 MEDIUM

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface …

Nov 13, 2025
CVE-2025-60682
6.5 MEDIUM

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update …

Nov 13, 2025
CVE-2025-52186
6.5 MEDIUM

Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed directly to …

Nov 13, 2025
CVE-2025-13120
5.3 MEDIUM

A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use …

Nov 13, 2025
CVE-2025-64741
8.1 HIGH

Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

Nov 13, 2025
CVE-2025-64740
7.5 HIGH

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of …

Nov 13, 2025
CVE-2025-64739
4.3 MEDIUM

External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.

Nov 13, 2025
CVE-2025-64738
5.0 MEDIUM

External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of …

Nov 13, 2025
CVE-2025-62483
5.3 MEDIUM

Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network …

Nov 13, 2025
CVE-2025-62482
4.3 MEDIUM

Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.

Nov 13, 2025
CVE-2025-30669
4.8 MEDIUM

Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.

Nov 13, 2025
CVE-2025-30662
6.6 MEDIUM

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may …

Nov 13, 2025
CVE-2025-13119
4.3 MEDIUM

A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack …

Nov 13, 2025
CVE-2025-13118
6.3 MEDIUM

A vulnerability was detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The …

Nov 13, 2025
CVE-2025-13117
5.4 MEDIUM

A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder of the file …

Nov 13, 2025
CVE-2025-41069

Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to access or modify unauthorized resources by manipulating requests using …

Nov 13, 2025
CVE-2025-13116
5.4 MEDIUM

A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserOrder. Executing manipulation of …

Nov 13, 2025
CVE-2025-13115
4.3 MEDIUM

A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the …

Nov 13, 2025
CVE-2025-13114
6.3 MEDIUM

A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /cart/update/attr. Such manipulation leads to improper authorization. …

Nov 13, 2025
CVE-2025-40681

Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a …

Nov 13, 2025
CVE-2025-12818
5.9 MEDIUM

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and …

Nov 13, 2025
CVE-2025-12817
3.1 LOW

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any …

Nov 13, 2025
CVE-2025-12765
7.5 HIGH

pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.

Nov 13, 2025
CVE-2025-12764
7.5 HIGH

pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in …

Nov 13, 2025
CVE-2025-12763
6.8 MEDIUM

pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True …

Nov 13, 2025
CVE-2025-12762
9.1 CRITICAL

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from …

Nov 13, 2025
CVE-2025-12377
4.3 MEDIUM

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Nov 13, 2025
CVE-2025-7704
5.4 MEDIUM

Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability

Nov 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.