CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59827
9.8 CRITICAL

Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign …

Sep 24, 2025
CVE-2025-59828
9.8 CRITICAL

Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-executed …

Sep 24, 2025
CVE-2025-57321
9.8 CRITICAL

A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, …

Sep 24, 2025
CVE-2025-57347
9.8 CRITICAL

A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConflict function, which fails to properly sanitize user-supplied input during …

Sep 24, 2025
CVE-2025-52906
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through …

Sep 24, 2025
CVE-2025-10890
9.1 CRITICAL

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10585
9.8 CRITICAL KEV

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-56819
9.8 CRITICAL

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

Sep 24, 2025
CVE-2025-27034
9.8 CRITICAL

Memory corruption while selecting the PLMN from SOR failed list.

Sep 24, 2025
CVE-2025-21483
9.8 CRITICAL

Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.

Sep 24, 2025
CVE-2025-9054
9.8 CRITICAL

The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Sep 24, 2025
CVE-2025-41715
9.8 CRITICAL

The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to gain unauthorized access and potentially compromise it.

Sep 24, 2025
CVE-2025-59545
9.0 CRITICAL

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of …

Sep 23, 2025
CVE-2025-4993
9.1 CRITICAL

Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, …

Sep 23, 2025
CVE-2025-1255
9.1 CRITICAL

Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.2.0 before 7.3.0.9.

Sep 23, 2025
CVE-2025-9846
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command Injection.This issue affects Inka.Net: before 6.7.1.

Sep 23, 2025
CVE-2025-10412
9.8 CRITICAL

The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured …

Sep 23, 2025
CVE-2025-10147
9.8 CRITICAL

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all …

Sep 23, 2025
CVE-2025-9588
10.0 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection.This issue …

Sep 23, 2025
CVE-2025-9321
9.8 CRITICAL

The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input validation …

Sep 23, 2025
CVE-2025-26399
9.8 CRITICAL KEV

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker …

Sep 23, 2025
CVE-2025-59528
10.0 CRITICAL

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code …

Sep 22, 2025
CVE-2025-59434
9.6 CRITICAL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated vulnerability …

Sep 22, 2025
CVE-2025-58255
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Images custom-post-types-image allows Code Injection.This issue affects Custom Post Type Images: from n/a through <= …

Sep 22, 2025
CVE-2025-57441
9.8 CRITICAL

The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker …

Sep 22, 2025
CVE-2025-57437
9.8 CRITICAL

The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive …

Sep 22, 2025
CVE-2025-57602
9.8 CRITICAL

Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote …

Sep 22, 2025
CVE-2025-57601
9.8 CRITICAL

AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devices. When an …

Sep 22, 2025
CVE-2025-57432
9.8 CRITICAL

Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, …

Sep 22, 2025
CVE-2025-35042
9.8 CRITICAL

Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this …

Sep 22, 2025
CVE-2025-56074
9.8 CRITICAL

A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary …

Sep 22, 2025
CVE-2025-6544
9.8 CRITICAL

A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises from improper …

Sep 21, 2025
CVE-2025-40925
9.1 CRITICAL

Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with a counter, the epoch time, …

Sep 20, 2025
CVE-2025-59431
9.8 CRITICAL

MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It …

Sep 19, 2025
CVE-2025-10568
9.8 CRITICAL

HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to address the potential vulnerability.

Sep 19, 2025
CVE-2025-34206
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers …

Sep 19, 2025
CVE-2025-34205
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (VA and SaaS deployments) contains dangerous PHP dead code …

Sep 19, 2025
CVE-2025-34204
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple Docker containers that run primary application processes (for example PHP …

Sep 19, 2025
CVE-2025-34203
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior to 20.0.2614 (VA and SaaS deployments) contain multiple Docker containers …

Sep 19, 2025
CVE-2025-34198
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.2368 (VA and SaaS deployments) contain shared, hardcoded SSH host …

Sep 19, 2025
CVE-2025-34195
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments) contain a remote code execution vulnerability …

Sep 19, 2025
CVE-2025-34193
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLauncher.exe) that …

Sep 19, 2025
CVE-2025-34192
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to 20.0.2140 (macOS/Linux client deployments) are built against OpenSSL 1.0.2h-fips …

Sep 19, 2025
CVE-2025-48703
9.0 CRITICAL KEV

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a …

Sep 19, 2025
CVE-2025-57644
9.1 CRITICAL

Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting …

Sep 19, 2025
CVE-2025-5948
9.8 CRITICAL

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is …

Sep 19, 2025
CVE-2025-10690
9.8 CRITICAL

The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the …

Sep 19, 2025
CVE-2025-10035
10.0 CRITICAL KEV

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary …

Sep 18, 2025
CVE-2025-54807
9.8 CRITICAL

The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, …

Sep 18, 2025
CVE-2025-30519
9.8 CRITICAL

Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to …

Sep 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.