CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13151
9.8 CRITICAL

CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI Information and Telecommunication Industry and Trade …

Sep 18, 2025
CVE-2025-6237
9.8 CRITICAL

A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file deletion via the GET /api/v1/images/download/{bulk_download_item_name} endpoint. By manipulating …

Sep 18, 2025
CVE-2025-9083
9.8 CRITICAL

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a …

Sep 18, 2025
CVE-2025-8942
9.1 CRITICAL

The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending …

Sep 18, 2025
CVE-2025-5305
9.8 CRITICAL

The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading …

Sep 18, 2025
CVE-2025-23316
9.8 CRITICAL

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by …

Sep 17, 2025
CVE-2025-10644
9.4 CRITICAL

Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required …

Sep 17, 2025
CVE-2025-10643
9.1 CRITICAL

Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not …

Sep 17, 2025
CVE-2025-59352
9.8 CRITICAL

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send …

Sep 17, 2025
CVE-2025-59340
9.8 CRITICAL

jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical(), it is possible …

Sep 17, 2025
CVE-2025-59345
9.1 CRITICAL

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are …

Sep 17, 2025
CVE-2025-58766
9.0 CRITICAL

Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to …

Sep 17, 2025
CVE-2025-59304
9.8 CRITICAL

A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted HTTP …

Sep 17, 2025
CVE-2025-8077
9.8 CRITICAL

A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` …

Sep 17, 2025
CVE-2025-10439
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics Yordam Library Automation System allows SQL Injection.This issue affects …

Sep 17, 2025
CVE-2025-10156
9.8 CRITICAL

An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This …

Sep 17, 2025
CVE-2025-9242
9.8 CRITICAL KEV

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User …

Sep 17, 2025
CVE-2025-9972
9.8 CRITICAL

Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands …

Sep 17, 2025
CVE-2025-9971
9.8 CRITICAL

Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a …

Sep 17, 2025
CVE-2025-54391
9.1 CRITICAL

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The …

Sep 16, 2025
CVE-2025-57631
9.8 CRITICAL

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

Sep 16, 2025
CVE-2025-34186
9.8 CRITICAL

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing …

Sep 16, 2025
CVE-2025-34184
9.8 CRITICAL

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands …

Sep 16, 2025
CVE-2025-56557
9.1 CRITICAL

An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Matter protocol.

Sep 16, 2025
CVE-2025-59334
9.6 CRITICAL

Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authenticity of …

Sep 16, 2025
CVE-2025-10492
9.8 CRITICAL

A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on …

Sep 16, 2025
CVE-2025-41243
10.0 CRITICAL

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: …

Sep 16, 2025
CVE-2024-13149
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability …

Sep 16, 2025
CVE-2025-57119
9.8 CRITICAL

An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function

Sep 16, 2025
CVE-2025-55113
9.0 CRITICAL

If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 …

Sep 16, 2025
CVE-2025-55109
9.0 CRITICAL

An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb …

Sep 16, 2025
CVE-2025-7744
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dolusoft Omaspot allows SQL Injection.This issue affects Omaspot: before 12.09.2025.

Sep 16, 2025
CVE-2025-7743
9.6 CRITICAL

Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation.This issue affects Omaspot: before 12.09.2025.

Sep 16, 2025
CVE-2025-4688
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection.This issue affects …

Sep 16, 2025
CVE-2025-43362
9.8 CRITICAL

The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may …

Sep 15, 2025
CVE-2025-43359
9.8 CRITICAL

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS …

Sep 15, 2025
CVE-2025-43347
9.8 CRITICAL

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS …

Sep 15, 2025
CVE-2025-43343
9.8 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, …

Sep 15, 2025
CVE-2025-43342
9.8 CRITICAL

A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, …

Sep 15, 2025
CVE-2025-31255
9.8 CRITICAL

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, …

Sep 15, 2025
CVE-2025-57118
9.8 CRITICAL

An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php

Sep 15, 2025
CVE-2025-58748
9.8 CRITICAL

Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify …

Sep 15, 2025
CVE-2025-57174
9.8 CRITICAL

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening …

Sep 15, 2025
CVE-2025-58046
9.8 CRITICAL

Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to remote code …

Sep 15, 2025
CVE-2025-58045
9.8 CRITICAL

Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch introduced to mitigate DB2 JDBC deserialization remote …

Sep 15, 2025
CVE-2025-52053
9.8 CRITICAL

TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attackers to …

Sep 15, 2025
CVE-2025-46408
9.8 CRITICAL

An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation.

Sep 15, 2025
CVE-2025-59361
9.8 CRITICAL

The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote …

Sep 15, 2025
CVE-2025-59360
9.8 CRITICAL

The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote …

Sep 15, 2025
CVE-2025-59359
9.8 CRITICAL

The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote …

Sep 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.