CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-63293
6.5 MEDIUM

FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets …

Nov 3, 2025
CVE-2025-12657
5.0 MEDIUM

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of …

Nov 3, 2025
CVE-2025-63593
6.1 MEDIUM

Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).

Nov 3, 2025
CVE-2025-50735
7.5 HIGH

Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing …

Nov 3, 2025
CVE-2025-12642
9.1 CRITICAL

lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful exploitation may …

Nov 3, 2025
CVE-2025-12531
7.1 HIGH

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could …

Nov 3, 2025
CVE-2025-8558
5.4 MEDIUM

Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent …

Nov 3, 2025
CVE-2025-45959

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Nov 3, 2025
CVE-2025-63441
7.3 HIGH

Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.

Nov 3, 2025
CVE-2025-50363
5.4 MEDIUM

Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.

Nov 3, 2025
CVE-2025-12463
9.8 CRITICAL

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on …

Nov 3, 2025
CVE-2025-11953
9.8 CRITICAL KEV

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that …

Nov 3, 2025
CVE-2025-10280
7.1 HIGH

IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions …

Nov 3, 2025
CVE-2025-63453
9.8 CRITICAL

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.

Nov 3, 2025
CVE-2025-63452
9.4 CRITICAL

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.

Nov 3, 2025
CVE-2025-63451
9.8 CRITICAL

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.

Nov 3, 2025
CVE-2025-63450
5.4 MEDIUM

Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.

Nov 3, 2025
CVE-2025-63449
5.4 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.

Nov 3, 2025
CVE-2025-63448
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.

Nov 3, 2025
CVE-2025-63447
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.

Nov 3, 2025
CVE-2025-63446
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.

Nov 3, 2025
CVE-2025-60785
8.8 HIGH

A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a crafted …

Nov 3, 2025
CVE-2025-60503
8.7 HIGH

A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper …

Nov 3, 2025
CVE-2025-36093
4.8 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in …

Nov 3, 2025
CVE-2025-36092
6.5 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper …

Nov 3, 2025
CVE-2025-36091
4.3 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due …

Nov 3, 2025
CVE-2025-11761
7.8 HIGH

A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. …

Nov 3, 2025
CVE-2025-8900
9.8 CRITICAL

The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. This is due to the plugin allowing …

Nov 3, 2025
CVE-2025-63443
5.4 MEDIUM

School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.

Nov 3, 2025
CVE-2025-63442
4.6 MEDIUM

Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, …

Nov 3, 2025
CVE-2025-60892
6.8 MEDIUM

An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub …

Nov 3, 2025
CVE-2025-45663
6.5 MEDIUM

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

Nov 3, 2025
CVE-2025-29699
6.5 MEDIUM

NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

Nov 3, 2025
CVE-2024-51317
6.5 MEDIUM

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

Nov 3, 2025
CVE-2025-64294
5.3 MEDIUM

Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through …

Nov 3, 2025
CVE-2025-40107

In the Linux kernel, the following vulnerability has been resolved: can: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled This …

Nov 3, 2025
CVE-2025-12626
4.3 MEDIUM

A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the …

Nov 3, 2025
CVE-2025-0987
9.9 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection.This issue affects CVLand: from 2.1.0 through 20251103. NOTE: The vendor …

Nov 3, 2025
CVE-2025-48397
7.1 HIGH

The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch …

Nov 3, 2025
CVE-2025-48396
8.3 HIGH

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the …

Nov 3, 2025
CVE-2025-12623
3.1 LOW

A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this issue is some unknown functionality of the file fuint-application/src/main/java/com/fuint/module/clientApi/controller/ClientSignController.java of the component …

Nov 3, 2025
CVE-2025-12622
8.8 HIGH

A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument …

Nov 3, 2025
CVE-2025-12619
8.8 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in …

Nov 3, 2025
CVE-2025-12618
8.8 HIGH

A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads …

Nov 3, 2025
CVE-2025-12503
6.5 MEDIUM

EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database …

Nov 3, 2025
CVE-2025-12617
7.3 HIGH

A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument …

Nov 3, 2025
CVE-2025-12616
3.7 LOW

A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in …

Nov 3, 2025
CVE-2025-12615
5.0 MEDIUM

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of …

Nov 3, 2025
CVE-2025-12614
4.7 MEDIUM

A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of …

Nov 3, 2025
CVE-2025-12612
6.3 MEDIUM

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The …

Nov 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.