CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-63562
6.3 MEDIUM

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions …

Oct 31, 2025
CVE-2025-63561
7.5 HIGH

Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where …

Oct 31, 2025
CVE-2025-60711
6.3 MEDIUM

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Oct 31, 2025
CVE-2025-10693

When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists …

Oct 31, 2025
CVE-2025-64349
8.8 HIGH

ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and …

Oct 31, 2025
CVE-2025-64348
7.1 HIGH

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with …

Oct 31, 2025
CVE-2025-63458
7.5 HIGH

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63454
7.5 HIGH

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-62618
8.0 HIGH

ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the …

Oct 31, 2025
CVE-2025-62267
6.1 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 …

Oct 31, 2025
CVE-2025-12547
3.7 LOW

A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of the file /login.jsp of the component Admin Login …

Oct 31, 2025
CVE-2025-12546
3.5 LOW

A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This manipulation …

Oct 31, 2025
CVE-2025-63459
7.5 HIGH

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-62264
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 …

Oct 31, 2025
CVE-2025-6075
5.5 MEDIUM

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

Oct 31, 2025
CVE-2025-63465
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63464
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63463
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63462
7.5 HIGH

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63461
7.5 HIGH

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63460
7.5 HIGH

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-59501
4.8 MEDIUM

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

Oct 31, 2025
CVE-2025-63469
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63468
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63467
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63466
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-29270
10.0 CRITICAL

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel …

Oct 31, 2025
CVE-2025-12554
9.8 CRITICAL

Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 31, 2025
CVE-2025-12553
9.8 CRITICAL

Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 31, 2025
CVE-2025-12552
9.8 CRITICAL

Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 31, 2025
CVE-2025-12509
8.4 HIGH

On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator …

Oct 31, 2025
CVE-2025-12508
8.4 HIGH

When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise …

Oct 31, 2025
CVE-2025-12507
8.8 HIGH

The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs …

Oct 31, 2025
CVE-2025-12357
6.3 MEDIUM

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers …

Oct 31, 2025
CVE-2025-64389

The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.

Oct 31, 2025
CVE-2025-64388

Denial of service of the web server through specific requests to this protocol

Oct 31, 2025
CVE-2025-64387

The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by …

Oct 31, 2025
CVE-2025-64385

The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the manufacturer’s software. Using the manufacturer's software, …

Oct 31, 2025
CVE-2025-64168
7.1 HIGH

Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team …

Oct 31, 2025
CVE-2025-61427
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execute arbitrary code in the context of a …

Oct 31, 2025
CVE-2025-60749
7.8 HIGH

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

Oct 31, 2025
CVE-2025-57108
9.8 CRITICAL

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are …

Oct 31, 2025
CVE-2025-57107
7.1 HIGH

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor …

Oct 31, 2025
CVE-2025-57106
7.5 HIGH

Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF …

Oct 31, 2025
CVE-2025-12501
7.5 HIGH

Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-service attacks (DoS). GameMaker users who use the …

Oct 31, 2025
CVE-2025-64386

The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be …

Oct 31, 2025
CVE-2025-12521
5.3 MEDIUM

The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify Tag HTML …

Oct 31, 2025
CVE-2025-12460

An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript …

Oct 31, 2025
CVE-2025-4952

Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized …

Oct 31, 2025
CVE-2025-36249
3.7 LOW

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to …

Oct 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.