CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6176
7.5 HIGH

Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection …

Oct 31, 2025
CVE-2025-52665
10.0 CRITICAL

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API …

Oct 31, 2025
CVE-2025-52664
8.8 HIGH

SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users

Oct 31, 2025
CVE-2025-52663
7.3 HIGH

A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to …

Oct 31, 2025
CVE-2025-48984
8.8 HIGH

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

Oct 31, 2025
CVE-2025-48983
9.9 CRITICAL

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an …

Oct 31, 2025
CVE-2025-48982
7.8 HIGH

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

Oct 31, 2025
CVE-2025-48980
6.5 MEDIUM

In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did …

Oct 31, 2025
CVE-2025-27208
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user …

Oct 31, 2025
CVE-2025-34298
8.8 HIGH

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to …

Oct 30, 2025
CVE-2025-34287
7.8 HIGH

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because …

Oct 30, 2025
CVE-2025-34286
7.2 HIGH

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters …

Oct 30, 2025
CVE-2025-34284
8.8 HIGH

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to …

Oct 30, 2025
CVE-2025-34283
6.5 MEDIUM

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user …

Oct 30, 2025
CVE-2025-34280
7.2 HIGH

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate …

Oct 30, 2025
CVE-2025-34278
5.4 MEDIUM

Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can …

Oct 30, 2025
CVE-2025-34277
9.8 CRITICAL

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to …

Oct 30, 2025
CVE-2025-34274
9.8 CRITICAL

Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. …

Oct 30, 2025
CVE-2025-34273
6.5 MEDIUM

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly …

Oct 30, 2025
CVE-2025-34272
6.5 MEDIUM

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an …

Oct 30, 2025
CVE-2025-34271
9.8 CRITICAL

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted …

Oct 30, 2025
CVE-2025-34270
4.9 MEDIUM

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during …

Oct 30, 2025
CVE-2025-34269

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60424.

Oct 30, 2025
CVE-2025-34249

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60425.

Oct 30, 2025
CVE-2025-34135
4.4 MEDIUM

Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable …

Oct 30, 2025
CVE-2025-34134
7.2 HIGH

Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled …

Oct 30, 2025
CVE-2024-58273
7.8 HIGH

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web …

Oct 30, 2025
CVE-2024-58272

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2023-7323.

Oct 30, 2025
CVE-2024-14009
7.2 HIGH

Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/configuration capability. …

Oct 30, 2025
CVE-2024-14008
7.2 HIGH

Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of user-supplied input allows an authenticated …

Oct 30, 2025
CVE-2024-14006
6.1 MEDIUM

Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without …

Oct 30, 2025
CVE-2024-14005
8.8 HIGH

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an …

Oct 30, 2025
CVE-2024-14004
8.8 HIGH

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data …

Oct 30, 2025
CVE-2024-14003
9.8 CRITICAL

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of …

Oct 30, 2025
CVE-2024-14002
5.5 MEDIUM

Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values …

Oct 30, 2025
CVE-2024-14001
5.4 MEDIUM

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report component. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2024-14000
5.4 MEDIUM

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report component. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2024-13999
9.8 CRITICAL

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of …

Oct 30, 2025
CVE-2024-13996
9.8 CRITICAL

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, …

Oct 30, 2025
CVE-2024-13995
8.8 HIGH

Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated …

Oct 30, 2025
CVE-2024-13994
9.8 CRITICAL

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can …

Oct 30, 2025
CVE-2024-13993
6.1 MEDIUM

Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. …

Oct 30, 2025
CVE-2023-7325

Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The …

Oct 30, 2025
CVE-2023-7323
5.4 MEDIUM

Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2023-7322
8.1 HIGH

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API …

Oct 30, 2025
CVE-2023-7321
5.4 MEDIUM

Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for …

Oct 30, 2025
CVE-2023-7319
5.4 MEDIUM

Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2023-7318
5.4 MEDIUM

Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expansion page. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2023-7317
8.8 HIGH

Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact …

Oct 30, 2025
CVE-2023-7316
5.4 MEDIUM

Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.