CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27225
7.5 HIGH

TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.

Oct 27, 2025
CVE-2025-27224
9.8 CRITICAL

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path …

Oct 27, 2025
CVE-2025-27223
7.5 HIGH

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key …

Oct 27, 2025
CVE-2025-27222
8.6 HIGH

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path …

Oct 27, 2025
CVE-2025-12299
4.3 MEDIUM

A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of …

Oct 27, 2025
CVE-2025-12298
4.3 MEDIUM

A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the file /editcategory.php. The manipulation of the argument …

Oct 27, 2025
CVE-2025-12297
4.3 MEDIUM

A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. …

Oct 27, 2025
CVE-2025-12296
4.7 MEDIUM

A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Update Handler. The manipulation …

Oct 27, 2025
CVE-2025-12295
6.6 MEDIUM

A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler. Executing manipulation can …

Oct 27, 2025
CVE-2025-61247
8.2 HIGH

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php.

Oct 27, 2025
CVE-2025-60791
6.2 MEDIUM

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory after a …

Oct 27, 2025
CVE-2025-60425
8.6 HIGH

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session …

Oct 27, 2025
CVE-2025-60424
7.6 HIGH

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

Oct 27, 2025
CVE-2025-34133

Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated request that contains a …

Oct 27, 2025
CVE-2025-12294
4.7 MEDIUM

A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /delete_category.php. Performing manipulation of the …

Oct 27, 2025
CVE-2025-12293
7.3 HIGH

A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the file /category.php. Such manipulation of the argument …

Oct 27, 2025
CVE-2025-12292
7.3 HIGH

A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file /index.php. This manipulation of the argument Username …

Oct 27, 2025
CVE-2025-12291
4.7 MEDIUM

A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file /admin/index.php?add_product of the …

Oct 27, 2025
CVE-2025-10023
6.2 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules) allows Stored XSS by users …

Oct 27, 2025
CVE-2023-49440
8.8 HIGH

AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."

Oct 27, 2025
CVE-2023-37749
5.3 MEDIUM

Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.

Oct 27, 2025
CVE-2025-61482
7.2 HIGH

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By …

Oct 27, 2025
CVE-2025-52268
7.5 HIGH

StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tokens.

Oct 27, 2025
CVE-2025-52264
8.0 HIGH

StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.

Oct 27, 2025
CVE-2025-36121
5.4 MEDIUM

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed …

Oct 27, 2025
CVE-2025-34292

Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the …

Oct 27, 2025
CVE-2025-26862

Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.

Oct 27, 2025
CVE-2025-12351
6.8 MEDIUM

Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to …

Oct 27, 2025
CVE-2025-12290
4.3 MEDIUM

A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality …

Oct 27, 2025
CVE-2025-12289
4.3 MEDIUM

A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality …

Oct 27, 2025
CVE-2025-12288
4.3 MEDIUM

A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User …

Oct 27, 2025
CVE-2025-12287
4.7 MEDIUM

A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the …

Oct 27, 2025
CVE-2025-9164

Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder …

Oct 27, 2025
CVE-2025-61481
10.0 CRITICAL

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute …

Oct 27, 2025
CVE-2025-60291
9.1 CRITICAL

An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and …

Oct 27, 2025
CVE-2025-52263
8.0 HIGH

An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted firmware, leading to …

Oct 27, 2025
CVE-2025-50055
6.4 MEDIUM

Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) …

Oct 27, 2025
CVE-2025-12286
7.0 HIGH

A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. …

Oct 27, 2025
CVE-2025-12283
4.3 MEDIUM

A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results in authorization bypass. …

Oct 27, 2025
CVE-2025-12282
2.4 LOW

A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function of the file /admin/manage-users.php. The manipulation leads to …

Oct 27, 2025
CVE-2025-12281
2.4 LOW

A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executing manipulation can lead to cross …

Oct 27, 2025
CVE-2025-12280
2.4 LOW

A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Performing manipulation results in cross …

Oct 27, 2025
CVE-2025-41384
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include …

Oct 27, 2025
CVE-2025-41068
7.5 HIGH

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is achieved …

Oct 27, 2025
CVE-2025-41067
7.5 HIGH

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request …

Oct 27, 2025
CVE-2025-12279
2.4 LOW

A vulnerability has been found in code-projects Client Details System 1.0. This vulnerability affects unknown code of the file /welcome.php. Such manipulation leads to cross …

Oct 27, 2025
CVE-2025-12277
7.3 HIGH

A flaw has been found in Abdullah-Hasan-Sajjad Online-School up to f09dda77b4c29aa083ff57f4b1eb991b98b68883. This affects an unknown part of the file /studentLogin.php. This manipulation of the argument …

Oct 27, 2025
CVE-2025-12276
4.3 MEDIUM

A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation results …

Oct 27, 2025
CVE-2025-12274
8.8 HIGH

A security vulnerability has been detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of …

Oct 27, 2025
CVE-2025-12273
8.8 HIGH

A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page …

Oct 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.