CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62256
5.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and …

Oct 23, 2025
CVE-2025-60852
6.5 MEDIUM

A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize …

Oct 23, 2025
CVE-2025-53702
6.5 MEDIUM

Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action …

Oct 23, 2025
CVE-2025-53701
6.1 MEDIUM

Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET requests sent to /cgi-bin/action endpoint are not sanitized properly, …

Oct 23, 2025
CVE-2025-1680

An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate …

Oct 23, 2025
CVE-2025-1679

Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service …

Oct 23, 2025
CVE-2025-11429
5.4 MEDIUM

A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created …

Oct 23, 2025
CVE-2025-8427
6.4 MEDIUM

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and …

Oct 23, 2025
CVE-2025-11128
5.0 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery …

Oct 23, 2025
CVE-2025-11023
9.8 CRITICAL

Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ArkSigner Software …

Oct 23, 2025
CVE-2025-10705
5.3 MEDIUM

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.4.6. …

Oct 23, 2025
CVE-2025-62401
5.4 MEDIUM

An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

Oct 23, 2025
CVE-2025-62400
4.3 MEDIUM

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal …

Oct 23, 2025
CVE-2025-62399
7.5 HIGH

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

Oct 23, 2025
CVE-2025-62398
5.4 MEDIUM

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

Oct 23, 2025
CVE-2025-62397
5.3 MEDIUM

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

Oct 23, 2025
CVE-2025-62396
5.3 MEDIUM

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

Oct 23, 2025
CVE-2025-62395
4.3 MEDIUM

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted …

Oct 23, 2025
CVE-2025-62394
4.3 MEDIUM

Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course …

Oct 23, 2025
CVE-2025-62393
4.3 MEDIUM

A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view …

Oct 23, 2025
CVE-2025-10355

Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirection parameter, potentially leading users …

Oct 23, 2025
CVE-2024-14011

Rejected reason: This is a duplicate.

Oct 23, 2025
CVE-2025-41073
6.5 MEDIUM

Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated attacker to download a ZIP file containing files from …

Oct 23, 2025
CVE-2025-40643
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of …

Oct 23, 2025
CVE-2025-9981
4.8 MEDIUM

QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, …

Oct 23, 2025
CVE-2025-9980
4.8 MEDIUM

QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, …

Oct 23, 2025
CVE-2025-12105
7.5 HIGH

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. …

Oct 23, 2025
CVE-2025-10914
7.6 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Reflected …

Oct 23, 2025
CVE-2025-10727
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner Software and Hardware Inc. AcBakImzala allows Reflected XSS.This issue affects …

Oct 23, 2025
CVE-2025-62499
4.8 MEDIUM

Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" …

Oct 23, 2025
CVE-2025-61865
6.7 MEDIUM

Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the …

Oct 23, 2025
CVE-2025-54856
4.8 MEDIUM

Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an …

Oct 23, 2025
CVE-2025-54806
6.1 MEDIUM

GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to …

Oct 23, 2025
CVE-2025-62820
4.9 MEDIUM

Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.

Oct 23, 2025
CVE-2025-62813

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Oct 23, 2025
CVE-2025-48430
5.5 MEDIUM

Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Command Centre Server at will. This issue affects …

Oct 23, 2025
CVE-2025-48428
6.7 MEDIUM

Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to the Command Centre Server to export …

Oct 23, 2025
CVE-2025-47699
9.9 CRITICAL

Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions …

Oct 23, 2025
CVE-2025-41402
5.5 MEDIUM

Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue …

Oct 23, 2025
CVE-2025-35981
5.5 MEDIUM

Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about …

Oct 23, 2025
CVE-2025-12104
9.8 CRITICAL

Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 23, 2025
CVE-2025-62812

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62811

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62810

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62809

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62808

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62807

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62806

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62805

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62804

Rejected reason: Not used

Oct 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.