CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60934
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or …

Oct 21, 2025
CVE-2025-60933
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts …

Oct 21, 2025
CVE-2025-60932
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts …

Oct 21, 2025
CVE-2025-60344
8.6 HIGH

A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path …

Oct 21, 2025
CVE-2025-59438
5.3 MEDIUM

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

Oct 21, 2025
CVE-2025-57521
6.1 MEDIUM

Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without …

Oct 21, 2025
CVE-2025-56450
6.5 MEDIUM

Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLeadHistory` endpoint. A remote attacker can exploit this …

Oct 21, 2025
CVE-2022-4981
3.3 LOW

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The …

Oct 21, 2025
CVE-2020-36855
5.3 MEDIUM

A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of …

Oct 21, 2025
CVE-2025-9339

SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user a malicious query injection. Potential exploitation is limited …

Oct 21, 2025
CVE-2025-11625
9.8 CRITICAL

Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.

Oct 21, 2025
CVE-2025-11624
9.8 CRITICAL

Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or …

Oct 21, 2025
CVE-2025-11151
8.2 HIGH

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beyaz Bilgisayar Software Design Industry …

Oct 21, 2025
CVE-2025-6239
6.5 MEDIUM

Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

Oct 21, 2025
CVE-2025-10020
8.5 HIGH

Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.

Oct 21, 2025
CVE-2025-9428
8.3 HIGH

Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.

Oct 21, 2025
CVE-2025-10641
7.1 HIGH

All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to …

Oct 21, 2025
CVE-2025-10640
9.8 CRITICAL

An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side authentication checks to bypass the login prompt in …

Oct 21, 2025
CVE-2025-10639
8.8 HIGH

The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with …

Oct 21, 2025
CVE-2025-7473
5.2 MEDIUM

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

Oct 21, 2025
CVE-2025-5496
3.3 LOW

ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.

Oct 21, 2025
CVE-2025-10612
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Information Technologies City Guide allows Reflected XSS.This issue affects City …

Oct 21, 2025
CVE-2025-26392
5.4 MEDIUM

SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege …

Oct 21, 2025
CVE-2025-12004

Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue …

Oct 21, 2025
CVE-2025-11949
7.5 HIGH

EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to obtain database administrator credentials via a specific …

Oct 21, 2025
CVE-2025-10916
9.1 CRITICAL

The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers …

Oct 21, 2025
CVE-2025-62702

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - PageTriage Extension allows Stored XSS.This issue …

Oct 21, 2025
CVE-2025-62701

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikistories allows Stored XSS.This issue affects …

Oct 21, 2025
CVE-2025-62694

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLove Extension allows Stored XSS.This issue …

Oct 21, 2025
CVE-2025-62699

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Translate Extension allows Footprinting. Translate extension appears to use jobs …

Oct 21, 2025
CVE-2025-62696

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue …

Oct 21, 2025
CVE-2025-62695

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Stored XSS.This issue …

Oct 21, 2025
CVE-2025-62684

Rejected reason: Not used

Oct 21, 2025
CVE-2025-62683

Rejected reason: Not used

Oct 21, 2025
CVE-2025-62682

Rejected reason: Not used

Oct 21, 2025
CVE-2025-62681

Rejected reason: Not used

Oct 21, 2025
CVE-2025-62680

Rejected reason: Not used

Oct 21, 2025
CVE-2025-62679

Rejected reason: Not used

Oct 21, 2025
CVE-2025-62678

Rejected reason: Not used

Oct 21, 2025
CVE-2025-62677

Rejected reason: Not used

Oct 21, 2025
CVE-2025-9133
8.1 HIGH

A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX …

Oct 21, 2025
CVE-2025-8078
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG …

Oct 21, 2025
CVE-2025-7851
9.8 CRITICAL

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

Oct 21, 2025
CVE-2025-7850
7.2 HIGH

A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

Oct 21, 2025
CVE-2025-6542
9.8 CRITICAL

An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

Oct 21, 2025
CVE-2025-6541
8.8 HIGH

An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

Oct 21, 2025
CVE-2025-54764
6.2 MEDIUM

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.

Oct 20, 2025
CVE-2025-12001
6.1 MEDIUM

Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 20, 2025
CVE-2025-11536
5.0 MEDIUM

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via …

Oct 20, 2025
CVE-2018-25118

GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands …

Oct 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.