CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53950
5.5 MEDIUM

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 …

Oct 16, 2025
CVE-2025-46752
4.4 MEDIUM

A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the …

Oct 16, 2025
CVE-2025-11839
3.3 LOW

A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked …

Oct 16, 2025
CVE-2025-9955
5.7 MEDIUM

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs …

Oct 16, 2025
CVE-2025-9804
9.6 CRITICAL

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. …

Oct 16, 2025
CVE-2025-9152
9.8 CRITICAL

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. …

Oct 16, 2025
CVE-2025-10611
9.8 CRITICAL

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to …

Oct 16, 2025
CVE-2025-3930

Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen …

Oct 16, 2025
CVE-2025-6338

There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This …

Oct 16, 2025
CVE-2025-58426
4.3 MEDIUM

desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applications.

Oct 16, 2025
CVE-2025-58079
4.3 MEDIUM

Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.

Oct 16, 2025
CVE-2025-55072
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-54859
4.8 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-54760
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-52583
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-24833
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-61581
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. People with access …

Oct 16, 2025
CVE-2025-58115
6.1 MEDIUM

ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be executed on the web browser of the user …

Oct 16, 2025
CVE-2025-58075
8.1 HIGH

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the …

Oct 16, 2025
CVE-2025-58073
8.1 HIGH

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the …

Oct 16, 2025
CVE-2025-54539
9.8 CRITICAL

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up …

Oct 16, 2025
CVE-2025-54499
3.1 LOW

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to …

Oct 16, 2025
CVE-2025-54461
5.3 MEDIUM

ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited, an uninvited guest user may register itself as a …

Oct 16, 2025
CVE-2025-53858
5.4 MEDIUM

ChatLuck contains a cross-site scripting vulnerability in Chat Rooms. If exploited, an arbitrary script may be executed on the web browser of the user who …

Oct 16, 2025
CVE-2025-41410
5.4 MEDIUM

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create …

Oct 16, 2025
CVE-2025-10545
3.1 LOW

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add …

Oct 16, 2025
CVE-2025-0277
6.5 MEDIUM

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing …

Oct 16, 2025
CVE-2025-0276
6.5 MEDIUM

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick …

Oct 16, 2025
CVE-2025-55091
6.5 MEDIUM

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function …

Oct 16, 2025
CVE-2025-41443
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover …

Oct 16, 2025
CVE-2025-41021
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validation of user input by sending …

Oct 16, 2025
CVE-2025-41020
7.5 HIGH

Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' …

Oct 16, 2025
CVE-2025-41019

SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' parameter in '/index.php?view=ticket_detail'.

Oct 16, 2025
CVE-2025-41018
9.8 CRITICAL

SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' parameter in '/public.php'.

Oct 16, 2025
CVE-2025-62585
7.5 HIGH

Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.

Oct 16, 2025
CVE-2025-62584
7.5 HIGH

Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.

Oct 16, 2025
CVE-2025-62583
9.8 CRITICAL

Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

Oct 16, 2025
CVE-2025-55090
6.5 MEDIUM

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function …

Oct 16, 2025
CVE-2025-55089
9.8 CRITICAL

In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in the FileX RAM disk driver. It …

Oct 16, 2025
CVE-2025-55084
5.3 MEDIUM

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.

Oct 16, 2025
CVE-2025-10850
9.8 CRITICAL

The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password …

Oct 16, 2025
CVE-2025-10849
5.3 MEDIUM

The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_actions' function called via …

Oct 16, 2025
CVE-2025-10742
9.8 CRITICAL

The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6. This is due to the …

Oct 16, 2025
CVE-2025-10706
8.8 HIGH

The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_plugin_cb' function in all versions …

Oct 16, 2025
CVE-2025-58778
7.2 HIGH

Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabled in the initial configuration. …

Oct 16, 2025
CVE-2025-0275
5.3 MEDIUM

HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access …

Oct 16, 2025
CVE-2025-11814
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 3.21.1 (exclusive) due to insufficient input …

Oct 16, 2025
CVE-2025-0274
5.3 MEDIUM

HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, …

Oct 16, 2025
CVE-2025-10700
4.3 MEDIUM

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This …

Oct 16, 2025
CVE-2025-62580
7.8 HIGH

ASDA-Soft Stack-based Buffer Overflow Vulnerability

Oct 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.