CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-61779

Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint …

Oct 9, 2025
CVE-2025-61773
8.1 HIGH

pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both …

Oct 9, 2025
CVE-2025-61602
7.5 HIGH

BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for …

Oct 9, 2025
CVE-2025-61601
7.5 HIGH

BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash …

Oct 9, 2025
CVE-2025-60375
7.3 HIGH

The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password …

Oct 9, 2025
CVE-2025-59286
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

Oct 9, 2025
CVE-2025-59272
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

Oct 9, 2025
CVE-2025-59271
8.7 HIGH

Redis Enterprise Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-59252
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

Oct 9, 2025
CVE-2025-59247
8.8 HIGH

Azure PlayFab Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-59246
9.8 CRITICAL

Azure Entra ID Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-59218
9.6 CRITICAL

Azure Entra ID Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-55321
9.3 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.

Oct 9, 2025
CVE-2025-43296
5.5 MEDIUM

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

Oct 9, 2025
CVE-2025-35062
5.3 MEDIUM

Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.

Oct 9, 2025
CVE-2025-35061
5.9 MEDIUM

Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can …

Oct 9, 2025
CVE-2025-35060
5.5 MEDIUM

Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or …

Oct 9, 2025
CVE-2025-35059
4.3 MEDIUM

Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

Oct 9, 2025
CVE-2025-35058
5.9 MEDIUM

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can …

Oct 9, 2025
CVE-2025-35057
5.3 MEDIUM

Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can …

Oct 9, 2025
CVE-2025-35056
5.0 MEDIUM

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary …

Oct 9, 2025
CVE-2025-35055
8.8 HIGH

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can …

Oct 9, 2025
CVE-2025-35054
5.3 MEDIUM

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same …

Oct 9, 2025
CVE-2025-35053
6.4 MEDIUM

Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT …

Oct 9, 2025
CVE-2025-35052
5.3 MEDIUM

Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing …

Oct 9, 2025
CVE-2025-35051
9.8 CRITICAL

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with …

Oct 9, 2025
CVE-2025-35050
9.8 CRITICAL

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. …

Oct 9, 2025
CVE-2025-34248

D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow …

Oct 9, 2025
CVE-2025-11558
7.3 HIGH

A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/user_index_search.php. Performing manipulation of the argument Search results …

Oct 9, 2025
CVE-2025-11557
7.3 HIGH

A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of …

Oct 9, 2025
CVE-2025-11556
7.3 HIGH

A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /user.php. This manipulation of the argument …

Oct 9, 2025
CVE-2025-11555
7.3 HIGH

A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/calendar_of_events.php. The manipulation of the argument …

Oct 9, 2025
CVE-2016-15047

AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying …

Oct 9, 2025
CVE-2025-60316
9.4 CRITICAL

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.

Oct 9, 2025
CVE-2025-11554
6.3 MEDIUM

A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of …

Oct 9, 2025
CVE-2025-11553
6.3 MEDIUM

A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-courier.php. Executing manipulation …

Oct 9, 2025
CVE-2025-59146
8.5 HIGH

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in …

Oct 9, 2025
CVE-2025-55200
7.1 HIGH

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input …

Oct 9, 2025
CVE-2025-4615
7.2 HIGH

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions …

Oct 9, 2025
CVE-2025-4614
2.7 LOW

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web …

Oct 9, 2025
CVE-2025-11552
6.3 MEDIUM

A vulnerability was identified in code-projects Online Complaint Site 1.0. This impacts an unknown function of the file /admin/category.php. Such manipulation of the argument Category …

Oct 9, 2025
CVE-2025-60267
6.5 MEDIUM

In xckk v9.6, there is a SQL injection vulnerability in which the cond parameter in notice/list is not securely filtered, resulting in a SQL injection …

Oct 9, 2025
CVE-2025-11573
7.5 HIGH

An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text …

Oct 9, 2025
CVE-2025-11551
6.3 MEDIUM

A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file src/students/Database.java. This manipulation of the argument roll/name/gpa …

Oct 9, 2025
CVE-2025-11550
6.5 MEDIUM

A vulnerability was found in Tenda W12 3.0.0.6(3948). The impacted element is the function wifiScheduledSet of the file /goform/modules of the component HTTP Request Handler. …

Oct 9, 2025
CVE-2025-60304
6.1 MEDIUM

code-projects Simple Scheduling System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Subject Description field.

Oct 9, 2025
CVE-2025-60266
6.5 MEDIUM

In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in address/list is not securely filtered, resulting in a SQL injection …

Oct 9, 2025
CVE-2025-60010
5.4 MEDIUM

A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the …

Oct 9, 2025
CVE-2025-60009
6.1 MEDIUM

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in …

Oct 9, 2025
CVE-2025-60006
5.3 MEDIUM

Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos …

Oct 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.