CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36354
7.3 HIGH

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary …

Oct 6, 2025
CVE-2025-11341
7.3 HIGH

A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in …

Oct 6, 2025
CVE-2025-11339
8.8 HIGH

A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the file /webchat/hi_block.asp of the component …

Oct 6, 2025
CVE-2025-10363

Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affects at least Topal Finanzbuchhaltung: 10.1.5.20 and …

Oct 6, 2025
CVE-2025-0038
6.6 MEDIUM

In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or …

Oct 6, 2025
CVE-2025-61765
6.4 MEDIUM

python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers …

Oct 6, 2025
CVE-2025-61687
8.3 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI …

Oct 6, 2025
CVE-2025-61224
6.5 MEDIUM

Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter

Oct 6, 2025
CVE-2025-59159
9.6 CRITICAL

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. …

Oct 6, 2025
CVE-2025-59152
7.5 HIGH

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders …

Oct 6, 2025
CVE-2025-11338
8.8 HIGH

A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component …

Oct 6, 2025
CVE-2025-52472

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 4.3-milestone-1 and prior to versions …

Oct 6, 2025
CVE-2025-49594

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access …

Oct 6, 2025
CVE-2023-49886
9.8 CRITICAL

IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending …

Oct 6, 2025
CVE-2025-61198
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 …

Oct 6, 2025
CVE-2025-61197
8.9 HIGH

An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 allows a remote attacker …

Oct 6, 2025
CVE-2025-11337
5.3 MEDIUM

A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneReport/index.do/../../aloneReport/download.do;othersusrlogout.do. Performing manipulation of …

Oct 6, 2025
CVE-2025-11336
5.3 MEDIUM

A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown functionality of the …

Oct 6, 2025
CVE-2025-11335
4.7 MEDIUM

A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.htm?flag=qos of …

Oct 6, 2025
CVE-2025-11334
7.3 HIGH

A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-detail.php. The manipulation …

Oct 6, 2025
CVE-2025-11333
2.4 LOW

A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This impacts an unknown function of the file /customer_add_action.php of the component Add …

Oct 6, 2025
CVE-2025-11332
3.5 LOW

A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php of the component URL Handler. Executing a …

Oct 6, 2025
CVE-2025-11331
4.7 MEDIUM

A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the component Website Name …

Oct 6, 2025
CVE-2025-11330
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/sales-reports-detail.php. Such manipulation …

Oct 6, 2025
CVE-2025-0609
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Software Inc. Logo Cloud allows Cross-Site Scripting (XSS).This issue affects …

Oct 6, 2025
CVE-2025-0608
5.5 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forceful Browsing.This issue affects Logo Cloud: before 2025.R6.

Oct 6, 2025
CVE-2025-0607
4.3 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing.This issue affects Logo Cloud: before 2.57.

Oct 6, 2025
CVE-2025-11329
7.3 HIGH

A flaw has been found in code-projects Online Course Registration 1.0. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument …

Oct 6, 2025
CVE-2025-11328
8.8 HIGH

A vulnerability was detected in Tenda AC18 15.03.05.19(6318). This issue affects some unknown processing of the file /goform/SetDDNSCfg. The manipulation of the argument ddnsEn results …

Oct 6, 2025
CVE-2025-0606
6.0 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing, Resource Leak Exposure.This issue affects Logo Cloud: before 0.67.

Oct 6, 2025
CVE-2025-59734

It is possible to cause an use-after-free write in SANM decoding with a carefully crafted animation using subversion <2. When a STOR chunk is present, …

Oct 6, 2025
CVE-2025-59733

When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that all image channels have the same pixel type (and …

Oct 6, 2025
CVE-2025-59732

When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8. If …

Oct 6, 2025
CVE-2025-59731

When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to …

Oct 6, 2025
CVE-2025-59730

When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded …

Oct 6, 2025
CVE-2025-59729

When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start …

Oct 6, 2025
CVE-2025-59728

When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call …

Oct 6, 2025
CVE-2025-11327
8.8 HIGH

A security vulnerability has been detected in Tenda AC18 15.03.05.19(6318). This vulnerability affects unknown code of the file /goform/SetUpnpCfg. The manipulation of the argument upnpEn …

Oct 6, 2025
CVE-2025-11326
8.8 HIGH

A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet. Executing a manipulation of the argument wifi_chkHz …

Oct 6, 2025
CVE-2025-9914
4.3 MEDIUM

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to …

Oct 6, 2025
CVE-2025-9913
4.5 MEDIUM

JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

Oct 6, 2025
CVE-2025-58591
6.5 MEDIUM

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive …

Oct 6, 2025
CVE-2025-58590
6.5 MEDIUM

It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.

Oct 6, 2025
CVE-2025-58589
2.7 LOW

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as …

Oct 6, 2025
CVE-2025-58587
6.5 MEDIUM

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to …

Oct 6, 2025
CVE-2025-58586
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Oct 6, 2025
CVE-2025-58585
5.3 MEDIUM

Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.

Oct 6, 2025
CVE-2025-58584
5.3 MEDIUM

In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such …

Oct 6, 2025
CVE-2025-58583
5.3 MEDIUM

The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

Oct 6, 2025
CVE-2025-58582
5.3 MEDIUM

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated …

Oct 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.