CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49844
9.9 CRITICAL

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua …

Oct 3, 2025
CVE-2025-57714
7.8 HIGH

An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gains a user account, they can then …

Oct 3, 2025
CVE-2025-54154
6.8 MEDIUM

An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise …

Oct 3, 2025
CVE-2025-54153
8.8 HIGH

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Oct 3, 2025
CVE-2025-53595
8.8 HIGH

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Oct 3, 2025
CVE-2025-53407
6.5 MEDIUM

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, …

Oct 3, 2025
CVE-2025-53406
6.5 MEDIUM

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, …

Oct 3, 2025
CVE-2025-52867
6.5 MEDIUM

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-52866
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52862
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52860
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52859
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52858
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52857
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52855
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52854
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52853
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52658
3.5 LOW

HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited.

Oct 3, 2025
CVE-2025-52656
7.6 HIGH

HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or …

Oct 3, 2025
CVE-2025-52654
4.6 MEDIUM

HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing …

Oct 3, 2025
CVE-2025-52433
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52432
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52429
6.5 MEDIUM

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, …

Oct 3, 2025
CVE-2025-52428
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52427
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52424
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-48730
6.5 MEDIUM

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, …

Oct 3, 2025
CVE-2025-48729
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-48728
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-48727
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-48726
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-47214
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-47213
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-47212
7.2 HIGH

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Oct 3, 2025
CVE-2025-47211
4.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Oct 3, 2025
CVE-2025-47210
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-46819
6.3 MEDIUM

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA …

Oct 3, 2025
CVE-2025-46818
6.0 MEDIUM

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua …

Oct 3, 2025
CVE-2025-44014
8.8 HIGH

An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Oct 3, 2025
CVE-2025-44012
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-44011
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44010
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44009
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44008
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-61593
7.1 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its …

Oct 3, 2025
CVE-2025-61592
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current working …

Oct 3, 2025
CVE-2025-52653
7.6 HIGH

HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in …

Oct 3, 2025
CVE-2025-46817
7.0 HIGH

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua …

Oct 3, 2025
CVE-2025-44007
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-44006
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.