CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11082
5.3 MEDIUM

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can …

Sep 27, 2025
CVE-2025-11081
3.3 LOW

A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The …

Sep 27, 2025
CVE-2025-11080
4.3 MEDIUM

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamInfoController.java. Such manipulation of …

Sep 27, 2025
CVE-2025-11079
5.3 MEDIUM

A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation results in file …

Sep 27, 2025
CVE-2025-11078
6.3 MEDIUM

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/controller.php?action=photos. The manipulation …

Sep 27, 2025
CVE-2025-11077
7.3 HIGH

A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument …

Sep 27, 2025
CVE-2025-11076
7.3 HIGH

A vulnerability was found in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_teacher.php. Performing manipulation of the argument …

Sep 27, 2025
CVE-2025-11075
7.3 HIGH

A vulnerability has been found in Campcodes Online Learning Management System 1.0. This affects an unknown function of the file /admin/de_activate.php. Such manipulation of the …

Sep 27, 2025
CVE-2025-11074
7.3 HIGH

A flaw has been found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of …

Sep 27, 2025
CVE-2025-11073
4.7 MEDIUM

A vulnerability was detected in Keyfactor RG-EW5100BE EW_3.0B11P280_EW5100BE-PRO_12183019. The affected element is an unknown function of the file /cgi-bin/luci/api/cmd of the component HTTP POST Request …

Sep 27, 2025
CVE-2025-11071
4.7 MEDIUM

A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_cron.php of the component Cron Task Management Module. …

Sep 27, 2025
CVE-2025-8014
7.5 HIGH

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior …

Sep 27, 2025
CVE-2025-7647
7.3 HIGH

The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is used on Linux …

Sep 27, 2025
CVE-2025-11070
7.3 HIGH

A vulnerability was identified in Projectworlds Online Shopping System 1.0. This affects an unknown part of the file /store/cart_add.php. Such manipulation of the argument ID …

Sep 27, 2025
CVE-2025-11069
2.4 LOW

A vulnerability was determined in westboy CicadasCMS 1.0. Affected by this issue is some unknown functionality of the file /system/org/save of the component Add Department …

Sep 27, 2025
CVE-2025-11068
2.4 LOW

A vulnerability was found in westboy CicadasCMS 1.0. Affected by this vulnerability is an unknown functionality of the file /system/cms/category/save. The manipulation of the argument …

Sep 27, 2025
CVE-2025-11067
2.4 LOW

A vulnerability has been found in Projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /myform.php of the component Add Visitor …

Sep 27, 2025
CVE-2025-11066
7.3 HIGH

A flaw has been found in code-projects Online Bidding System 1.0. This impacts an unknown function of the file /administrator/bidlist.php. Executing manipulation of the argument …

Sep 27, 2025
CVE-2025-11064
7.3 HIGH

A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Impacted is an unknown function of the file /admin/teachers.php. The manipulation of …

Sep 27, 2025
CVE-2025-11063
7.3 HIGH

A vulnerability was identified in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /admin/edit_department.php. The manipulation of the …

Sep 27, 2025
CVE-2025-11062
7.3 HIGH

A vulnerability was determined in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/save_student.php. Executing manipulation of the argument …

Sep 27, 2025
CVE-2025-11061
7.3 HIGH

A vulnerability was found in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/edit_student.php. Performing manipulation of the argument …

Sep 27, 2025
CVE-2025-11057
7.3 HIGH

A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/print_inv.php. Such …

Sep 27, 2025
CVE-2025-11056
6.3 MEDIUM

A flaw has been found in ProjectsAndPrograms School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file owner_panel/fetch-data/select-students.php. This manipulation …

Sep 27, 2025
CVE-2025-11055
7.3 HIGH

A vulnerability was detected in SourceCodester Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/updateaddress.php. The manipulation of the argument …

Sep 27, 2025
CVE-2025-11054
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/category/index.php?view=edit. The manipulation of …

Sep 27, 2025
CVE-2025-11053
7.3 HIGH

A weakness has been identified in PHPGurukul Small CRM 4.0. This affects an unknown function of the file /forgot-password.php. Executing manipulation of the argument email …

Sep 27, 2025
CVE-2025-9944
4.3 MEDIUM

The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to …

Sep 27, 2025
CVE-2025-9899
6.1 MEDIUM

The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Sep 27, 2025
CVE-2025-9898
4.3 MEDIUM

The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. …

Sep 27, 2025
CVE-2025-9896
4.3 MEDIUM

The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.8. This is due to missing or …

Sep 27, 2025
CVE-2025-9894
4.3 MEDIUM

The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing …

Sep 27, 2025
CVE-2025-9893
4.3 MEDIUM

The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due …

Sep 27, 2025
CVE-2025-11052
7.3 HIGH

A security flaw has been discovered in kidaze CourseSelectionSystem 1.0/5.php. The impacted element is an unknown function of the file /Profilers/PriProfile/COUNT3s5.php. Performing manipulation of the …

Sep 27, 2025
CVE-2025-11051
4.3 MEDIUM

A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The …

Sep 27, 2025
CVE-2025-9816
7.2 HIGH

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all …

Sep 27, 2025
CVE-2025-3193
7.5 HIGH

Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to …

Sep 27, 2025
CVE-2025-11050
6.3 MEDIUM

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lead to …

Sep 27, 2025
CVE-2025-10954
5.3 MEDIUM

Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause …

Sep 27, 2025
CVE-2025-11049
6.3 MEDIUM

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /unificacao-aluno. Performing manipulation results …

Sep 27, 2025
CVE-2025-10499
4.3 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Sep 27, 2025
CVE-2025-10498
4.3 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, …

Sep 27, 2025
CVE-2025-8440
6.4 MEDIUM

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in all versions up to, and …

Sep 27, 2025
CVE-2025-36239
6.1 MEDIUM

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the …

Sep 27, 2025
CVE-2024-43192
6.5 MEDIUM

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Sep 27, 2025
CVE-2025-59945
8.1 HIGH

SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission …

Sep 27, 2025
CVE-2025-59939
8.8 HIGH

WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks in the control.php endpoint with the …

Sep 27, 2025
CVE-2025-59938
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from 3.8.0 to before 4.11.0, wazuh-analysisd is …

Sep 27, 2025
CVE-2025-59936
9.4 CRITICAL

get-jwks contains fetch utils for JWKS keys. In versions prior to 11.0.2, a vulnerability in get-jwks can lead to cache poisoning in the JWKS key-fetching …

Sep 27, 2025
CVE-2025-59932
8.6 HIGH

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without …

Sep 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.