CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59841
9.8 CRITICAL

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated …

Sep 25, 2025
CVE-2025-57446
7.5 HIGH

An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a denial of service (DoS) via a crafted …

Sep 25, 2025
CVE-2025-55560
7.5 HIGH

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled …

Sep 25, 2025
CVE-2025-55559
7.5 HIGH

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

Sep 25, 2025
CVE-2025-55558
7.5 HIGH

A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a …

Sep 25, 2025
CVE-2025-55557
7.5 HIGH

A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service …

Sep 25, 2025
CVE-2025-55556
6.5 MEDIUM

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

Sep 25, 2025
CVE-2025-55554
5.3 MEDIUM

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

Sep 25, 2025
CVE-2025-55553
7.5 HIGH

A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

Sep 25, 2025
CVE-2025-55552
7.5 HIGH

pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

Sep 25, 2025
CVE-2025-43943
6.7 MEDIUM

Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Sep 25, 2025
CVE-2025-33116
4.4 MEDIUM

IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Sep 25, 2025
CVE-2025-26333
5.9 MEDIUM

Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, …

Sep 25, 2025
CVE-2025-20363
9.0 CRITICAL

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, …

Sep 25, 2025
CVE-2025-20362
6.5 MEDIUM KEV

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software …

Sep 25, 2025
CVE-2025-20333
9.9 CRITICAL KEV

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could …

Sep 25, 2025
CVE-2025-10953
8.8 HIGH

A security vulnerability has been detected in UTT 1200GW and 1250GW up to 3.0.0-170831/3.2.2-200710. This vulnerability affects unknown code of the file /goform/formApMail. The manipulation …

Sep 25, 2025
CVE-2025-10952
5.3 MEDIUM

A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream_handler of the file ml_logger/server.py of …

Sep 25, 2025
CVE-2025-10911
5.5 MEDIUM

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

Sep 25, 2025
CVE-2024-48014
7.5 HIGH

Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, …

Sep 25, 2025
CVE-2025-59838
5.4 MEDIUM

Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user input when loading a saved custom text results …

Sep 25, 2025
CVE-2025-59832
9.9 CRITICAL

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket …

Sep 25, 2025
CVE-2025-59830
7.5 HIGH

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting …

Sep 25, 2025
CVE-2025-59823
9.9 CRITICAL

Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers …

Sep 25, 2025
CVE-2025-55551
7.5 HIGH

An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

Sep 25, 2025
CVE-2025-46153
5.3 MEDIUM

PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, …

Sep 25, 2025
CVE-2025-46152
5.3 MEDIUM

In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.

Sep 25, 2025
CVE-2025-46150
5.3 MEDIUM

In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.

Sep 25, 2025
CVE-2025-46149
5.3 MEDIUM

In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.

Sep 25, 2025
CVE-2025-46148
5.3 MEDIUM

In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.

Sep 25, 2025
CVE-2025-40838
7.5 HIGH

Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of …

Sep 25, 2025
CVE-2025-40837
8.8 HIGH

Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than …

Sep 25, 2025
CVE-2025-40836
9.8 CRITICAL

Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.

Sep 25, 2025
CVE-2025-36857
3.3 LOW

Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place …

Sep 25, 2025
CVE-2025-36601
4.0 MEDIUM

Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit …

Sep 25, 2025
CVE-2025-27262
7.8 HIGH

Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.

Sep 25, 2025
CVE-2025-10951
7.3 HIGH

A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vulnerability is the function log_handler of the file ml_logger/server.py. Such manipulation of …

Sep 25, 2025
CVE-2025-10950
6.3 MEDIUM

A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file ml_logger/server.py of the component Ping Handler. This …

Sep 25, 2025
CVE-2025-10949
2.4 LOW

A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation …

Sep 25, 2025
CVE-2025-10542
9.8 CRITICAL

iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these …

Sep 25, 2025
CVE-2025-10541
7.8 HIGH

iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files …

Sep 25, 2025
CVE-2020-36851

Rob -- W / cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to make HTTP requests to arbitrary …

Sep 25, 2025
CVE-2025-5494
3.9 LOW

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

Sep 25, 2025
CVE-2025-59839
8.6 HIGH

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video …

Sep 25, 2025
CVE-2025-59834
9.8 CRITICAL

ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server …

Sep 25, 2025
CVE-2025-59831
8.8 HIGH

git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerability in git-commiters. …

Sep 25, 2025
CVE-2025-59426
4.3 MEDIUM

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of …

Sep 25, 2025
CVE-2025-59422
3.1 LOW

Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/<APP_ID>chat-messages?conversation_id=<CONVERSATION_ID>&limit=10 endpoint allows users in the same …

Sep 25, 2025
CVE-2025-57317
7.5 HIGH

apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess function of apidoc-core versions thru …

Sep 25, 2025
CVE-2025-27261
9.8 CRITICAL

Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.

Sep 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.