CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-26278
7.5 HIGH

A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Sep 25, 2025
CVE-2025-10948
8.8 HIGH

A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads …

Sep 25, 2025
CVE-2025-10540
6.5 MEDIUM

iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the …

Sep 25, 2025
CVE-2025-10467
8.9 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs …

Sep 25, 2025
CVE-2025-10947
5.3 MEDIUM

A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of the file /api/areacliente/pessoa/validarCpf …

Sep 25, 2025
CVE-2025-10946
3.5 LOW

A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is an unknown function of the file dy.php. Performing manipulation of the …

Sep 25, 2025
CVE-2025-10945
3.5 LOW

A security vulnerability has been detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. Impacted is an unknown function of the file d.php. Such manipulation of the …

Sep 25, 2025
CVE-2025-10944
3.5 LOW

A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects the function ip of the file ip.php. This manipulation of the …

Sep 25, 2025
CVE-2025-10449
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Portal allows Path Traversal.This …

Sep 25, 2025
CVE-2025-40698

SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST …

Sep 25, 2025
CVE-2025-10957

This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by …

Sep 25, 2025
CVE-2025-10943
3.5 LOW

A security flaw has been discovered in MikeCen WeChat-Face-Recognition up to 6e3f72bf8547d80b59e330f1137e4aa505f492c1. This vulnerability affects the function valid of the file wx.php. The manipulation of …

Sep 25, 2025
CVE-2025-10942
8.8 HIGH

A vulnerability was identified in H3C Magic B3 up to 100R002. This affects the function AddMacList/EditMacList of the file /goform/aspForm. The manipulation of the argument …

Sep 25, 2025
CVE-2025-10941
7.8 HIGH

A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. …

Sep 25, 2025
CVE-2025-10940
2.4 LOW

A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. …

Sep 25, 2025
CVE-2025-10438
8.6 HIGH

Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog allows Path Traversal.This issue affects Yordam Katalog: …

Sep 25, 2025
CVE-2025-21056
6.6 MEDIUM

Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on their own devices.

Sep 25, 2025
CVE-2025-54520

Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to undervolt the platform resulting in a loss …

Sep 24, 2025
CVE-2025-10894
9.6 CRITICAL

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via …

Sep 24, 2025
CVE-2025-59833
7.5 HIGH

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in …

Sep 24, 2025
CVE-2025-59827
9.8 CRITICAL

Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign …

Sep 24, 2025
CVE-2025-57324
6.5 MEDIUM

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers …

Sep 24, 2025
CVE-2025-57320
6.5 MEDIUM

json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers …

Sep 24, 2025
CVE-2025-57319
7.5 HIGH

fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedRestore function of fast-redact version 3.5.0 and before …

Sep 24, 2025
CVE-2025-57318
7.5 HIGH

A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, …

Sep 24, 2025
CVE-2025-59828
9.8 CRITICAL

Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-executed …

Sep 24, 2025
CVE-2025-59824
5.4 MEDIUM

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escape. Omni …

Sep 24, 2025
CVE-2025-57329
7.5 HIGH

web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability in the attachToObject function of web3-core-method version 1.10.4 …

Sep 24, 2025
CVE-2025-57328
7.5 HIGH

toggle-array is a package designed to enables a property on the object at the specified index, while disabling the property on all other objects. A …

Sep 24, 2025
CVE-2025-57327
7.5 HIGH

spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config function of spmrc version 1.2.0 …

Sep 24, 2025
CVE-2025-57326
7.5 HIGH

A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, …

Sep 24, 2025
CVE-2025-57325
7.5 HIGH

rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes advanced error tracking features and an intuitive interface …

Sep 24, 2025
CVE-2025-57323
7.5 HIGH

mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vulnerability in the mp.addEventHandler function of mpregular version …

Sep 24, 2025
CVE-2025-57321
9.8 CRITICAL

A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, …

Sep 24, 2025
CVE-2025-59525
6.1 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded …

Sep 24, 2025
CVE-2025-59251
7.6 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 24, 2025
CVE-2025-57351
6.5 MEDIUM

A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation of user-provided keys in the assign function allows attackers …

Sep 24, 2025
CVE-2025-57349
7.5 HIGH

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key …

Sep 24, 2025
CVE-2025-57348
6.5 MEDIUM

The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties …

Sep 24, 2025
CVE-2025-57347
9.8 CRITICAL

A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConflict function, which fails to properly sanitize user-supplied input during …

Sep 24, 2025
CVE-2025-57330
7.5 HIGH

The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows …

Sep 24, 2025
CVE-2025-55322
7.3 HIGH

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.

Sep 24, 2025
CVE-2025-55178
5.3 MEDIUM

Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.

Sep 24, 2025
CVE-2025-59524
6.1 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in the …

Sep 24, 2025
CVE-2025-59343

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable …

Sep 24, 2025
CVE-2025-59305
7.6 HIGH

Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to …

Sep 24, 2025
CVE-2025-57354
6.5 MEDIUM

A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user-controlled input in translation key processing. The affected …

Sep 24, 2025
CVE-2025-57353
5.3 MEDIUM

The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the …

Sep 24, 2025
CVE-2025-57352
5.3 MEDIUM

A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious …

Sep 24, 2025
CVE-2025-57350
8.6 HIGH

The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10. …

Sep 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.