CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27238
3.5 LOW

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to …

Sep 12, 2025
CVE-2025-27234

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 …

Sep 12, 2025
CVE-2025-27233

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be …

Sep 12, 2025
CVE-2025-10267
5.3 MEDIUM

NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass …

Sep 12, 2025
CVE-2025-10266
9.8 CRITICAL

NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete …

Sep 12, 2025
CVE-2025-10265
8.8 HIGH

Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them …

Sep 12, 2025
CVE-2025-7448

Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack

Sep 12, 2025
CVE-2025-10264
10.0 CRITICAL

Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remoter attackers to access the system configuration file and …

Sep 12, 2025
CVE-2025-21043
8.8 HIGH KEV

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

Sep 12, 2025
CVE-2025-21042
8.8 HIGH KEV

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

Sep 12, 2025
CVE-2025-9086
7.5 HIGH

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, …

Sep 12, 2025
CVE-2025-8575
7.2 HIGH

The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'lws_cl_delete_file' function in all versions …

Sep 12, 2025
CVE-2025-8280
5.8 MEDIUM

The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead …

Sep 12, 2025
CVE-2025-7337
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-6769
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-6454
8.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-58781
4.8 MEDIUM

WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.

Sep 12, 2025
CVE-2025-3650
3.5 LOW

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with …

Sep 12, 2025
CVE-2025-2256
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-1250
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-10291
6.3 MEDIUM

A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. Executing manipulation of the argument …

Sep 12, 2025
CVE-2025-10148
5.3 MEDIUM

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed …

Sep 12, 2025
CVE-2025-10288
5.3 MEDIUM

A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the file /user/info/list. Performing manipulation results in …

Sep 12, 2025
CVE-2025-10287
3.1 LOW

A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element is an unknown function of the file /auth/orderQuery. Such manipulation of …

Sep 12, 2025
CVE-2025-10094
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-9881
6.1 MEDIUM

The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing …

Sep 12, 2025
CVE-2025-9880
6.1 MEDIUM

The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due …

Sep 12, 2025
CVE-2025-9879
6.4 MEDIUM

The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' shortcode in all versions up to, and including, …

Sep 12, 2025
CVE-2025-9877
6.4 MEDIUM

The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' shortcode in all versions up to, and including, …

Sep 12, 2025
CVE-2025-10278
6.3 MEDIUM

A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument …

Sep 12, 2025
CVE-2025-43789
5.3 MEDIUM

JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered …

Sep 12, 2025
CVE-2025-43788
4.3 MEDIUM

The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check …

Sep 12, 2025
CVE-2025-10277
6.3 MEDIUM

A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file /crm/receivable/submit. The manipulation of the argument …

Sep 12, 2025
CVE-2025-10276
6.3 MEDIUM

A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the …

Sep 12, 2025
CVE-2025-10269
7.5 HIGH

The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.13. This makes it possible for …

Sep 12, 2025
CVE-2025-9807
7.5 HIGH

The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 …

Sep 12, 2025
CVE-2025-58754
7.5 HIGH

Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 …

Sep 12, 2025
CVE-2025-55319
8.8 HIGH

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

Sep 12, 2025
CVE-2025-10275
6.3 MEDIUM

A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipulation of the argument …

Sep 12, 2025
CVE-2025-10274
4.3 MEDIUM

A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the file /trial/mvc/item. Performing manipulation of …

Sep 12, 2025
CVE-2025-10273
3.5 LOW

A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the file /view/file.aspx. Such manipulation of the argument …

Sep 12, 2025
CVE-2025-4974

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 11, 2025
CVE-2025-10272
4.3 MEDIUM

A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. This manipulation of the argument Name causes cross …

Sep 11, 2025
CVE-2025-10271
4.3 MEDIUM

A vulnerability was found in erjinzhi 10OA 1.0. This impacts an unknown function of the file /trial/mvc/finder. The manipulation of the argument Name results in …

Sep 11, 2025
CVE-2025-36222
8.7 HIGH

IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that …

Sep 11, 2025
CVE-2025-10127
9.8 CRITICAL

Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An …

Sep 11, 2025
CVE-2025-9319
7.5 HIGH

A potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under certain conditions.

Sep 11, 2025
CVE-2025-9214
5.4 MEDIUM

A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via …

Sep 11, 2025
CVE-2025-9201
7.8 HIGH

A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that could allow a local user to execute code with …

Sep 11, 2025
CVE-2025-8557
8.8 HIGH

An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo …

Sep 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.