CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58758
5.1 MEDIUM

TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the `.env` file to exist …

Sep 9, 2025
CVE-2025-58753
7.5 HIGH

Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a …

Sep 9, 2025
CVE-2025-58442
5.3 MEDIUM

Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in …

Sep 9, 2025
CVE-2025-58435

Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was …

Sep 9, 2025
CVE-2025-58430
6.1 MEDIUM

listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session …

Sep 9, 2025
CVE-2025-58180
8.8 HIGH

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker …

Sep 9, 2025
CVE-2025-58063
7.1 HIGH

CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plugin contains a TTL confusion …

Sep 9, 2025
CVE-2025-55054
6.1 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Sep 9, 2025
CVE-2025-55053
6.5 MEDIUM

CWE-328: Use of Weak Hash

Sep 9, 2025
CVE-2025-54257
7.8 HIGH

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the …

Sep 9, 2025
CVE-2025-54255
4.0 MEDIUM

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature …

Sep 9, 2025
CVE-2025-53914

Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.

Sep 9, 2025
CVE-2025-53913

Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.

Sep 9, 2025
CVE-2025-47415

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from …

Sep 9, 2025
CVE-2025-44594
9.1 CRITICAL

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.

Sep 9, 2025
CVE-2025-43786
5.3 MEDIUM

Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 …

Sep 9, 2025
CVE-2025-36125
6.4 MEDIUM

IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript …

Sep 9, 2025
CVE-2025-36011
4.3 MEDIUM

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to …

Sep 9, 2025
CVE-2025-34175
6.1 MEDIUM

In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting …

Sep 9, 2025
CVE-2025-34174
5.4 MEDIUM

In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being …

Sep 9, 2025
CVE-2025-34173
4.3 MEDIUM

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file …

Sep 9, 2025
CVE-2025-34172
6.1 MEDIUM

In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting …

Sep 9, 2025
CVE-2025-57278
8.8 HIGH

The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, …

Sep 9, 2025
CVE-2025-57060
7.5 HIGH

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This vulnerability allows attackers to cause a …

Sep 9, 2025
CVE-2025-55730
10.0 CRITICAL

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing …

Sep 9, 2025
CVE-2025-55729
10.0 CRITICAL

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing …

Sep 9, 2025
CVE-2025-55728
10.0 CRITICAL

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing …

Sep 9, 2025
CVE-2025-55727
10.0 CRITICAL

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing …

Sep 9, 2025
CVE-2025-55052
4.3 MEDIUM

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Sep 9, 2025
CVE-2025-55051
10.0 CRITICAL

CWE-1392: Use of Default Credentials

Sep 9, 2025
CVE-2025-55050
9.8 CRITICAL

CWE-1242: Inclusion of Undocumented Features

Sep 9, 2025
CVE-2025-55049
9.1 CRITICAL

Use of Default Cryptographic Key (CWE-1394)

Sep 9, 2025
CVE-2025-55048
9.8 CRITICAL

Multiple CWE-78

Sep 9, 2025
CVE-2025-55047
8.4 HIGH

CWE-798 Use of Hard-coded Credentials

Sep 9, 2025
CVE-2025-54256
8.6 HIGH

Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in arbitrary code execution in the context …

Sep 9, 2025
CVE-2025-54242
7.8 HIGH

Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Sep 9, 2025
CVE-2025-43781
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.12 allows …

Sep 9, 2025
CVE-2025-43775
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 …

Sep 9, 2025
CVE-2025-29089
7.5 HIGH

An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information

Sep 9, 2025
CVE-2025-10164
7.3 HIGH

A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of …

Sep 9, 2025
CVE-2025-9269

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can be leveraged by an …

Sep 9, 2025
CVE-2025-57665
6.4 MEDIUM

Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. …

Sep 9, 2025
CVE-2025-57086
7.5 HIGH

Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to cause …

Sep 9, 2025
CVE-2025-57085
9.8 CRITICAL

Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause …

Sep 9, 2025
CVE-2025-57078
7.5 HIGH

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the formModifyPppAuthWhiteMac function. This vulnerability allows attackers to cause a …

Sep 9, 2025
CVE-2025-10199
7.8 HIGH

A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.

Sep 9, 2025
CVE-2025-10198
7.8 HIGH

Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories.

Sep 9, 2025
CVE-2025-5500
5.3 MEDIUM

A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component …

Sep 9, 2025
CVE-2025-5005
7.3 HIGH

A vulnerability was detected in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. This affects an unknown function of the file crm/WeiXinApp/dingtalk/index_event.php. The manipulation …

Sep 9, 2025
CVE-2025-59008
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection zip-code-based-content-protection allows SQL Injection.This issue …

Sep 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.