CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7385

Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an …

Sep 4, 2025
CVE-2025-41063
5.4 MEDIUM

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of …

Sep 4, 2025
CVE-2025-41062
5.4 MEDIUM

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of …

Sep 4, 2025
CVE-2025-41061
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41060
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41059
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41058
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41057
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41056
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41055
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41054
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41053
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41052
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41051
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41050
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41049
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41048
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41047
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41046
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41045
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41044
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41043
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41042
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41041
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41040
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41039
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41038
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41037
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41036
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41035
6.5 MEDIUM

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions …

Sep 4, 2025
CVE-2025-41034
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2025-41033
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2025-41032
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2024-34598
7.7 HIGH

Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store.

Sep 4, 2025
CVE-2022-39888
4.3 MEDIUM

Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.

Sep 4, 2025
CVE-2025-9942
6.3 MEDIUM

A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulation leads to …

Sep 4, 2025
CVE-2025-9941
6.3 MEDIUM

A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the …

Sep 4, 2025
CVE-2025-9940
3.5 LOW

A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /feature.php. Performing manipulation of the argument …

Sep 4, 2025
CVE-2025-9939
3.5 LOW

A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /propertyview.php. Such …

Sep 4, 2025
CVE-2025-9938
8.8 HIGH

A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the file /yyxz.asp. This manipulation of the argument …

Sep 4, 2025
CVE-2025-9937
5.4 MEDIUM

A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulation results in improper authorization. …

Sep 4, 2025
CVE-2025-9936
4.3 MEDIUM

A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The …

Sep 4, 2025
CVE-2025-9935
7.3 HIGH

A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi-bin/cstecgi.cgi. Executing manipulation can lead to command injection. …

Sep 4, 2025
CVE-2025-9934
6.3 MEDIUM

A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in …

Sep 4, 2025
CVE-2025-9933
7.3 HIGH

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such …

Sep 4, 2025
CVE-2025-9932
7.3 HIGH

A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This …

Sep 4, 2025
CVE-2025-9931
4.3 MEDIUM

A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation …

Sep 4, 2025
CVE-2025-9930
7.3 HIGH

A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulation of …

Sep 4, 2025
CVE-2025-9929
2.4 LOW

A weakness has been identified in code-projects Responsive Blog Site 1.0. This affects an unknown function of the file blogs_view.php. Executing manipulation of the argument …

Sep 4, 2025
CVE-2025-9616
5.3 MEDIUM

The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or …

Sep 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.