CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9927
7.3 HIGH

A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown function of the file /viewpackage.php. Such manipulation of the …

Sep 3, 2025
CVE-2025-8268
6.5 MEDIUM

The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and …

Sep 3, 2025
CVE-2025-58056
7.5 HIGH

Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, …

Sep 3, 2025
CVE-2025-57833
7.1 HIGH

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, …

Sep 3, 2025
CVE-2025-55748
7.5 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are …

Sep 3, 2025
CVE-2025-55747
9.1 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are …

Sep 3, 2025
CVE-2025-9926
7.3 HIGH

A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the file /viewsubcategory.php. This manipulation of the argument t1 …

Sep 3, 2025
CVE-2025-9925
7.3 HIGH

A vulnerability was found in projectworlds Travel Management System 1.0. This issue affects some unknown processing of the file /detail.php. The manipulation of the argument …

Sep 3, 2025
CVE-2025-9365
7.8 HIGH

Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker …

Sep 3, 2025
CVE-2025-56139
5.3 MEDIUM

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a …

Sep 3, 2025
CVE-2025-55162
6.3 MEDIUM

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1.33.6, …

Sep 3, 2025
CVE-2025-53690
9.0 CRITICAL KEV

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience …

Sep 3, 2025
CVE-2025-9924
7.3 HIGH

A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /enquiry.php. The manipulation of the argument …

Sep 3, 2025
CVE-2025-9923
4.3 MEDIUM

A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. Executing manipulation of the …

Sep 3, 2025
CVE-2025-36193
8.4 HIGH

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the …

Sep 3, 2025
CVE-2025-56803
8.4 HIGH

Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands by setting …

Sep 3, 2025
CVE-2025-56752
9.4 CRITICAL

A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter …

Sep 3, 2025
CVE-2025-52494
7.5 HIGH

Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes during connection initialization. When …

Sep 3, 2025
CVE-2025-45805
7.6 HIGH

In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered …

Sep 3, 2025
CVE-2025-20336
5.3 MEDIUM

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Sep 3, 2025
CVE-2025-20335
5.3 MEDIUM

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Sep 3, 2025
CVE-2025-20330
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker …

Sep 3, 2025
CVE-2025-20328
5.4 MEDIUM

A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site …

Sep 3, 2025
CVE-2025-20326
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could …

Sep 3, 2025
CVE-2025-20291
4.3 MEDIUM

A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco …

Sep 3, 2025
CVE-2025-20287
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to …

Sep 3, 2025
CVE-2025-20280
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Sep 3, 2025
CVE-2025-20270
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Sep 3, 2025
CVE-2025-9959
7.6 HIGH

Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt …

Sep 3, 2025
CVE-2025-9922
4.3 MEDIUM

A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. …

Sep 3, 2025
CVE-2025-9921
2.4 LOW

A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown function of the file /main/products.php. This manipulation of the argument …

Sep 3, 2025
CVE-2025-9867
5.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Sep 3, 2025
CVE-2025-9866
8.8 HIGH

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium …

Sep 3, 2025
CVE-2025-9865
5.4 MEDIUM

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI …

Sep 3, 2025
CVE-2025-9864

Rejected reason: This CVE ID was assigned in error to a vulnerability that was both introduced and fixed before the code landed in the Stable …

Sep 3, 2025
CVE-2025-56761
5.4 MEDIUM

Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content …

Sep 3, 2025
CVE-2025-56760
4.3 MEDIUM

When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in …

Sep 3, 2025
CVE-2025-56689
4.6 MEDIUM

One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker …

Sep 3, 2025
CVE-2025-9920
4.7 MEDIUM

A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of the file /admin/index.php. The manipulation of the …

Sep 3, 2025
CVE-2025-9919
7.3 HIGH

A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument …

Sep 3, 2025
CVE-2025-56498
5.3 MEDIUM

An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submits user input to the …

Sep 3, 2025
CVE-2025-56435
5.3 MEDIUM

SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on the …

Sep 3, 2025
CVE-2025-55944
6.1 MEDIUM

Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded …

Sep 3, 2025
CVE-2025-55852
7.5 HIGH

Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g.

Sep 3, 2025
CVE-2025-48876

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-0280
7.5 HIGH

A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.

Sep 3, 2025
CVE-2025-9824
5.9 MEDIUM

ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after …

Sep 3, 2025
CVE-2025-9823

SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is …

Sep 3, 2025
CVE-2025-58644
7.2 HIGH

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes-tql-edition allows Object Injection.This issue affects LTL Freight Quotes - TQL Edition: …

Sep 3, 2025
CVE-2025-58643
7.2 HIGH

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-quotes-daylight-edition allows Object Injection.This issue affects LTL Freight Quotes – Daylight Edition: …

Sep 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.