CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58330

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58329

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58328

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58327

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58326

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58323
7.7 HIGH

NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege …

Aug 29, 2025
CVE-2025-39247
8.6 HIGH

There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.

Aug 29, 2025
CVE-2025-39246
5.3 MEDIUM

There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via …

Aug 29, 2025
CVE-2025-39245
4.7 MEDIUM

There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.

Aug 29, 2025
CVE-2025-9604
3.7 LOW

A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backend/domain/plugin/encrypt/aes.go. The manipulation of the argument …

Aug 29, 2025
CVE-2025-9603
6.3 MEDIUM

A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname …

Aug 29, 2025
CVE-2025-9602
6.3 MEDIUM

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. …

Aug 29, 2025
CVE-2025-9601
7.3 HIGH

A vulnerability was detected in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /setting/employee_salary_setup.php. The manipulation of the argument ddlEmpName …

Aug 29, 2025
CVE-2025-9600
7.3 HIGH

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /setting/member_type_setup.php. The …

Aug 29, 2025
CVE-2025-9599
7.3 HIGH

A weakness has been identified in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /setting/month_setup.php. Executing manipulation …

Aug 29, 2025
CVE-2025-54142
4.0 MEDIUM

Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within …

Aug 29, 2025
CVE-2025-43284
5.5 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app …

Aug 29, 2025
CVE-2025-43268
7.8 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root …

Aug 29, 2025
CVE-2025-43255
3.3 LOW

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app …

Aug 29, 2025
CVE-2025-43187
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Running an …

Aug 29, 2025
CVE-2025-40927
7.3 HIGH

CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows …

Aug 29, 2025
CVE-2024-54568
4.3 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may lead to an …

Aug 29, 2025
CVE-2024-54554
5.5 MEDIUM

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive …

Aug 29, 2025
CVE-2024-44271
3.3 LOW

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record the screen without …

Aug 29, 2025
CVE-2025-9598
7.3 HIGH

A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of the file /setting/year_setup.php. Performing manipulation of the …

Aug 29, 2025
CVE-2025-9597
7.3 HIGH

A vulnerability was identified in itsourcecode Apartment Management System 1.0. This impacts an unknown function of the file /o_dashboard/rented_all_info.php. Such manipulation of the argument uid …

Aug 29, 2025
CVE-2025-9596
7.3 HIGH

A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /login.php. This manipulation of the argument User …

Aug 29, 2025
CVE-2025-9595
4.3 MEDIUM

A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of …

Aug 29, 2025
CVE-2025-48979
3.4 LOW

An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileges and local access.

Aug 29, 2025
CVE-2025-9594
7.3 HIGH

A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /report/complain_info.php. The manipulation of …

Aug 28, 2025
CVE-2025-9593
7.3 HIGH

A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/unit_status_info.php. Executing manipulation of the argument …

Aug 28, 2025
CVE-2025-58062

LSTM-Kirigaya's openmcp-client is a vscode plugin for mcp developer. Prior to version 0.1.12, when users on a Windows platform connect to an attacker controlled MCP …

Aug 28, 2025
CVE-2025-9592
7.3 HIGH

A vulnerability was detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/bill_info.php. Performing manipulation of the argument …

Aug 28, 2025
CVE-2025-9591
2.4 LOW

A security vulnerability has been detected in ZrLog up to 3.1.5. This vulnerability affects unknown code of the file /api/admin/template/config of the component Theme Configuration …

Aug 28, 2025
CVE-2025-9590
3.5 LOW

A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerability is an unknown functionality. The manipulation of the …

Aug 28, 2025
CVE-2025-9589
2.5 LOW

A vulnerability was determined in Cudy WR1200EA 2.3.7-20250113-121810. Affected is an unknown function of the file /etc/shadow. Executing manipulation can lead to use of default …

Aug 28, 2025
CVE-2025-58061
5.5 MEDIUM

OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, persistent volume data is world …

Aug 28, 2025
CVE-2025-58058
5.3 MEDIUM

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of …

Aug 28, 2025
CVE-2025-9586
6.3 MEDIUM

A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads …

Aug 28, 2025
CVE-2025-9585
6.3 MEDIUM

A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of the argument portal_delete_picname causes command …

Aug 28, 2025
CVE-2025-9584
6.3 MEDIUM

A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of the argument …

Aug 28, 2025
CVE-2025-9583
6.3 MEDIUM

A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to …

Aug 28, 2025
CVE-2025-9582
6.3 MEDIUM

A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can …

Aug 28, 2025
CVE-2025-6203
7.5 HIGH

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption …

Aug 28, 2025
CVE-2025-9581
6.3 MEDIUM

A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in …

Aug 28, 2025
CVE-2025-9580
6.3 MEDIUM

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such …

Aug 28, 2025
CVE-2025-9579
6.3 MEDIUM

A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the component HTTP Handler. …

Aug 28, 2025
CVE-2025-9577
2.5 LOW

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the …

Aug 28, 2025
CVE-2025-57220
5.3 MEDIUM

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.

Aug 28, 2025
CVE-2025-57219
5.3 MEDIUM

Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted …

Aug 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.