CVE Database

11758+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2020-36902
9.8 CRITICAL

UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send …

Dec 10, 2025
CVE-2020-36898
9.1 CRITICAL

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers to delete files without authentication. …

Dec 10, 2025
CVE-2020-36897
9.8 CRITICAL

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. …

Dec 10, 2025
CVE-2020-36892
9.8 CRITICAL

Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can …

Dec 10, 2025
CVE-2020-36885
9.8 CRITICAL

Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execute arbitrary code. Attackers can …

Dec 10, 2025
CVE-2025-65602
9.8 CRITICAL

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

Dec 10, 2025
CVE-2025-64539
9.3 CRITICAL

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker …

Dec 10, 2025
CVE-2025-64538
9.3 CRITICAL

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker …

Dec 10, 2025
CVE-2025-64537
9.3 CRITICAL

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker …

Dec 10, 2025
CVE-2025-13607
9.4 CRITICAL

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

Dec 10, 2025
CVE-2025-65792
9.1 CRITICAL

DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.

Dec 10, 2025
CVE-2025-34394
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization …

Dec 10, 2025
CVE-2025-34393
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, …

Dec 10, 2025
CVE-2025-34392
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that …

Dec 10, 2025
CVE-2025-13184
9.8 CRITICAL

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions …

Dec 10, 2025
CVE-2025-41732
9.8 CRITICAL

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full …

Dec 10, 2025
CVE-2025-41730
9.8 CRITICAL

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full …

Dec 10, 2025
CVE-2025-13613
9.8 CRITICAL

The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin …

Dec 10, 2025
CVE-2025-67506
9.8 CRITICAL

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The …

Dec 10, 2025
CVE-2025-61811
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2025
CVE-2025-61809
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker …

Dec 10, 2025
CVE-2025-61808
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code …

Dec 10, 2025
CVE-2025-67494
9.3 CRITICAL

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats …

Dec 9, 2025
CVE-2025-66039
9.8 CRITICAL

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set …

Dec 9, 2025
CVE-2025-67489
9.8 CRITICAL

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution on the development server through …

Dec 9, 2025
CVE-2023-53774
9.8 CRITICAL

MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV systems. Attackers can …

Dec 9, 2025
CVE-2023-53771
9.8 CRITICAL

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to …

Dec 9, 2025
CVE-2021-47731
9.8 CRITICAL

Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden …

Dec 9, 2025
CVE-2021-47728
9.8 CRITICAL

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit …

Dec 9, 2025
CVE-2025-66456
9.8 CRITICAL

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in …

Dec 9, 2025
CVE-2025-65741
9.8 CRITICAL

Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution …

Dec 9, 2025
CVE-2025-64113
9.8 CRITICAL

Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby …

Dec 9, 2025
CVE-2025-65882
9.8 CRITICAL

An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.

Dec 9, 2025
CVE-2025-59719
9.8 CRITICAL

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to …

Dec 9, 2025
CVE-2025-59718
9.8 CRITICAL KEV

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, …

Dec 9, 2025
CVE-2025-63742
9.8 CRITICAL

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database …

Dec 9, 2025
CVE-2025-67504
9.1 CRITICAL

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, …

Dec 9, 2025
CVE-2025-66631
9.8 CRITICAL

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. …

Dec 9, 2025
CVE-2025-66568
9.1 CRITICAL

The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 …

Dec 9, 2025
CVE-2025-66567
9.1 CRITICAL

The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability …

Dec 9, 2025
CVE-2025-66565
9.8 CRITICAL

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, …

Dec 9, 2025
CVE-2025-42928
9.1 CRITICAL

Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The system may be vulnerable …

Dec 9, 2025
CVE-2025-42880
9.9 CRITICAL

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide …

Dec 9, 2025
CVE-2025-14330
9.8 CRITICAL

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

Dec 9, 2025
CVE-2025-14326
9.8 CRITICAL

Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.

Dec 9, 2025
CVE-2025-14324
9.8 CRITICAL

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird …

Dec 9, 2025
CVE-2025-14321
9.8 CRITICAL

Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

Dec 9, 2025
CVE-2025-14308
9.8 CRITICAL

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length …

Dec 9, 2025
CVE-2025-14306
9.1 CRITICAL

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to …

Dec 9, 2025
CVE-2025-12504
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection.This issue affects UNIS: before 42321.

Dec 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.