CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9132
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Aug 20, 2025
CVE-2024-12223

Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim …

Aug 20, 2025
CVE-2025-9193
3.5 LOW

A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing …

Aug 20, 2025
CVE-2025-9176
5.3 MEDIUM

A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment …

Aug 20, 2025
CVE-2025-9175
5.3 MEDIUM

A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c. The manipulation leads to stack-based …

Aug 19, 2025
CVE-2025-9174
5.3 MEDIUM

A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filename Handler. …

Aug 19, 2025
CVE-2025-9171
3.5 LOW

A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component …

Aug 19, 2025
CVE-2025-9170
3.5 LOW

A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates …

Aug 19, 2025
CVE-2025-9169
3.5 LOW

A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation …

Aug 19, 2025
CVE-2025-9187
9.8 CRITICAL

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Aug 19, 2025
CVE-2025-9186
6.5 MEDIUM

Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.

Aug 19, 2025
CVE-2025-9185
8.1 HIGH

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. …

Aug 19, 2025
CVE-2025-9184
8.1 HIGH

Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption …

Aug 19, 2025
CVE-2025-9183
6.5 MEDIUM

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.

Aug 19, 2025
CVE-2025-9182
7.5 HIGH

Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.

Aug 19, 2025
CVE-2025-9181
6.5 MEDIUM

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and …

Aug 19, 2025
CVE-2025-9180
8.1 HIGH

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird …

Aug 19, 2025
CVE-2025-9179
9.8 CRITICAL

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly …

Aug 19, 2025
CVE-2025-9168
3.5 LOW

A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. …

Aug 19, 2025
CVE-2025-9167
3.5 LOW

A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. …

Aug 19, 2025
CVE-2025-8364
4.3 MEDIUM

A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue …

Aug 19, 2025
CVE-2025-8042
9.8 CRITICAL

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.

Aug 19, 2025
CVE-2025-8041
5.3 MEDIUM

In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in …

Aug 19, 2025
CVE-2025-55033
6.1 MEDIUM

Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability …

Aug 19, 2025
CVE-2025-55032
6.1 MEDIUM

Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowing for XSS attacks. This …

Aug 19, 2025
CVE-2025-55031
9.8 CRITICAL

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …

Aug 19, 2025
CVE-2025-55030
6.1 MEDIUM

Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for …

Aug 19, 2025
CVE-2025-55029
7.5 HIGH

Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed in Firefox for …

Aug 19, 2025
CVE-2025-55028
6.5 MEDIUM

Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed …

Aug 19, 2025
CVE-2025-54145
9.1 CRITICAL

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL …

Aug 19, 2025
CVE-2025-54144
5.4 MEDIUM

The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if …

Aug 19, 2025
CVE-2025-54143
9.8 CRITICAL

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed …

Aug 19, 2025
CVE-2025-9165
2.5 LOW

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead …

Aug 19, 2025
CVE-2025-9157
5.3 MEDIUM

A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. …

Aug 19, 2025
CVE-2025-9156
7.3 HIGH

A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the …

Aug 19, 2025
CVE-2025-9155
7.3 HIGH

A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget_password.php. Such manipulation …

Aug 19, 2025
CVE-2025-55740
6.5 MEDIUM

nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender …

Aug 19, 2025
CVE-2025-55737
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. …

Aug 19, 2025
CVE-2025-52337
6.5 MEDIUM

An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to execute arbitrary code via uploading a …

Aug 19, 2025
CVE-2025-51543
9.8 CRITICAL

An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password endpoint.

Aug 19, 2025
CVE-2025-50926
6.5 MEDIUM

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function.

Aug 19, 2025
CVE-2025-43744
5.4 MEDIUM

A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, …

Aug 19, 2025
CVE-2025-43743
4.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 …

Aug 19, 2025
CVE-2025-2988
2.7 LOW

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized …

Aug 19, 2025
CVE-2025-9154
7.3 HIGH

A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This …

Aug 19, 2025
CVE-2025-9153
6.3 MEDIUM

A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of …

Aug 19, 2025
CVE-2025-55736
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges …

Aug 19, 2025
CVE-2025-55735
5.4 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post …

Aug 19, 2025
CVE-2025-55734
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin …

Aug 19, 2025
CVE-2025-55733
9.6 CRITICAL

DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker …

Aug 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.