CVE Database

11758+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59245
9.8 CRITICAL

Microsoft SharePoint Online Elevation of Privilege Vulnerability

Nov 20, 2025
CVE-2025-49752
10.0 CRITICAL

Azure Bastion Elevation of Privilege Vulnerability

Nov 20, 2025
CVE-2025-63807
9.8 CRITICAL

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows …

Nov 20, 2025
CVE-2025-63685
9.8 CRITICAL

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate …

Nov 20, 2025
CVE-2025-10571
9.6 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects ABB Ability Edgenius: 3.2.0.0, 3.2.1.1.

Nov 20, 2025
CVE-2025-63888
9.8 CRITICAL

The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

Nov 20, 2025
CVE-2025-64428
9.8 CRITICAL

Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch …

Nov 20, 2025
CVE-2025-52410
9.8 CRITICAL

Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The `myds` GET parameter is not adequately sanitized before being used in …

Nov 20, 2025
CVE-2025-60738
9.8 CRITICAL

An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute …

Nov 20, 2025
CVE-2025-40604
9.8 CRITICAL

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or …

Nov 20, 2025
CVE-2025-63213
9.8 CRITICAL

The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the /cgi-bin/net_ping.cgi endpoint. An attacker …

Nov 19, 2025
CVE-2025-65099
9.8 CRITICAL

Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have …

Nov 19, 2025
CVE-2025-65021
9.1 CRITICAL

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists in the poll finalization feature …

Nov 19, 2025
CVE-2025-63210
9.8 CRITICAL

The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying …

Nov 19, 2025
CVE-2025-63207
9.8 CRITICAL

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. …

Nov 19, 2025
CVE-2025-63206
9.8 CRITICAL

An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via …

Nov 19, 2025
CVE-2025-13315
9.8 CRITICAL

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to …

Nov 19, 2025
CVE-2025-34329
9.8 CRITICAL

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web …

Nov 19, 2025
CVE-2025-34328
9.8 CRITICAL

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script-management endpoint …

Nov 19, 2025
CVE-2025-63224
10.0 CRITICAL

The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT …

Nov 19, 2025
CVE-2025-63223
9.8 CRITICAL

The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi …

Nov 19, 2025
CVE-2025-63221
9.1 CRITICAL

The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated …

Nov 19, 2025
CVE-2025-63218
9.8 CRITICAL

The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi …

Nov 19, 2025
CVE-2025-10437
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System …

Nov 19, 2025
CVE-2025-12057
9.8 CRITICAL

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied …

Nov 19, 2025
CVE-2025-64325
9.0 CRITICAL

Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request …

Nov 18, 2025
CVE-2025-63217
9.8 CRITICAL

The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT …

Nov 18, 2025
CVE-2025-63216
10.0 CRITICAL

The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT …

Nov 18, 2025
CVE-2025-63228
9.8 CRITICAL

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this …

Nov 18, 2025
CVE-2025-63225
9.8 CRITICAL

The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access …

Nov 18, 2025
CVE-2025-54321
9.8 CRITICAL

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated …

Nov 18, 2025
CVE-2025-63994
9.8 CRITICAL

An arbitrary file upload vulnerability in the /php/UploadHandler.php component of RichFilemanager v2.7.6 allows attackers to execute arbitrary code via uploading a crafted file.

Nov 18, 2025
CVE-2025-63695
9.8 CRITICAL

DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

Nov 18, 2025
CVE-2025-63694
9.8 CRITICAL

DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.

Nov 18, 2025
CVE-2025-56643
9.1 CRITICAL

Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid …

Nov 18, 2025
CVE-2025-9312
9.8 CRITICAL

A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due …

Nov 18, 2025
CVE-2025-41348
9.8 CRITICAL

SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete databases by sendng a POST …

Nov 18, 2025
CVE-2025-41734
9.8 CRITICAL

An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.

Nov 18, 2025
CVE-2025-41733
9.8 CRITICAL

The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to …

Nov 18, 2025
CVE-2025-41347
9.8 CRITICAL

Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending …

Nov 18, 2025
CVE-2025-41346
9.8 CRITICAL

Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning …

Nov 18, 2025
CVE-2025-40549
9.1 CRITICAL

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute …

Nov 18, 2025
CVE-2025-40548
9.1 CRITICAL

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. …

Nov 18, 2025
CVE-2025-40547
9.1 CRITICAL

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. …

Nov 18, 2025
CVE-2024-44659
9.8 CRITICAL

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

Nov 17, 2025
CVE-2025-63747
9.8 CRITICAL

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the …

Nov 17, 2025
CVE-2025-9501
9.0 CRITICAL

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by …

Nov 17, 2025
CVE-2025-13284
9.8 CRITICAL

ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

Nov 17, 2025
CVE-2025-58083
10.0 CRITICAL

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

Nov 15, 2025
CVE-2025-13188
9.8 CRITICAL

A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument …

Nov 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.