CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-69205
6.3 MEDIUM

Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a3026bcd6816d51c7f3b93c55893, an attacker can crafts …

Dec 29, 2025
CVE-2025-15205
6.3 MEDIUM

A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download.php. The manipulation …

Dec 29, 2025
CVE-2025-15204
2.4 LOW

A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/main/java/com/sohu/cache/web/controller/QuartzManageController.java. Executing manipulation can lead to cross …

Dec 29, 2025
CVE-2024-27480
9.8 CRITICAL

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

Dec 29, 2025
CVE-2024-25183
7.5 HIGH

givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.

Dec 29, 2025
CVE-2024-25182
9.8 CRITICAL

givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

Dec 29, 2025
CVE-2025-69202
6.5 MEDIUM

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor …

Dec 29, 2025
CVE-2025-15203
2.4 LOW

A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/com/sohu/cache/web/controller/ResourceController.java. Performing manipulation results in cross site …

Dec 29, 2025
CVE-2025-15202
2.4 LOW

A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src/main/java/com/sohu/cache/web/controller/TaskController.java. Such manipulation leads to cross …

Dec 29, 2025
CVE-2025-14175
6.5 MEDIUM

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and …

Dec 29, 2025
CVE-2024-30855
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.

Dec 29, 2025
CVE-2024-25181
9.1 CRITICAL

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from …

Dec 29, 2025
CVE-2025-68706
9.8 CRITICAL

A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to …

Dec 29, 2025
CVE-2025-68431
6.5 MEDIUM

libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path …

Dec 29, 2025
CVE-2025-67255
8.8 HIGH

In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.

Dec 29, 2025
CVE-2025-67254
7.5 HIGH

NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.

Dec 29, 2025
CVE-2025-15201
3.5 LOW

A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file src/main/java/com/sohu/cache/web/controller/WebResourceController.java. This manipulation causes …

Dec 29, 2025
CVE-2025-15200
2.4 LOW

A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. The affected element is the function getExceptionStatisticsByClient/getCommandStatisticsByClient/doIndex of the file src/main/java/com/sohu/cache/web/controller/AppClientDataShowController.java. The manipulation results in …

Dec 29, 2025
CVE-2025-15199
6.3 MEDIUM

A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboard/userprofile.php. The manipulation of …

Dec 29, 2025
CVE-2025-14728
6.8 MEDIUM

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written …

Dec 29, 2025
CVE-2025-14280
5.3 MEDIUM

The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.1.5 through publicly exposed log files. This …

Dec 29, 2025
CVE-2025-13592
7.2 HIGH

The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the 'change-ad__content' shortcode parameter. This …

Dec 29, 2025
CVE-2025-68861
7.1 HIGH

Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin Optimizer: from n/a through <= 1.3.7.

Dec 29, 2025
CVE-2025-66877
7.5 HIGH

Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.

Dec 29, 2025
CVE-2025-55064
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Dec 29, 2025
CVE-2025-55063
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Dec 29, 2025
CVE-2025-55062
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Dec 29, 2025
CVE-2025-55061
8.8 HIGH

CWE-434 Unrestricted Upload of File with Dangerous Type

Dec 29, 2025
CVE-2025-55060
6.1 MEDIUM

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

Dec 29, 2025
CVE-2025-15198
7.3 HIGH

A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown processing of the file /login.php. Executing a manipulation …

Dec 29, 2025
CVE-2025-68870
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in reDim GmbH CookieHint WP cookiehint-wp allows PHP Local File …

Dec 29, 2025
CVE-2025-68868
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Text Slider Widget wp-text-slider-widget allows Stored XSS.This issue affects Wp Text …

Dec 29, 2025
CVE-2025-66869
7.5 HIGH

Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.

Dec 29, 2025
CVE-2025-66866
7.5 HIGH

An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Dec 29, 2025
CVE-2025-66865
7.5 HIGH

An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Dec 29, 2025
CVE-2025-66864
7.5 HIGH

An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Dec 29, 2025
CVE-2025-66863
7.5 HIGH

An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Dec 29, 2025
CVE-2025-66862
7.5 HIGH

A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Dec 29, 2025
CVE-2025-66861
2.5 LOW

An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.

Dec 29, 2025
CVE-2025-53627
5.3 MEDIUM

Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces asymmetric encryption (PKI) for direct messages, but when the …

Dec 29, 2025
CVE-2025-15197
4.7 MEDIUM

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation …

Dec 29, 2025
CVE-2025-15196
7.3 HIGH

A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads …

Dec 29, 2025
CVE-2025-69211
7.4 HIGH

Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is …

Dec 29, 2025
CVE-2025-69206
4.3 MEDIUM

Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Server-Side Request Forgery (SSRF) filter bypass vulnerability exists …

Dec 29, 2025
CVE-2025-69201
9.8 CRITICAL

Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. …

Dec 29, 2025
CVE-2025-69200
7.5 HIGH

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP …

Dec 29, 2025
CVE-2025-68951
5.4 MEDIUM

phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute …

Dec 29, 2025
CVE-2025-68897
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-shortcode allows Code Injection.This issue affects IF AS Shortcode: …

Dec 29, 2025
CVE-2025-68893
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through <= …

Dec 29, 2025
CVE-2025-68879
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Content Grid Slider content-grid-slider allows Reflected XSS.This issue affects Content Grid Slider: …

Dec 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.