CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59887
8.6 HIGH

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to …

Dec 26, 2025
CVE-2025-62578
7.5 HIGH

DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information

Dec 26, 2025
CVE-2025-8075
5.4 MEDIUM

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format …

Dec 26, 2025
CVE-2025-68946
5.4 MEDIUM

In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.

Dec 26, 2025
CVE-2025-52601
7.8 HIGH

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that …

Dec 26, 2025
CVE-2025-52600
7.2 HIGH

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in camera video analytics …

Dec 26, 2025
CVE-2025-52599
6.5 MEDIUM

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered Inadequate of permission management for camera …

Dec 26, 2025
CVE-2025-52598
3.7 LOW

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has found a flaw that camera's client service …

Dec 26, 2025
CVE-2025-68945
5.8 MEDIUM

In Gitea before 1.21.2, an anonymous user can visit a private user's project.

Dec 26, 2025
CVE-2025-68944
5.0 MEDIUM

Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

Dec 26, 2025
CVE-2025-68943
5.3 MEDIUM

Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

Dec 26, 2025
CVE-2025-15099
7.3 HIGH

A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps/sim/lib/auth/internal.ts of the component CRON Secret Handler. …

Dec 26, 2025
CVE-2025-68942
5.4 MEDIUM

Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

Dec 26, 2025
CVE-2025-68941
4.9 MEDIUM

Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

Dec 26, 2025
CVE-2025-68940
3.1 LOW

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

Dec 26, 2025
CVE-2025-68939
8.2 HIGH

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

Dec 26, 2025
CVE-2025-15098
6.3 MEDIUM

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the …

Dec 26, 2025
CVE-2025-15097
7.3 HIGH

A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/api/status/. Performing manipulation results in improper authentication. …

Dec 26, 2025
CVE-2025-15095
3.5 LOW

A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to …

Dec 26, 2025
CVE-2025-68938
4.3 MEDIUM

Gitea before 1.25.2 mishandles authorization for deletion of releases.

Dec 26, 2025
CVE-2025-15094
4.3 MEDIUM

A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component …

Dec 26, 2025
CVE-2025-15093
4.3 MEDIUM

A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected element is an unknown function of the file src/main/java/com/flycms/web/system/IndexAdminController.java of the …

Dec 26, 2025
CVE-2025-15092
8.8 HIGH

A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/ConfigExceptMSN. Such manipulation of the argument …

Dec 26, 2025
CVE-2025-68937

Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template …

Dec 26, 2025
CVE-2025-15091
8.8 HIGH

A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the …

Dec 26, 2025
CVE-2025-14913
5.3 MEDIUM

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect …

Dec 26, 2025
CVE-2025-15090
8.8 HIGH

A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the …

Dec 25, 2025
CVE-2025-15089
8.8 HIGH

A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the …

Dec 25, 2025
CVE-2025-14820

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 25, 2025
CVE-2025-14715

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 25, 2025
CVE-2025-15088
6.3 MEDIUM

A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.loadPostils of the file /je/postil/postil/loadPostil. Performing a manipulation …

Dec 25, 2025
CVE-2025-15087
4.3 MEDIUM

A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java. Such manipulation of the argument orderSn …

Dec 25, 2025
CVE-2025-15086
4.3 MEDIUM

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation causes improper access controls. The …

Dec 25, 2025
CVE-2025-68936
6.4 MEDIUM

ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

Dec 25, 2025
CVE-2025-68935
6.4 MEDIUM

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

Dec 25, 2025
CVE-2025-15085
4.3 MEDIUM

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balance Handler. The …

Dec 25, 2025
CVE-2025-15084
3.1 LOW

A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java of the component Order Payment Handler. …

Dec 25, 2025
CVE-2025-15083
2.0 LOW

A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing manipulation …

Dec 25, 2025
CVE-2025-15082
5.3 MEDIUM

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management …

Dec 25, 2025
CVE-2025-15081
6.3 MEDIUM

A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdcapi. Such manipulation of the argument …

Dec 25, 2025
CVE-2025-2406
7.6 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Trizbi …

Dec 25, 2025
CVE-2025-2405
7.6 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus …

Dec 25, 2025
CVE-2025-2307
7.6 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Aidango …

Dec 25, 2025
CVE-2025-66443
7.5 HIGH

Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an …

Dec 25, 2025
CVE-2025-66379
7.5 HIGH

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media …

Dec 25, 2025
CVE-2025-66378
5.9 MEDIUM

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy …

Dec 25, 2025
CVE-2025-66377
7.5 HIGH

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code …

Dec 25, 2025
CVE-2025-59683
8.2 HIGH

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange …

Dec 25, 2025
CVE-2025-49088
5.9 MEDIUM

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in …

Dec 25, 2025
CVE-2025-48704
7.5 HIGH

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a …

Dec 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.