CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-32096
7.5 HIGH

Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a …

Dec 25, 2025
CVE-2025-32095
7.5 HIGH

Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, …

Dec 25, 2025
CVE-2025-15078
7.3 HIGH

A vulnerability was detected in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /list_report.php. The manipulation of the …

Dec 25, 2025
CVE-2025-15077
7.3 HIGH

A security vulnerability has been detected in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /form137.php. The manipulation …

Dec 25, 2025
CVE-2025-15076
7.3 HIGH

A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a manipulation can lead to path …

Dec 25, 2025
CVE-2025-15075
7.3 HIGH

A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown processing of the file /student_p.php. Performing manipulation of …

Dec 25, 2025
CVE-2025-15074
7.3 HIGH

A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /customer_details.php. Such manipulation leads to …

Dec 25, 2025
CVE-2025-68922
7.4 HIGH

OpenOps before 0.6.11 allows remote code execution in the Terraform block.

Dec 25, 2025
CVE-2025-15073
7.3 HIGH

A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the …

Dec 24, 2025
CVE-2025-68920
8.9 HIGH

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary …

Dec 24, 2025
CVE-2025-8769
9.8 CRITICAL

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an …

Dec 24, 2025
CVE-2025-68919
5.6 MEDIUM

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority …

Dec 24, 2025
CVE-2025-68917
6.4 MEDIUM

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

Dec 24, 2025
CVE-2025-68916
9.1 CRITICAL

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

Dec 24, 2025
CVE-2025-68915
5.5 MEDIUM

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.

Dec 24, 2025
CVE-2025-68914
6.5 MEDIUM

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.

Dec 24, 2025
CVE-2025-3232
7.5 HIGH

A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.

Dec 24, 2025
CVE-2019-25258
7.5 HIGH

LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit …

Dec 24, 2025
CVE-2019-25257
6.5 MEDIUM

LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these …

Dec 24, 2025
CVE-2019-25256
6.5 MEDIUM

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers to access arbitrary system files through unvalidated 'ID' parameters. Attackers …

Dec 24, 2025
CVE-2019-25255
4.3 MEDIUM

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can …

Dec 24, 2025
CVE-2019-25254
8.8 HIGH

KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious …

Dec 24, 2025
CVE-2019-25253
7.5 HIGH

KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system …

Dec 24, 2025
CVE-2019-25252
4.3 MEDIUM

Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft malicious …

Dec 24, 2025
CVE-2019-25251
6.5 MEDIUM

Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers …

Dec 24, 2025
CVE-2019-25250
5.3 MEDIUM

Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can …

Dec 24, 2025
CVE-2019-25249
9.8 CRITICAL

devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can …

Dec 24, 2025
CVE-2019-25248
7.5 HIGH

Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve the camera's RTSP …

Dec 24, 2025
CVE-2019-25247
5.3 MEDIUM

Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers …

Dec 24, 2025
CVE-2019-25246
8.8 HIGH

Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. …

Dec 24, 2025
CVE-2019-25245
8.8 HIGH

Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files due to improper permission settings. Attackers can …

Dec 24, 2025
CVE-2019-25244
5.3 MEDIUM

Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site …

Dec 24, 2025
CVE-2019-25243
8.8 HIGH

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary …

Dec 24, 2025
CVE-2019-25242
4.3 MEDIUM

FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious …

Dec 24, 2025
CVE-2019-25241
9.8 CRITICAL

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration …

Dec 24, 2025
CVE-2019-25240
9.8 CRITICAL

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web …

Dec 24, 2025
CVE-2019-25239
7.5 HIGH

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve …

Dec 24, 2025
CVE-2019-25238
4.3 MEDIUM

V-SOL GPON/EPON OLT Platform 2.03 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious …

Dec 24, 2025
CVE-2019-25237
9.8 CRITICAL

V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers …

Dec 24, 2025
CVE-2019-25236
9.8 CRITICAL

iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video …

Dec 24, 2025
CVE-2019-25235
9.8 CRITICAL

Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to …

Dec 24, 2025
CVE-2019-25234
5.3 MEDIUM

SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by …

Dec 24, 2025
CVE-2019-25233
5.3 MEDIUM

AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious …

Dec 24, 2025
CVE-2018-25156
4.3 MEDIUM

Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious …

Dec 24, 2025
CVE-2018-25155
4.3 MEDIUM

Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious …

Dec 24, 2025
CVE-2018-25154
9.8 CRITICAL

GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary …

Dec 24, 2025
CVE-2018-25153

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported issue does not constitute a security vulnerability …

Dec 24, 2025
CVE-2018-25152
5.3 MEDIUM

Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious …

Dec 24, 2025
CVE-2018-25151
4.3 MEDIUM

Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft …

Dec 24, 2025
CVE-2018-25150
5.3 MEDIUM

Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious …

Dec 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.