CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-57840
2.2 LOW

ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.

Dec 24, 2025
CVE-2025-13407
6.8 MEDIUM

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload …

Dec 24, 2025
CVE-2024-58335
5.0 MEDIUM

OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/VisualizerImpl.java.

Dec 24, 2025
CVE-2025-66445
7.1 HIGH

Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue …

Dec 24, 2025
CVE-2025-66444
8.2 HIGH

Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue …

Dec 24, 2025
CVE-2025-13773
9.8 CRITICAL

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 …

Dec 24, 2025
CVE-2025-68695

Rejected reason: Not used

Dec 24, 2025
CVE-2025-68694

Rejected reason: Not used

Dec 24, 2025
CVE-2025-68693

Rejected reason: Not used

Dec 24, 2025
CVE-2025-68692

Rejected reason: Not used

Dec 24, 2025
CVE-2025-68691

Rejected reason: Not used

Dec 24, 2025
CVE-2025-68690

Rejected reason: Not used

Dec 24, 2025
CVE-2025-68689

Rejected reason: Not used

Dec 24, 2025
CVE-2025-68688

Rejected reason: Not used

Dec 24, 2025
CVE-2025-68687

Rejected reason: Not used

Dec 24, 2025
CVE-2025-15053
7.3 HIGH

A flaw has been found in code-projects Student Information System 1.0. This issue affects some unknown processing of the file /searchresults.php. Executing manipulation of the …

Dec 24, 2025
CVE-2025-15052
3.5 LOW

A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of the file /profile.php. Performing manipulation of the argument firstname/lastname …

Dec 24, 2025
CVE-2025-15050
6.3 MEDIUM

A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.php. Such manipulation of …

Dec 24, 2025
CVE-2025-68696
8.2 HIGH

httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, …

Dec 23, 2025
CVE-2025-68669
9.6 CRITICAL

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerability exists in useMarkdown.ts, where …

Dec 23, 2025
CVE-2025-68667

Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows a remote, unauthenticated attacker to force the …

Dec 23, 2025
CVE-2025-68665
8.6 HIGH

LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0.3.37 and 1.2.3, a serialization …

Dec 23, 2025
CVE-2025-68664
9.3 CRITICAL

LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and …

Dec 23, 2025
CVE-2025-68617
7.0 HIGH

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS …

Dec 23, 2025
CVE-2025-15049
7.3 HIGH

A vulnerability was identified in code-projects Online Farm System 1.0. Affected is an unknown function of the file /addProduct.php. The manipulation of the argument Username …

Dec 23, 2025
CVE-2025-15048
7.3 HIGH

A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing a …

Dec 23, 2025
CVE-2025-66213
8.8 HIGH

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the File …

Dec 23, 2025
CVE-2025-66212
8.8 HIGH

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Dynamic …

Dec 23, 2025
CVE-2025-66211
8.8 HIGH

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in PostgreSQL Init …

Dec 23, 2025
CVE-2025-66210
8.8 HIGH

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database …

Dec 23, 2025
CVE-2025-66209
9.9 CRITICAL

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database …

Dec 23, 2025
CVE-2025-15047
9.8 CRITICAL

A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing a …

Dec 23, 2025
CVE-2025-15046
9.8 CRITICAL

A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HTTP Request …

Dec 23, 2025
CVE-2025-14501
7.5 HIGH

Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations …

Dec 23, 2025
CVE-2025-14500
9.8 CRITICAL

IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IceWarp. Authentication is not …

Dec 23, 2025
CVE-2025-14499
8.8 HIGH

IceWarp gmaps Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of IceWarp. User interaction is required to …

Dec 23, 2025
CVE-2025-14498
7.8 HIGH

TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An …

Dec 23, 2025
CVE-2025-14497
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14496
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14495
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14494
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14493
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14492
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14491
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14490
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14489
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14488
7.8 HIGH

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker …

Dec 23, 2025
CVE-2025-14425
7.8 HIGH

GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. …

Dec 23, 2025
CVE-2025-14424
7.8 HIGH

GIMP XCF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction …

Dec 23, 2025
CVE-2025-14423
7.8 HIGH

GIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. …

Dec 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.