CVE Database

138577+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-61740

Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-service condition or modify the configuration …

Dec 22, 2025
CVE-2025-26379

Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.

Dec 22, 2025
CVE-2025-14018
7.3 HIGH

Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Libraries.This issue affects e-Fatura: …

Dec 22, 2025
CVE-2025-14273
7.2 HIGH

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 …

Dec 22, 2025
CVE-2025-8460
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Notification rules, Open tickets module) allows Stored XSS …

Dec 22, 2025
CVE-2025-61739

Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.

Dec 22, 2025
CVE-2025-61738

Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.

Dec 22, 2025
CVE-2025-54890
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hostgroup configuration page) allows Stored XSS by users …

Dec 22, 2025
CVE-2025-12514
7.2 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration parameters, Open tickets …

Dec 22, 2025
CVE-2025-62880
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through <= …

Dec 22, 2025
CVE-2025-62107
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Request Forgery.This issue affects Feather Login Page: from n/a through <= …

Dec 22, 2025
CVE-2025-62094
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidthemes Void Elementor WHMCS Elements For Elementor Page Builder void-elementor-whmcs-elements.This issue affects Void …

Dec 22, 2025
CVE-2025-8305
6.5 MEDIUM

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in …

Dec 22, 2025
CVE-2025-8304
6.5 MEDIUM

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows …

Dec 22, 2025
CVE-2025-11545

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a attacker may improperly access the HTTP server …

Dec 22, 2025
CVE-2025-11544

Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware.

Dec 22, 2025
CVE-2025-15014
6.3 MEDIUM

A security flaw has been discovered in loganhong php loganSite up to c035fb5c3edd0b2a5e32fd4051cbbc9e61a31426. This affects an unknown function of the file /includes/article_detail.php of the component …

Dec 22, 2025
CVE-2025-15013
5.3 MEDIUM

A vulnerability was identified in floooh sokol up to 5d11344150973f15e16d3ec4ee7550a73fb995e0. The impacted element is the function _sg_validate_pipeline_desc in the library sokol_gfx.h. Such manipulation leads to …

Dec 22, 2025
CVE-2025-15012
7.3 HIGH

A vulnerability was determined in code-projects Refugee Food Management System 1.0. The affected element is an unknown function of the file /home/home.php. This manipulation of …

Dec 22, 2025
CVE-2025-12049
9.8 CRITICAL

Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of …

Dec 22, 2025
CVE-2025-11543
9.8 CRITICAL

Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware.

Dec 22, 2025
CVE-2025-11542
9.8 CRITICAL

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.

Dec 22, 2025
CVE-2025-11541
9.8 CRITICAL

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.

Dec 22, 2025
CVE-2025-11540
7.5 HIGH

Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

Dec 22, 2025
CVE-2025-59301
4.0 MEDIUM

Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.

Dec 22, 2025
CVE-2025-15016
9.8 CRITICAL

Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information …

Dec 22, 2025
CVE-2025-15015
7.5 HIGH

Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system …

Dec 22, 2025
CVE-2025-15011
7.3 HIGH

A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.php. The manipulation of the argument uname …

Dec 22, 2025
CVE-2025-15010
9.8 CRITICAL

A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulation of the argument page …

Dec 22, 2025
CVE-2025-15009
6.3 MEDIUM

A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/common/upload of the component Filename …

Dec 22, 2025
CVE-2025-15008
7.3 HIGH

A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a …

Dec 22, 2025
CVE-2025-15007
9.8 CRITICAL

A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of the component …

Dec 22, 2025
CVE-2025-15006
9.8 CRITICAL

A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of the component HTTP …

Dec 22, 2025
CVE-2025-15005
3.7 LOW

A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. …

Dec 22, 2025
CVE-2025-15004
6.3 MEDIUM

A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads …

Dec 22, 2025
CVE-2025-15003
4.7 MEDIUM

A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php. Performing a manipulation of the …

Dec 22, 2025
CVE-2025-15002
7.3 HIGH

A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the …

Dec 21, 2025
CVE-2025-62926
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool [Show Current Template Info] current-template-name allows Stored XSS.This issue affects TempTool …

Dec 21, 2025
CVE-2025-62901
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten WP Microdata wp-microdata allows Stored XSS.This issue affects WP Microdata: from n/a …

Dec 21, 2025
CVE-2025-62955
4.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool [Show Current Template Info] current-template-name allows Retrieve Embedded Sensitive Data.This issue …

Dec 21, 2025
CVE-2025-14995
8.8 HIGH

A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads …

Dec 21, 2025
CVE-2025-14994
8.8 HIGH

A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the file /goform/webtypelibrary of the component HTTP Request …

Dec 21, 2025
CVE-2025-14855
7.2 HIGH

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due …

Dec 21, 2025
CVE-2025-14800
8.1 HIGH

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function …

Dec 21, 2025
CVE-2025-14993
8.8 HIGH

A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation …

Dec 21, 2025
CVE-2025-9343
7.2 HIGH

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, …

Dec 21, 2025
CVE-2025-68644
7.4 HIGH

Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security …

Dec 21, 2025
CVE-2025-14992
8.8 HIGH

A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the file /goform/GetParentControlInfo of the component HTTP …

Dec 21, 2025
CVE-2025-14991
2.4 LOW

A weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/bwdates-reports-details.php. …

Dec 21, 2025
CVE-2025-14990
7.3 HIGH

A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing …

Dec 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.