CVE Vulnerabilities
CVE vulnerability database enriched with CISA KEV and NVD data
| CVE ID | CVSS | Severity | KEV | Sightings |
|---|---|---|---|---|
| CVE-2025-61717 Rejected reason: Not used | N/A | NONE | — | 0 |
| CVE-2025-61718 Rejected reason: Not used | N/A | NONE | — | 0 |
| CVE-2025-61719 Rejected reason: Not used | N/A | NONE | — | 0 |
| CVE-2025-61720 Rejected reason: Not used | N/A | NONE | — | 0 |
| CVE-2025-61721 Rejected reason: Not used | N/A | NONE | — | 0 |
| CVE-2025-61722 Rejected reason: Not used | N/A | NONE | — | 0 |
| CVE-2025-10538 An authentication bypass vulnerability exists in LG Innotek camera models LND7210 and LNV7210R. The vulnerability allows a malicious actor to gain access to camera information including user account i... | N/A | NONE | — | 0 |
| CVE-2025-10735 The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.12 via the mcbSubmit_Form_Da... | 4.0 | MEDIUM | — | 0 |
| CVE-2025-9075 The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization ... | 6.4 | MEDIUM | — | 0 |
| CVE-2025-9512 The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modifications, making it possible for unauthenticated attackers to conduct Stored XS... | 6.1 | MEDIUM | — | 0 |
| CVE-2020-36852 The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a missing capability check and lack of suff... | 9.1 | CRITICAL | — | 0 |
| CVE-2025-10847 DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or ... | N/A | NONE | — | 0 |
| CVE-2022-50450 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | N/A | NONE | — | 0 |
| CVE-2022-50455 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | N/A | NONE | — | 0 |
| CVE-2023-53502 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | N/A | NONE | — | 0 |
| CVE-2025-40647 Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper validation of user input, through the 'email' parameter in '/index.php?menu=addres... | N/A | NONE | — | 0 |
| CVE-2025-40648 Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper validation of user input, through the 'numero_conferencia' parameter in '/index.ph... | N/A | NONE | — | 0 |
| CVE-2025-41421 Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access... | 4.7 | MEDIUM | — | 0 |
| CVE-2025-40649 Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infrastructure (BBMRI-ERIC), consisting of a stored XSS due to a lack of proper valida... | N/A | NONE | — | 0 |
| CVE-2025-52039 In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable to SQL Injection, which allows an attacker... | 8.2 | HIGH | — | 0 |
| CVE-2025-52040 In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can extract all information from databases by in... | 8.2 | HIGH | — | 0 |
| CVE-2025-52041 In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Injection, which allows an attacker to extrac... | 8.2 | HIGH | — | 0 |
| CVE-2025-52042 In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vulnerable to SQL Injection, which allows an attacker ... | 8.2 | HIGH | — | 0 |
| CVE-2025-57275 Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf. | 5.5 | MEDIUM | — | 0 |
| CVE-2025-59684 DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking. | 8.8 | HIGH | — | 0 |
| CVE-2025-59687 IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization. | 4.3 | MEDIUM | — | 0 |
| CVE-2025-61044 TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-61045 TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-56514 Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malicious SVG files are rendered by other users. | 5.4 | MEDIUM | — | 0 |
| CVE-2025-56515 File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded forei... | 8.8 | HIGH | — | 0 |
| CVE-2023-49881 IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | 6.3 | MEDIUM | — | 0 |
| CVE-2023-49883 IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | 5.9 | MEDIUM | — | 0 |
| CVE-2023-50300 IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls. | 5.1 | MEDIUM | — | 0 |
| CVE-2025-11233 Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle path separators, causing the standard library's Path API to ignore path componen... | N/A | NONE | — | 0 |
| CVE-2025-20356 A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the int... | 5.4 | MEDIUM | — | 0 |
| CVE-2025-43718 Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular express... | 2.9 | LOW | — | 0 |
| CVE-2025-20357 A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the int... | 5.4 | MEDIUM | — | 0 |
| CVE-2025-20361 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could al... | 4.8 | MEDIUM | — | 0 |
| CVE-2025-20366 In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin o... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-20367 In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' o... | 5.7 | MEDIUM | — | 0 |
| CVE-2025-20368 In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or... | 5.7 | MEDIUM | — | 0 |
| CVE-2025-57444 An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Management v33.0.4.50 allows attackers to execute arbitrary web scripts or HTML via... | 6.1 | MEDIUM | — | 0 |
| CVE-2025-20369 In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" o... | 4.6 | MEDIUM | — | 0 |
| CVE-2025-20370 In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the hig... | 4.9 | MEDIUM | — | 0 |
| CVE-2025-20371 In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a bl... | 7.5 | HIGH | — | 0 |
| CVE-2025-34182 In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the parameter ptpid is not sanitized of HTML-related characters/strings. This value is dire... | N/A | NONE | — | 0 |
| CVE-2025-61596 Rejected reason: This is a fork and is not in the Rust registry. | N/A | NONE | — | 0 |
| CVE-2024-57494 Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter. | 6.5 | MEDIUM | — | 0 |
| CVE-2025-28357 A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted HTTP request. | 8.8 | HIGH | — | 0 |
| CVE-2025-57393 A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted ... | 8.8 | HIGH | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.