CVE / JVNDB Latest 100

IDDescriptionSeverity
CVE-2025-10405
2025-09-14 18:32:07 UTC

itsourcecode Baptism Information Management System listbaptism.php sql injection

MEDIUM
6.9
CVE-2025-10404
2025-09-14 18:02:08 UTC

itsourcecode Baptism Information Management System rptbaptismal.php sql injection

MEDIUM
6.9
CVE-2025-10403
2025-09-14 17:32:07 UTC

PHPGurukul Beauty Parlour Management System view-enquiry.php sql injection

MEDIUM
6.9
CVE-2025-6051
2025-09-14 17:03:03 UTC

Regular Expression Denial of Service (ReDoS) in huggingface/transformers

MEDIUM
5.3
CVE-2025-10402
2025-09-14 16:32:07 UTC

PHPGurukul Beauty Parlour Management System readenq.php sql injection

MEDIUM
6.9
CVE-2025-10401
2025-09-14 15:32:06 UTC

D-Link DIR-823x diag_ping command injection

MEDIUM
5.3
CVE-2025-10400
2025-09-14 14:02:07 UTC

SourceCodester Food Ordering Management System ticket-message.php sql injection

MEDIUM
5.3
CVE-2025-10399
2025-09-14 13:02:06 UTC

Korzh EasyQuery Query Builder UI fetch sql injection

MEDIUM
5.3
CVE-2025-0164
2025-09-14 12:57:32 UTC

IBM QRadar SIEM information disclosure

LOW
2.3
CVE-2025-36035
2025-09-14 12:52:49 UTC

IBM PowerVM Hypervisor denial of service

MEDIUM
6.7
CVE-2025-10204
2025-09-14 12:43:30 UTC

Unauth Admin Reset Password on AC Smart II

HIGH
7.1
CVE-2025-10398
2025-09-14 12:02:07 UTC

fcba_zzm ics-park Smart Park Management System FileUploadUtils.java unrestricted upload

MEDIUM
5.3
CVE-2025-10397
2025-09-14 11:02:06 UTC

Magicblack MacCMS API server-side request forgery

MEDIUM
5.1
CVE-2025-10396
2025-09-14 08:32:07 UTC

SourceCodester Pet Grooming Management Software edit_role.php sql injection

MEDIUM
6.9
CVE-2025-10395
2025-09-14 08:02:06 UTC

Magicblack MacCMS Scheduled Task col_url server-side request forgery

MEDIUM
5.1
CVE-2025-10394
2025-09-14 06:32:06 UTC

fcba_zzm ics-park Smart Park Management System Scheduled Task JobController.java code injection

MEDIUM
5.1
CVE-2025-10393
2025-09-14 06:02:07 UTC

miurla morphic HTTP Status Code 3xx advanced-search fetchHtml server-side request forgery

MEDIUM
5.3
CVE-2025-10392
2025-09-14 05:32:06 UTC

Mercury KM08-708H GiGA WiFi Wave2 HTTP Header stack-based overflow

CRITICAL
9.3
CVE-2025-10391
2025-09-14 05:02:07 UTC

CRMEB OutAccountServices.php testOutUrl server-side request forgery

MEDIUM
5.3
CVE-2025-59363
2025-09-14 04:51:44 UTC

In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),

HIGH
7.7
CVE-2025-10390
2025-09-14 04:32:05 UTC

CRMEB UserAddressServices.php editAddress improper authorization

MEDIUM
5.3
CVE-2025-10389
2025-09-14 04:02:06 UTC

CRMEB Administrator Password SystemAdminServices.php save improper authorization

MEDIUM
5.3
CVE-2025-10388
2025-09-14 03:32:07 UTC

Selleo Mentingo Create New Course Basic Settings enroll-course cross site scripting

MEDIUM
5.1
CVE-2025-10387
2025-09-14 03:02:06 UTC

codesiddhant Jasmin Ransomware handshake.php sql injection

MEDIUM
5.3
CVE-2025-10386
2025-09-14 01:32:07 UTC

Yida ECMS Consulting Enterprise Management System POST Request login.do cross site scripting

MEDIUM
5.3
CVE-2025-10385
2025-09-14 01:02:06 UTC

Mercury KM08-708H GiGA WiFi Wave2 mcr_setSysAdm sub_450B2C buffer overflow

HIGH
8.7
CVE-2024-0564
2025-09-14 00:09:20 UTC

Kernel: max page sharing of kernel samepage merging (ksm) may cause memory deduplication

MEDIUM
5.3
CVE-2025-10384
2025-09-13 19:32:07 UTC

yangzongzhuan RuoYi Role cancelAll improper authorization

MEDIUM
5.3
CVE-2025-10374
2025-09-13 19:02:07 UTC

Shenzhen Sixun Business Management System OperatorStop improper authorization

MEDIUM
6.9
CVE-2025-10373
2025-09-13 18:32:07 UTC

Portabilis i-Educar educar_turma_tipo_cad.php cross site scripting

MEDIUM
5.1
CVE-2025-10372
2025-09-13 18:02:05 UTC

Portabilis i-Educar educar_modulo_cad.php cross site scripting

MEDIUM
5.1
CVE-2025-10371
2025-09-13 17:32:06 UTC

eCharge Hardy Barth Salia PLCC api.php unrestricted upload

MEDIUM
6.9
CVE-2025-10370
2025-09-13 17:02:07 UTC

MiczFlor RPi-Jukebox-RFID userScripts.php cross site scripting

MEDIUM
5.1
CVE-2025-10369
2025-09-13 16:32:07 UTC

MiczFlor RPi-Jukebox-RFID cardRegisterNew.php cross site scripting

MEDIUM
5.1
CVE-2025-10368
2025-09-13 15:32:06 UTC

MiczFlor RPi-Jukebox-RFID manageFilesFolders.php cross site scripting

MEDIUM
5.1
CVE-2025-9135
2025-09-13 15:05:00 UTC

Verkehrsauskunft Österreich SmartRide/cleVVVer/BusBahnBim/Salzburg Verkehr AndroidManifest.xml improper export of android application components

MEDIUM
4.8
CVE-2025-10367
2025-09-13 14:02:07 UTC

MiczFlor RPi-Jukebox-RFID cardEdit.php cross site scripting

MEDIUM
5.1
CVE-2025-10366
2025-09-13 13:32:06 UTC

MiczFlor RPi-Jukebox-RFID inc.setWlanIpMail.php cross site scripting

MEDIUM
5.1
CVE-2025-10359
2025-09-13 13:02:05 UTC

Wavlink WL-WN578W2 wireless.cgi sub_404DBC os command injection

MEDIUM
6.9
CVE-2024-1394
2025-09-13 12:59:13 UTC

Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads

HIGH
7.5
CVE-2025-10358
2025-09-13 08:02:06 UTC

Wavlink WL-WN578W2 wireless.cgi sub_404850 os command injection

MEDIUM
6.9
CVE-2025-4234
2025-09-13 03:55:40 UTC

Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials

LOW
2.4
CVE-2025-36222
2025-09-13 03:55:39 UTC

IBM Fusion insecure default configuration

HIGH
8.7
CVE-2025-55319
2025-09-13 03:55:38 UTC

Agentic AI and Visual Studio Code Remote Code Execution Vulnerability

HIGH
8.8
CVE-2024-47120
2025-09-13 03:55:37 UTC

IBM Security Verify Information Queue code execution

MEDIUM
6.4
CVE-2025-21043
2025-09-13 03:55:36 UTC

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

HIGH
8.8
CVE-2025-21042
2025-09-13 03:55:35 UTC

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

HIGH
8.8
CVE-2025-27234
2025-09-13 03:55:35 UTC

Zabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.

HIGH
7.3
CVE-2025-27240
2025-09-13 03:55:34 UTC

Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host

HIGH
7.5
CVE-2025-4235
2025-09-13 03:55:32 UTC

User-ID Credential Agent: Cleartext Exposure of Service Account password

MEDIUM
5.8
CVE-2025-10340
2025-09-13 02:32:05 UTC

WhatCD Gazelle Commit Message change_log.php cross site scripting

MEDIUM
5.1
CVE-2025-10332
2025-09-13 02:02:06 UTC

cdevroe unmark info.php cross site scripting

MEDIUM
5.1
CVE-2025-10331
2025-09-13 01:02:07 UTC

cdevroe unmark Marks.php cross site scripting

MEDIUM
5.1
CVE-2025-10330
2025-09-12 23:02:07 UTC

cdevroe unmark searchform.php cross site scripting

MEDIUM
5.3
CVE-2025-10329
2025-09-12 22:02:06 UTC

cdevroe unmark Marks.php server-side request forgery

MEDIUM
5.3
CVE-2025-10328
2025-09-12 21:32:09 UTC

MiczFlor RPi-Jukebox-RFID playsinglefile.php os command injection

MEDIUM
5.3
CVE-2025-10176
2025-09-12 21:25:26 UTC

The Hack Repair Guy's Plugin Archiver <= 2.0.4 - Authenticated (Administrator+) Arbitrary File Deletion

HIGH
7.2
CVE-2025-10327
2025-09-12 21:02:06 UTC

MiczFlor RPi-Jukebox-RFID shuffle.php os command injection

MEDIUM
5.3
CVE-2025-10326
2025-09-12 20:32:05 UTC

MiczFlor RPi-Jukebox-RFID single.php os command injection

MEDIUM
5.3
CVE-2025-10325
2025-09-12 20:25:31 UTC

Wavlink WL-WN578W2 login.cgi sub_401BA4 command injection

MEDIUM
5.3
CVE-2025-45587
2025-09-12 20:13:34 UTC

A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2025-45586
2025-09-12 20:13:08 UTC

An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a crafted PUT request.

CVE-2025-45585
2025-09-12 20:12:38 UTC

Multiple stored cross-site scripting (XSS) vulnerabilities in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the wifi_sta_ssid or wifi_ap_ssid parameters.

CVE-2025-45584
2025-09-12 20:11:59 UTC

Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication.

CVE-2024-4629
2025-09-12 20:11:27 UTC

Keycloak: potential bypass of brute force protection

MEDIUM
6.5
CVE-2024-4540
2025-09-12 20:11:26 UTC

Keycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookie

HIGH
7.5
CVE-2024-5967
2025-09-12 20:11:18 UTC

Keycloak: leak of configured ldap bind credentials through the keycloak admin console

LOW
2.7
CVE-2025-43795
2025-09-12 20:11:09 UTC

Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_configuration_admin_web_portlet_SystemSettingsPortlet_redirect parameter.Open redirect vulnerability in the Instance Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_configuration_admin_web_portlet_InstanceSettingsPortlet_redirect parameter.Open redirect vulnerability in the Site Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_site_admin_web_portlet_SiteSettingsPortlet_redirect parameter.

MEDIUM
5.1
CVE-2025-45583
2025-09-12 20:10:36 UTC

Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.

CVE-2023-39418
2025-09-12 20:10:08 UTC

Postgresql: merge fails to enforce update or select row security policies

LOW
3.1
CVE-2023-4042
2025-09-12 20:10:04 UTC

Ghostscript: incomplete fix for cve-2020-16305

MEDIUM
5.5
CVE-2023-6484
2025-09-12 20:09:36 UTC

Keycloak: log injection during webauthn authentication or registration

MEDIUM
5.3
CVE-2024-9355
2025-09-12 20:07:36 UTC

Golang-fips: golang fips zeroed buffer

MEDIUM
6.5
CVE-2024-9407
2025-09-12 20:07:35 UTC

Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction

MEDIUM
4.7
CVE-2024-9341
2025-09-12 20:07:33 UTC

Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library

MEDIUM
5.4
CVE-2024-8676
2025-09-12 20:07:25 UTC

Cri-o: checkpoint restore can be triggered from different namespaces

HIGH
7.4
CVE-2024-8883
2025-09-12 20:07:25 UTC

Keycloak: vulnerable redirect uri validation results in open redirec

MEDIUM
6.1
CVE-2024-8418
2025-09-12 20:07:17 UTC

Containers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of service

HIGH
7.5
CVE-2024-8445
2025-09-12 20:07:17 UTC

389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for cve-2024-2199)

MEDIUM
5.7
CVE-2024-7341
2025-09-12 20:07:13 UTC

Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters

HIGH
7.1
CVE-2024-6655
2025-09-12 20:07:08 UTC

Gtk3: gtk2: library injection from cwd

HIGH
7.0
CVE-2024-6239
2025-09-12 20:07:05 UTC

Poppler: pdfinfo: crash in broken documents when using -dests parameter

HIGH
7.5
CVE-2024-6237
2025-09-12 20:07:03 UTC

389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request

MEDIUM
6.5
CVE-2024-5953
2025-09-12 20:06:58 UTC

389-ds-base: malformed userpassword hash may cause denial of service

MEDIUM
5.7
CVE-2025-0306
2025-09-12 20:06:05 UTC

Ruby: openssl: ruby marvin attack

HIGH
7.4
CVE-2024-3296
2025-09-12 20:05:20 UTC

Rust-openssl: timing based side-channel can lead to a bleichenbacher style attack

MEDIUM
5.9
CVE-2024-3056
2025-09-12 20:04:53 UTC

Podman: kernel: containers in shared ipc namespace are vulnerable to denial of service attack

HIGH
7.7
CVE-2024-56826
2025-09-12 20:04:14 UTC

Openjpeg: heap buffer overflow in bin/common/color.c

MEDIUM
5.6
CVE-2024-11029
2025-09-12 20:03:32 UTC

Freeipa: administrative user data leaked through systemd journal

MEDIUM
5.5
CVE-2024-10234
2025-09-12 20:03:26 UTC

Wildfly: wildfly vulnerable to cross-site scripting (xss)

MEDIUM
6.1
CVE-2024-1062
2025-09-12 20:03:23 UTC

389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)

MEDIUM
5.5
CVE-2024-1481
2025-09-12 20:03:21 UTC

Freeipa: specially crafted http requests potentially lead to denial of service

MEDIUM
5.3
CVE-2023-39329
2025-09-12 20:03:07 UTC

Openjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c

MEDIUM
6.5
CVE-2023-39328
2025-09-12 20:03:05 UTC

Openjpeg: denail of service via crafted image file

MEDIUM
5.5
CVE-2023-50782
2025-09-12 20:02:35 UTC

Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659

HIGH
7.5
CVE-2023-47039
2025-09-12 20:02:33 UTC

Perl: perl for windows binary hijacking vulnerability

HIGH
7.8
CVE-2023-47038
2025-09-12 20:02:30 UTC

Perl: write past buffer end via illegal user-defined unicode property

HIGH
7.0
CVE-2024-2199
2025-09-12 20:00:31 UTC

389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.c

MEDIUM
5.7
CVE-2023-6927
2025-09-12 19:59:53 UTC

Keycloak: open redirect via "form_post.jwt" jarm response mode

MEDIUM
4.6
CVE-2023-5455
2025-09-12 19:59:50 UTC

Ipa: invalid csrf protection

MEDIUM
6.5