Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-66644 KEV |
|
[KEV] OS Command Injection in Array networks array-networks (CVE-2025-66644)
OS command injection in Array networks array-networks (CVE-2025-66644). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-34291 KEV |
|
[KEV] Vulnerability in langflow (CVE-2025-34291)
vulnerability in langflow (CVE-2025-34291). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2025-6946 |
|
Cross-Site Scripting (XSS) in watchguard (CVE-2025-6946)
cross-site scripting in watchguard (CVE-2025-6946). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-55182 KEV |
|
[KEV] Vulnerability in Meta react-server-components (CVE-2025-55182)
vulnerability in Meta react-server-components (CVE-2025-55182). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-13939 |
|
Cross-Site Scripting (XSS) in watchguard (CVE-2025-13939)
cross-site scripting in watchguard (CVE-2025-13939). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13940 |
|
Vulnerability in watchguard (CVE-2025-13940)
vulnerability in watchguard (CVE-2025-13940). Data can be tampered with by attackers.
|
| CVE-2025-1545 |
|
Vulnerability in watchguard (CVE-2025-1545)
vulnerability in watchguard (CVE-2025-1545). Confidential information can be exposed externally.
|
| CVE-2025-1547 |
|
Vulnerability in watchguard (CVE-2025-1547)
vulnerability in watchguard (CVE-2025-1547). Successful exploitation can lead to full system takeover.
|
| CVE-2025-12196 |
|
Out-of-Bounds Write in watchguard (CVE-2025-12196)
out-of-bounds write in watchguard (CVE-2025-12196). Successful exploitation can lead to full system takeover.
|
| CVE-2025-11838 |
|
Vulnerability in dos (CVE-2025-11838)
vulnerability in dos (CVE-2025-11838). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-12026 |
|
Out-of-Bounds Write in watchguard (CVE-2025-12026)
out-of-bounds write in watchguard (CVE-2025-12026). Successful exploitation can lead to full system takeover.
|
| CVE-2025-12195 |
|
Out-of-Bounds Write in watchguard (CVE-2025-12195)
out-of-bounds write in watchguard (CVE-2025-12195). Successful exploitation can lead to full system takeover.
|
| CVE-2025-40251 |
|
Vulnerability in c (CVE-2025-40251)
vulnerability in c (CVE-2025-40251). Successful exploitation can lead to full system takeover. Exploitable via ``rate_leaf_parent_set``.
|
| CVE-2021-26828 KEV |
|
[KEV] Unrestricted File Upload in Openplc scadabr (CVE-2021-26828)
vulnerability in Openplc scadabr (CVE-2021-26828). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-65955 |
|
Vulnerability in imagemagick (CVE-2025-65955)
vulnerability in imagemagick (CVE-2025-65955). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.1.2-9` or later.
|
| CVE-2025-13875 |
|
Path Traversal in path-traversal (CVE-2025-13875)
path traversal in path-traversal (CVE-2025-13875). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13879 |
|
Path Traversal in path-traversal (CVE-2025-13879)
path traversal in path-traversal (CVE-2025-13879). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-48633 KEV |
|
[KEV] Vulnerability in Android framework (CVE-2025-48633)
vulnerability in Android framework (CVE-2025-48633). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-48572 KEV |
|
[KEV] Vulnerability in Android platform/frameworks/base (CVE-2025-48572)
vulnerability in Android platform/frameworks/base (CVE-2025-48572). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `14:2025-12-01` or later.
|
| CVE-2025-13811 |
|
Vulnerability in sqli (CVE-2025-13811)
vulnerability in sqli (CVE-2025-13811). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13810 |
|
Path Traversal in path-traversal (CVE-2025-13810)
path traversal in path-traversal (CVE-2025-13810). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13809 |
|
SSRF (Server-Side Request Forgery) in orionsec (CVE-2025-13809)
SSRF in orionsec (CVE-2025-13809). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13808 |
|
Vulnerability in orionsec (CVE-2025-13808)
vulnerability in orionsec (CVE-2025-13808). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13807 |
|
Vulnerability in c (CVE-2025-13807)
vulnerability in c (CVE-2025-13807). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13804 |
|
Information Disclosure in CVE-2025-13804 (CVE-2025-13804)
vulnerability in CVE-2025-13804 (CVE-2025-13804). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13805 |
|
Vulnerability in deserialization (CVE-2025-13805)
vulnerability in deserialization (CVE-2025-13805). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13795 |
|
Cross-Site Scripting (XSS) in CVE-2025-13795 (CVE-2025-13795)
cross-site scripting in CVE-2025-13795 (CVE-2025-13795). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13793 |
|
Cross-Site Scripting (XSS) in CVE-2025-13793 (CVE-2025-13793)
cross-site scripting in CVE-2025-13793 (CVE-2025-13793). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13792 |
|
Vulnerability in CVE-2025-13792 (CVE-2025-13792)
vulnerability in CVE-2025-13792 (CVE-2025-13792). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13791 |
|
Path Traversal in path-traversal (CVE-2025-13791)
path traversal in path-traversal (CVE-2025-13791). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13789 |
|
SSRF (Server-Side Request Forgery) in zentao (CVE-2025-13789)
SSRF in zentao (CVE-2025-13789). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13788 |
|
Vulnerability in sqli (CVE-2025-13788)
vulnerability in sqli (CVE-2025-13788). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13787 |
|
Vulnerability in zentao (CVE-2025-13787)
vulnerability in zentao (CVE-2025-13787). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13786 |
|
Vulnerability in wtcms-project (CVE-2025-13786)
vulnerability in wtcms-project (CVE-2025-13786). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-26829 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Openplc scadabr (CVE-2021-26829)
cross-site scripting in Openplc scadabr (CVE-2021-26829). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-61167 |
|
SQL Injection in sqli (CVE-2025-61167)
SQL injection in sqli (CVE-2025-61167). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61168 |
|
Unsafe Deserialization in sigb (CVE-2025-61168)
vulnerability in sigb (CVE-2025-61168). Successful exploitation can lead to full system takeover.
|
| CVE-2025-64047 |
|
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.
|
| CVE-2025-64048 |
|
Cross-Site Scripting (XSS) in yccms (CVE-2025-64048)
cross-site scripting in yccms (CVE-2025-64048). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61757 KEV |
|
[KEV] Vulnerability in Oracle fusion-middleware (CVE-2025-61757)
vulnerability in Oracle fusion-middleware (CVE-2025-61757). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-13223 KEV |
|
[KEV] Vulnerability in Google chromium-v8 (CVE-2025-13223)
vulnerability in Google chromium-v8 (CVE-2025-13223). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-61662 |
|
Use-After-Free in dos (CVE-2025-61662)
vulnerability in dos (CVE-2025-61662). Successful exploitation can lead to full system takeover.
|
| CVE-2025-58413 |
|
Vulnerability in fortinet (CVE-2025-58413)
vulnerability in fortinet (CVE-2025-58413). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53843 |
|
Vulnerability in fortinet (CVE-2025-53843)
vulnerability in fortinet (CVE-2025-53843). Successful exploitation can lead to full system takeover.
|
| CVE-2025-54821 |
|
Privilege Escalation in fortinet (CVE-2025-54821)
vulnerability in fortinet (CVE-2025-54821). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-63892 |
|
Cross-Site Scripting (XSS) in remyandrade (CVE-2025-63892)
cross-site scripting in remyandrade (CVE-2025-63892). Successful exploitation can lead to full system takeover.
|
| CVE-2025-58034 KEV |
|
[KEV] OS Command Injection in Fortinet fortiweb (CVE-2025-58034)
OS command injection in Fortinet fortiweb (CVE-2025-58034). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-63748 |
|
Unrestricted File Upload in testmanagement (CVE-2025-63748)
vulnerability in testmanagement (CVE-2025-63748). Successful exploitation can lead to full system takeover.
|
| CVE-2025-64046 |
|
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
|
| CVE-2025-64446 KEV |
|
[KEV] Vulnerability in Fortinet fortiweb (CVE-2025-64446)
vulnerability in Fortinet fortiweb (CVE-2025-64446). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|