VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 958 of 1202 · EPSS data 2026.08.08
ReviewHigh
CVE-2025-20701

Airoha Technology Corp. AB156x, AB157x, AB158x, AB159x series

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-45150

langchain-chatglm-webui

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-52327

restaurant order system

SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-44139

emlog

Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50572

the affected product

Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. NOTE: the Supplier does not accept this as a valid vulnerability report against their product.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50850

cs-cart

An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50849

the affected product

CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through a parameter (company_id) sent in the request. However, this operation is not properly validated on the server side. An authenticated user can manipulate the request to target other users' accounts and toggle the sticker setting by modifying the company_id or other object identifiers.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50777

2mp full hd smart wi-fi cctv home security camera firmware, 2mp full hd smart wi-fi cctv home security camera

The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in plaintext, enabling further compromise of the network and connected systems.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-45955

zena

Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2025-31277

Apple Safari, iOS and iPadOS, macOS

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2025-28170

gxp1628 firmware, gxp1628

Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50486

e-diary management system

Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50485

online course registration

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.

The CVSS severity warrants an early asset and exposure review.