CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49576
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing …

Jun 12, 2025
CVE-2025-49575
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing …

Jun 12, 2025
CVE-2025-49081
4.9 MEDIUM

There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions …

Jun 12, 2025
CVE-2025-43866
7.5 HIGH

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The …

Jun 12, 2025
CVE-2025-43863
9.8 CRITICAL

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access …

Jun 12, 2025
CVE-2025-5982
3.7 LOW

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions …

Jun 12, 2025
CVE-2025-49080
7.5 HIGH

There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a …

Jun 12, 2025
CVE-2024-55567
7.5 HIGH

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The …

Jun 12, 2025
CVE-2023-45256
5.4 MEDIUM

Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, …

Jun 12, 2025
CVE-2025-49467

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible …

Jun 12, 2025
CVE-2025-46035
7.5 HIGH

Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in …

Jun 12, 2025
CVE-2025-36573
7.1 HIGH

Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially …

Jun 12, 2025
CVE-2025-29744
5.4 MEDIUM

pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.

Jun 12, 2025
CVE-2024-7562

A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield 2023 …

Jun 12, 2025
CVE-2024-44906
6.5 MEDIUM

uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is …

Jun 12, 2025
CVE-2024-44905
6.5 MEDIUM

go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.

Jun 12, 2025
CVE-2025-49200
6.5 MEDIUM

The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.

Jun 12, 2025
CVE-2025-49199
8.8 HIGH

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. …

Jun 12, 2025
CVE-2025-49198
3.1 LOW

The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by …

Jun 12, 2025
CVE-2025-49197
6.5 MEDIUM

The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.

Jun 12, 2025
CVE-2025-49196
6.5 MEDIUM

A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways …

Jun 12, 2025
CVE-2025-49195
5.3 MEDIUM

The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.

Jun 12, 2025
CVE-2025-49194
7.5 HIGH

The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept traffic between a client …

Jun 12, 2025
CVE-2025-49193
4.2 MEDIUM

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application …

Jun 12, 2025
CVE-2025-49192
4.3 MEDIUM

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking …

Jun 12, 2025
CVE-2024-56158
9.8 CRITICAL

XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki …

Jun 12, 2025
CVE-2025-49191
4.8 MEDIUM

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible …

Jun 12, 2025
CVE-2025-49190
4.3 MEDIUM

The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.

Jun 12, 2025
CVE-2025-49189
5.3 MEDIUM

The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag …

Jun 12, 2025
CVE-2025-49188
5.3 MEDIUM

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

Jun 12, 2025
CVE-2025-49187
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Jun 12, 2025
CVE-2025-49186
5.3 MEDIUM

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

Jun 12, 2025
CVE-2025-49185
5.5 MEDIUM

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function …

Jun 12, 2025
CVE-2025-49184
7.5 HIGH

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.

Jun 12, 2025
CVE-2025-49183
7.5 HIGH

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the …

Jun 12, 2025
CVE-2025-49182
7.5 HIGH

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to …

Jun 12, 2025
CVE-2025-49181
8.6 HIGH

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP …

Jun 12, 2025
CVE-2024-9512
5.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may …

Jun 12, 2025
CVE-2025-6021
7.5 HIGH

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can …

Jun 12, 2025
CVE-2025-5195
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible …

Jun 12, 2025
CVE-2025-0673
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker …

Jun 12, 2025
CVE-2025-5996
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of …

Jun 12, 2025
CVE-2025-4278
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page …

Jun 12, 2025
CVE-2025-2254
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding …

Jun 12, 2025
CVE-2025-1516
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation …

Jun 12, 2025
CVE-2025-1478
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of …

Jun 12, 2025
CVE-2025-6003
5.3 MEDIUM

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions …

Jun 12, 2025
CVE-2025-4613
8.8 HIGH

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into …

Jun 12, 2025
CVE-2025-5301
6.1 MEDIUM

ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. …

Jun 12, 2025
CVE-2025-40592
6.1 MEDIUM

A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All versions < V10.12.17), Mendix Studio Pro …

Jun 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.