CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-23917

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-23914

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21795

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21207

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21206

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21188

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21185

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21183

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21175

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21171

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21161

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-21135

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2025-5256
5.4 MEDIUM

SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to …

May 28, 2025
CVE-2025-48749
9.1 CRITICAL

Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.

May 28, 2025
CVE-2025-48747
5.0 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.

May 28, 2025
CVE-2025-47748
5.3 MEDIUM

Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.

May 28, 2025
CVE-2025-32803
4.0 MEDIUM

In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 …

May 28, 2025
CVE-2025-31501
7.2 HIGH

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

May 28, 2025
CVE-2025-31500
7.2 HIGH

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

May 28, 2025
CVE-2025-30087
7.2 HIGH

Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.

May 28, 2025
CVE-2025-1461
5.6 MEDIUM

Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsanitized HTML to be inserted into the page. This …

May 28, 2025
CVE-2024-57338
6.5 MEDIUM

An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute …

May 28, 2025
CVE-2024-57337
6.5 MEDIUM

An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to …

May 28, 2025
CVE-2024-57336
6.5 MEDIUM

Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.

May 28, 2025
CVE-2024-47057
5.3 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate …

May 28, 2025
CVE-2024-47055
4.3 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper …

May 28, 2025
CVE-2022-43502

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-43496

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-43493

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-40970

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-38092

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-36406

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-36298

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-34860

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-34859

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-33893

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-32233

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-29924

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-27877

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-27876

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-26038

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2025-5257
6.5 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This …

May 28, 2025
CVE-2025-48931
3.2 LOW

The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.

May 28, 2025
CVE-2025-48930
2.8 LOW

The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.

May 28, 2025
CVE-2025-48929
4.0 MEDIUM

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at …

May 28, 2025
CVE-2025-48928
4.0 MEDIUM KEV

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which …

May 28, 2025
CVE-2025-48927
5.3 MEDIUM KEV

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in …

May 28, 2025
CVE-2025-48926
4.3 MEDIUM

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

May 28, 2025
CVE-2025-48925
4.3 MEDIUM

The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as …

May 28, 2025
CVE-2025-48746
6.5 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.

May 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.