CVE Database

116976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43596
7.8 HIGH

An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially …

May 22, 2025
CVE-2025-33138
5.4 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

May 22, 2025
CVE-2025-33137
7.1 HIGH

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due …

May 22, 2025
CVE-2025-33136
7.1 HIGH

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due …

May 22, 2025
CVE-2024-48853
9.0 CRITICAL

An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. …

May 22, 2025
CVE-2024-48850
7.2 HIGH

Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: …

May 22, 2025
CVE-2025-5081
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminprofile.php. …

May 22, 2025
CVE-2025-4366
6.1 MEDIUM

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading …

May 22, 2025
CVE-2025-45468
8.8 HIGH

Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.

May 22, 2025
CVE-2025-2506
5.3 MEDIUM

When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a …

May 22, 2025
CVE-2025-23183
6.1 MEDIUM

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

May 22, 2025
CVE-2025-23182
4.3 MEDIUM

CWE-203: Observable Discrepancy

May 22, 2025
CVE-2025-5080
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the …

May 22, 2025
CVE-2025-5079
7.3 HIGH

A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/updateorder.php. Executing manipulation …

May 22, 2025
CVE-2025-5024
7.4 HIGH

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There …

May 22, 2025
CVE-2025-45471
8.8 HIGH

Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.

May 22, 2025
CVE-2025-32915
5.5 MEDIUM

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 …

May 22, 2025
CVE-2025-32815
6.5 MEDIUM

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

May 22, 2025
CVE-2025-32814
9.8 CRITICAL

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

May 22, 2025
CVE-2025-32813
7.2 HIGH

An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

May 22, 2025
CVE-2025-0993
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated …

May 22, 2025
CVE-2025-0679
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions …

May 22, 2025
CVE-2025-0605
4.6 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls …

May 22, 2025
CVE-2024-54188
5.3 MEDIUM

Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root access.

May 22, 2025
CVE-2024-12093
6.8 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation …

May 22, 2025
CVE-2025-5078
7.3 HIGH

A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. Performing manipulation of the argument Category …

May 22, 2025
CVE-2025-5077
7.3 HIGH

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. …

May 22, 2025
CVE-2025-5076
7.3 HIGH

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component SEND …

May 22, 2025
CVE-2025-4979
4.9 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able …

May 22, 2025
CVE-2025-4575
6.5 MEDIUM

Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: …

May 22, 2025
CVE-2025-3111
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of …

May 22, 2025
CVE-2025-2853
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation …

May 22, 2025
CVE-2025-1110
2.7 LOW

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access …

May 22, 2025
CVE-2023-47466
2.9 LOW

TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the …

May 22, 2025
CVE-2025-5075
7.3 HIGH

A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component …

May 22, 2025
CVE-2025-46714
7.8 HIGH

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an …

May 22, 2025
CVE-2025-46713
7.8 HIGH

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 0.0.1 and prior to 1.15.12, API_SET_SECURE_PARAM may have …

May 22, 2025
CVE-2025-3945
7.2 HIGH

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command …

May 22, 2025
CVE-2025-3944
7.2 HIGH

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects …

May 22, 2025
CVE-2025-3943
4.1 MEDIUM

Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, …

May 22, 2025
CVE-2025-3942
4.3 MEDIUM

Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data …

May 22, 2025
CVE-2025-3941
5.4 MEDIUM

Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. …

May 22, 2025
CVE-2025-3940
5.3 MEDIUM

Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data …

May 22, 2025
CVE-2025-3939
5.3 MEDIUM

Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects …

May 22, 2025
CVE-2025-3938
6.8 MEDIUM

Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects …

May 22, 2025
CVE-2025-3937
7.7 HIGH

Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX …

May 22, 2025
CVE-2025-3936
6.5 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Exploiting Incorrectly Configured Access Control …

May 22, 2025
CVE-2025-2272
7.0 HIGH

Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process.This issue affects FIE Endpoint: before 25.05.

May 22, 2025
CVE-2025-5074
7.3 HIGH

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component PROMPT Command Handler. …

May 22, 2025
CVE-2025-5073
7.3 HIGH

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some unknown processing of the component MKDIR …

May 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.