CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-33138
5.4 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

May 22, 2025
CVE-2025-33137
7.1 HIGH

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due …

May 22, 2025
CVE-2025-33136
7.1 HIGH

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due …

May 22, 2025
CVE-2024-48853
9.0 CRITICAL

An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. …

May 22, 2025
CVE-2024-48850
7.2 HIGH

Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: …

May 22, 2025
CVE-2025-5081
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminprofile.php. …

May 22, 2025
CVE-2025-4366
6.1 MEDIUM

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading …

May 22, 2025
CVE-2025-45468
8.8 HIGH

Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.

May 22, 2025
CVE-2025-2506
5.3 MEDIUM

When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a …

May 22, 2025
CVE-2025-23183
6.1 MEDIUM

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

May 22, 2025
CVE-2025-23182
4.3 MEDIUM

CWE-203: Observable Discrepancy

May 22, 2025
CVE-2025-5080
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the …

May 22, 2025
CVE-2025-5079
7.3 HIGH

A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/updateorder.php. Executing manipulation …

May 22, 2025
CVE-2025-5024
7.4 HIGH

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There …

May 22, 2025
CVE-2025-45471
8.8 HIGH

Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.

May 22, 2025
CVE-2025-32915
5.5 MEDIUM

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 …

May 22, 2025
CVE-2025-32815
6.5 MEDIUM

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

May 22, 2025
CVE-2025-32814
9.8 CRITICAL

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

May 22, 2025
CVE-2025-32813
7.2 HIGH

An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

May 22, 2025
CVE-2025-0993
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated …

May 22, 2025
CVE-2025-0679
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions …

May 22, 2025
CVE-2025-0605
4.6 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls …

May 22, 2025
CVE-2024-54188
5.3 MEDIUM

Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root access.

May 22, 2025
CVE-2024-12093
6.8 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation …

May 22, 2025
CVE-2025-5078
7.3 HIGH

A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. Performing manipulation of the argument Category …

May 22, 2025
CVE-2025-5077
7.3 HIGH

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. …

May 22, 2025
CVE-2025-5076
7.3 HIGH

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component SEND …

May 22, 2025
CVE-2025-4979
4.9 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able …

May 22, 2025
CVE-2025-4575
6.5 MEDIUM

Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: …

May 22, 2025
CVE-2025-3111
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of …

May 22, 2025
CVE-2025-2853
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation …

May 22, 2025
CVE-2025-1110
2.7 LOW

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access …

May 22, 2025
CVE-2023-47466
2.9 LOW

TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the …

May 22, 2025
CVE-2025-5075
7.3 HIGH

A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component …

May 22, 2025
CVE-2025-46714
7.8 HIGH

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an …

May 22, 2025
CVE-2025-46713
7.8 HIGH

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 0.0.1 and prior to 1.15.12, API_SET_SECURE_PARAM may have …

May 22, 2025
CVE-2025-3945
7.2 HIGH

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command …

May 22, 2025
CVE-2025-3944
7.2 HIGH

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects …

May 22, 2025
CVE-2025-3943
4.1 MEDIUM

Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, …

May 22, 2025
CVE-2025-3942
4.3 MEDIUM

Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data …

May 22, 2025
CVE-2025-3941
5.4 MEDIUM

Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. …

May 22, 2025
CVE-2025-3940
5.3 MEDIUM

Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data …

May 22, 2025
CVE-2025-3939
5.3 MEDIUM

Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects …

May 22, 2025
CVE-2025-3938
6.8 MEDIUM

Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects …

May 22, 2025
CVE-2025-3937
7.7 HIGH

Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX …

May 22, 2025
CVE-2025-3936
6.5 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Exploiting Incorrectly Configured Access Control …

May 22, 2025
CVE-2025-2272
7.0 HIGH

Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process.This issue affects FIE Endpoint: before 25.05.

May 22, 2025
CVE-2025-5074
7.3 HIGH

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component PROMPT Command Handler. …

May 22, 2025
CVE-2025-5073
7.3 HIGH

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some unknown processing of the component MKDIR …

May 22, 2025
CVE-2025-41403
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.

May 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.