CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10865

Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5.

May 14, 2025
CVE-2024-10864

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5

May 14, 2025
CVE-2025-47436
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files …

May 14, 2025
CVE-2025-3600
7.5 HIGH

In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a …

May 14, 2025
CVE-2025-22756

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 14, 2025
CVE-2024-57273
5.4 MEDIUM

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, …

May 14, 2025
CVE-2024-54780
8.8 HIGH

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization …

May 14, 2025
CVE-2024-54779
5.4 MEDIUM

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

May 14, 2025
CVE-2023-53146
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer() In dw2102_i2c_transfer, msg is controlled by user. When msg[i].buf …

May 14, 2025
CVE-2025-47445
7.5 HIGH

Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.

May 14, 2025
CVE-2025-3931
7.8 HIGH

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus …

May 14, 2025
CVE-2025-3769
5.3 MEDIUM

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

May 14, 2025
CVE-2025-4430

Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (published on 22nd August 2024).

May 14, 2025
CVE-2025-47292

Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which …

May 14, 2025
CVE-2025-3834
8.1 HIGH

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.

May 14, 2025
CVE-2025-3833
8.1 HIGH

Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

May 14, 2025
CVE-2025-26864
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects …

May 14, 2025
CVE-2025-26795
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: …

May 14, 2025
CVE-2024-24780
9.8 CRITICAL

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from …

May 14, 2025
CVE-2025-2875
7.5 HIGH

CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s …

May 14, 2025
CVE-2024-8988
5.3 MEDIUM

The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the …

May 14, 2025
CVE-2024-13940
5.5 MEDIUM

The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form webhook …

May 14, 2025
CVE-2025-0020

Rejected reason: “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE as it is …

May 14, 2025
CVE-2024-52290
6.3 MEDIUM

LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate …

May 14, 2025
CVE-2025-47899

Rejected reason: Not used

May 14, 2025
CVE-2025-47898

Rejected reason: Not used

May 14, 2025
CVE-2025-47897

Rejected reason: Not used

May 14, 2025
CVE-2025-47896

Rejected reason: Not used

May 14, 2025
CVE-2025-47895

Rejected reason: Not used

May 14, 2025
CVE-2025-47894

Rejected reason: Not used

May 14, 2025
CVE-2025-47893

Rejected reason: Not used

May 14, 2025
CVE-2025-47892

Rejected reason: Not used

May 14, 2025
CVE-2025-47891

Rejected reason: Not used

May 14, 2025
CVE-2025-4520
5.4 MEDIUM

The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions …

May 14, 2025
CVE-2025-3623
9.1 CRITICAL

The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input …

May 14, 2025
CVE-2025-4574
6.5 MEDIUM

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could …

May 13, 2025
CVE-2025-47905
5.4 MEDIUM

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF …

May 13, 2025
CVE-2025-26646
8.0 HIGH

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over …

May 13, 2025
CVE-2025-43572
7.8 HIGH

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current …

May 13, 2025
CVE-2025-43571
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43570
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43569
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 13, 2025
CVE-2025-43568
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43567
9.3 CRITICAL

Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious …

May 13, 2025
CVE-2025-43566
6.8 MEDIUM

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could …

May 13, 2025
CVE-2025-43565
8.4 HIGH

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of …

May 13, 2025
CVE-2025-43564
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged …

May 13, 2025
CVE-2025-43563
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged …

May 13, 2025
CVE-2025-43562
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability …

May 13, 2025
CVE-2025-43561
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

May 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.