CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30175
7.5 HIGH

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA …

May 13, 2025
CVE-2025-30174
7.5 HIGH

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA …

May 13, 2025
CVE-2025-26390
9.8 CRITICAL

A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to …

May 13, 2025
CVE-2025-26389
10.0 CRITICAL

A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize …

May 13, 2025
CVE-2025-24510
6.5 MEDIUM

A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an …

May 13, 2025
CVE-2025-24009
5.9 MEDIUM

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not …

May 13, 2025
CVE-2025-24008
6.5 MEDIUM

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not …

May 13, 2025
CVE-2025-24007
7.5 HIGH

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). Affected devices only provide weak …

May 13, 2025
CVE-2025-22248
7.5 HIGH

The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside …

May 13, 2025
CVE-2024-51447
5.3 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an …

May 13, 2025
CVE-2024-51446
6.5 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected application improperly …

May 13, 2025
CVE-2024-51445
6.5 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection …

May 13, 2025
CVE-2024-51444
6.5 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read …

May 13, 2025
CVE-2024-23815
7.5 HIGH

A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of …

May 13, 2025
CVE-2025-41645
8.6 HIGH

An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.

May 13, 2025
CVE-2025-3916

CWE-121: Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these issues to potentially execute arbitrary code while the end …

May 13, 2025
CVE-2025-27696
8.8 HIGH

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: …

May 13, 2025
CVE-2025-4474
8.8 HIGH

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to …

May 13, 2025
CVE-2025-4473
8.8 HIGH

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions 1.0 to …

May 13, 2025
CVE-2025-4339
4.3 MEDIUM

The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxApi() function in all versions …

May 13, 2025
CVE-2025-4317
8.8 HIGH

The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all versions up …

May 13, 2025
CVE-2025-3107
6.5 MEDIUM

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to …

May 13, 2025
CVE-2025-4632
9.8 CRITICAL KEV

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as …

May 13, 2025
CVE-2025-22249
8.2 HIGH

VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a …

May 13, 2025
CVE-2025-22246
3.0 LOW

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.

May 13, 2025
CVE-2025-4396
7.5 HIGH

The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions …

May 13, 2025
CVE-2025-47864

Rejected reason: Not used

May 13, 2025
CVE-2025-47863

Rejected reason: Not used

May 13, 2025
CVE-2025-47862

Rejected reason: Not used

May 13, 2025
CVE-2025-47861

Rejected reason: Not used

May 13, 2025
CVE-2025-47860

Rejected reason: Not used

May 13, 2025
CVE-2025-47859

Rejected reason: Not used

May 13, 2025
CVE-2025-47858

Rejected reason: Not used

May 13, 2025
CVE-2025-35471
7.3 HIGH

conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. …

May 13, 2025
CVE-2025-43011
7.7 HIGH

Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. …

May 13, 2025
CVE-2025-43010
8.3 HIGH

SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain …

May 13, 2025
CVE-2025-43009
6.3 MEDIUM

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact …

May 13, 2025
CVE-2025-43008
5.8 MEDIUM

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. …

May 13, 2025
CVE-2025-43007
6.3 MEDIUM

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact …

May 13, 2025
CVE-2025-43006
6.1 MEDIUM

SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute malicious scripts in the application, potentially leading to a Cross-Site Scripting …

May 13, 2025
CVE-2025-43005
4.3 MEDIUM

SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT application to store user credentials. While this issue …

May 13, 2025
CVE-2025-43004
5.3 MEDIUM

Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access customer data when they access these …

May 13, 2025
CVE-2025-43003
6.4 MEDIUM

SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout …

May 13, 2025
CVE-2025-43002
4.3 MEDIUM

SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on …

May 13, 2025
CVE-2025-43000
7.9 HIGH

Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low …

May 13, 2025
CVE-2025-42999
9.1 CRITICAL KEV

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to …

May 13, 2025
CVE-2025-42997
6.6 MEDIUM

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of …

May 13, 2025
CVE-2025-31329
6.2 MEDIUM

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges …

May 13, 2025
CVE-2025-30018
8.6 HIGH

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file …

May 13, 2025
CVE-2025-30012
10.0 CRITICAL

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload …

May 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.