CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-55912
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

May 2, 2025
CVE-2024-55910
6.5 MEDIUM

IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

May 2, 2025
CVE-2024-55909
6.5 MEDIUM

IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expansion of archive files without …

May 2, 2025
CVE-2025-4191
7.3 HIGH

A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality of …

May 2, 2025
CVE-2025-4186
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 2024. Affected is an unknown function of the file /?g=route_ispinfo_export_save. The manipulation …

May 2, 2025
CVE-2025-4185
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024. This issue affects some unknown processing of the file ?g=obj_area_export_save. …

May 2, 2025
CVE-2025-4184
7.3 HIGH

A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component QUOTE Command Handler. The manipulation …

May 2, 2025
CVE-2025-4183
7.3 HIGH

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RECV Command Handler. The …

May 1, 2025
CVE-2025-4182
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the …

May 1, 2025
CVE-2025-4181
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

May 1, 2025
CVE-2024-52903
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions …

May 1, 2025
CVE-2025-4180
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function of the component TRACE Command …

May 1, 2025
CVE-2025-4178
5.4 MEDIUM

A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and classified as critical. This issue affects some unknown processing of the file …

May 1, 2025
CVE-2025-4176
7.3 HIGH

A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as critical. This vulnerability affects unknown code of the …

May 1, 2025
CVE-2025-43595
7.8 HIGH

An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' …

May 1, 2025
CVE-2025-27365
6.5 MEDIUM

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 …

May 1, 2025
CVE-2025-1333
6.0 MEDIUM

IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, …

May 1, 2025
CVE-2025-4175
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. This affects the function uploadUserProfileImage of the file /Spring-Boot-Advanced-Projects-main/Project-4.SpringBoot-AWS-S3/backend/src/main/java/com/urunov/profile/UserProfileController.java of …

May 1, 2025
CVE-2024-48907
7.5 HIGH

Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.

May 1, 2025
CVE-2024-48906
6.1 MEDIUM

Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.

May 1, 2025
CVE-2024-48905
9.1 CRITICAL

Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

May 1, 2025
CVE-2025-46635
7.1 HIGH

An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces on the router …

May 1, 2025
CVE-2025-46634
8.2 HIGH

Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenticate to the …

May 1, 2025
CVE-2025-46633
8.2 HIGH

Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client …

May 1, 2025
CVE-2025-46632
6.5 MEDIUM

Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more …

May 1, 2025
CVE-2025-46631
6.5 MEDIUM

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the …

May 1, 2025
CVE-2025-46630
6.5 MEDIUM

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system …

May 1, 2025
CVE-2025-46629
6.5 MEDIUM

Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes …

May 1, 2025
CVE-2025-46628
7.3 HIGH

Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access …

May 1, 2025
CVE-2025-46627
8.2 HIGH

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password …

May 1, 2025
CVE-2025-46626
7.3 HIGH

Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an …

May 1, 2025
CVE-2025-46625
8.8 HIGH

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to …

May 1, 2025
CVE-2025-46569

Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data …

May 1, 2025
CVE-2025-29763

Rejected reason: “This CVE ID is Rejected and will not be used. The issue was determined to not be a vulnerability.”

May 1, 2025
CVE-2025-4174
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality …

May 1, 2025
CVE-2025-3517
6.3 MEDIUM

Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured …

May 1, 2025
CVE-2025-36558
6.1 MEDIUM

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with …

May 1, 2025
CVE-2025-36521
8.8 HIGH

MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open …

May 1, 2025
CVE-2025-35996
9.0 CRITICAL

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That …

May 1, 2025
CVE-2025-35975
8.8 HIGH

MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM …

May 1, 2025
CVE-2025-32011
9.8 CRITICAL

KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path …

May 1, 2025
CVE-2025-24522
10.0 CRITICAL

KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote …

May 1, 2025
CVE-2025-46568
7.5 HIGH

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to …

May 1, 2025
CVE-2025-46567
6.1 MEDIUM

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The …

May 1, 2025
CVE-2025-46566
9.8 CRITICAL

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue …

May 1, 2025
CVE-2025-46565
5.3 MEDIUM

Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root …

May 1, 2025
CVE-2025-46345

Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided …

May 1, 2025
CVE-2025-46337
10.0 CRITICAL

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query …

May 1, 2025
CVE-2025-44867
6.3 MEDIUM

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute …

May 1, 2025
CVE-2025-44866
6.3 MEDIUM

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerability allows attackers to execute …

May 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.