CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30422
6.5 MEDIUM

A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker …

Apr 30, 2025
CVE-2025-24132
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on …

Apr 30, 2025
CVE-2022-42449
4.6 MEDIUM

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

Apr 30, 2025
CVE-2022-27562
4.6 MEDIUM

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

Apr 30, 2025
CVE-2025-4136
5.4 MEDIUM

A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the component Sale Endpoint. The …

Apr 30, 2025
CVE-2025-2082
7.5 HIGH

Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. …

Apr 30, 2025
CVE-2025-27611

base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, …

Apr 30, 2025
CVE-2024-6032
7.8 HIGH

Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S …

Apr 30, 2025
CVE-2024-6031
7.8 HIGH

Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model …

Apr 30, 2025
CVE-2024-6030
7.0 HIGH

Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected Tesla Model S vehicles. An …

Apr 30, 2025
CVE-2024-6029
5.0 MEDIUM

Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected …

Apr 30, 2025
CVE-2024-13943
7.8 HIGH

Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla …

Apr 30, 2025
CVE-2025-46558
9.0 CRITICAL

XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, …

Apr 30, 2025
CVE-2025-46557
9.8 CRITICAL

XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, …

Apr 30, 2025
CVE-2025-46554
5.3 MEDIUM

XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and …

Apr 30, 2025
CVE-2025-46331
9.8 CRITICAL

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker …

Apr 30, 2025
CVE-2025-32777

Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2, attacker compromise of either the Elastic service or the …

Apr 30, 2025
CVE-2025-2170
7.2 HIGH

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote …

Apr 30, 2025
CVE-2025-24887
6.3 MEDIUM

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user …

Apr 30, 2025
CVE-2024-9877
4.3 MEDIUM

: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through …

Apr 30, 2025
CVE-2024-9876
7.3 HIGH

: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

Apr 30, 2025
CVE-2024-47784
2.6 LOW

Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web …

Apr 30, 2025
CVE-2025-4135
6.3 MEDIUM

A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The manipulation of …

Apr 30, 2025
CVE-2025-46619
7.6 HIGH

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to …

Apr 30, 2025
CVE-2025-44194
7.3 HIGH

SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_household.

Apr 30, 2025
CVE-2025-44193
7.6 HIGH

SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.

Apr 30, 2025
CVE-2025-44192
9.8 CRITICAL

SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance.

Apr 30, 2025
CVE-2025-3269

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Apr 30, 2025
CVE-2025-39413
4.3 MEDIUM

Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This issue affects Simple Sitemap – Create a Responsive HTML Sitemap: …

Apr 30, 2025
CVE-2025-33074
7.5 HIGH

Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.

Apr 30, 2025
CVE-2025-30392
9.8 CRITICAL

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Apr 30, 2025
CVE-2025-30391
8.1 HIGH

Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.

Apr 30, 2025
CVE-2025-30390
9.9 CRITICAL

Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

Apr 30, 2025
CVE-2025-30389
8.7 HIGH

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Apr 30, 2025
CVE-2025-2156

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Apr 30, 2025
CVE-2025-24091
5.5 MEDIUM

An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An …

Apr 30, 2025
CVE-2025-21416
8.5 HIGH

Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

Apr 30, 2025
CVE-2025-3859
6.1 MEDIUM

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into …

Apr 30, 2025
CVE-2025-3599
6.5 MEDIUM

Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an …

Apr 30, 2025
CVE-2025-4122
6.3 MEDIUM

A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the function sub_435E04. The manipulation of …

Apr 30, 2025
CVE-2025-46342
8.5 HIGH

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using …

Apr 30, 2025
CVE-2025-32974
9.0 CRITICAL

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't …

Apr 30, 2025
CVE-2025-32973
9.0 CRITICAL

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, …

Apr 30, 2025
CVE-2025-32972
2.7 LOW

XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, …

Apr 30, 2025
CVE-2025-32971
3.8 LOW

XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, …

Apr 30, 2025
CVE-2025-32970
6.1 MEDIUM

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, …

Apr 30, 2025
CVE-2025-32376
4.3 MEDIUM

Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a …

Apr 30, 2025
CVE-2025-27409
7.5 HIGH

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version …

Apr 30, 2025
CVE-2025-27134
8.8 HIGH

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version …

Apr 30, 2025
CVE-2025-4121
6.3 MEDIUM

A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmd_wireless. The manipulation of …

Apr 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.