CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23178
7.6 HIGH

CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

Apr 29, 2025
CVE-2025-23177
7.6 HIGH

CWE-427: Uncontrolled Search Path Element

Apr 29, 2025
CVE-2025-1551
6.1 MEDIUM

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code …

Apr 29, 2025
CVE-2025-4067
5.3 MEDIUM

A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to …

Apr 29, 2025
CVE-2025-4066
7.3 HIGH

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/addpackage.php. The …

Apr 29, 2025
CVE-2025-4065
7.3 HIGH

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/addadvertisement.php. The manipulation …

Apr 29, 2025
CVE-2025-4093
8.1 HIGH

Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort …

Apr 29, 2025
CVE-2025-4092
6.5 MEDIUM

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Apr 29, 2025
CVE-2025-4091
8.1 HIGH

Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and …

Apr 29, 2025
CVE-2025-4090
5.3 MEDIUM

A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed in Firefox 138 and Thunderbird …

Apr 29, 2025
CVE-2025-4089
5.1 MEDIUM

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading …

Apr 29, 2025
CVE-2025-4088
6.5 MEDIUM

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the …

Apr 29, 2025
CVE-2025-4087
4.8 MEDIUM

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to …

Apr 29, 2025
CVE-2025-4086
6.5 MEDIUM

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug …

Apr 29, 2025
CVE-2025-4085
7.1 HIGH

An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was …

Apr 29, 2025
CVE-2025-4084
5.7 MEDIUM

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially …

Apr 29, 2025
CVE-2025-4083
9.1 CRITICAL

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead …

Apr 29, 2025
CVE-2025-4082
5.9 MEDIUM

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug …

Apr 29, 2025
CVE-2025-4064
5.3 MEDIUM

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation …

Apr 29, 2025
CVE-2025-4063
5.3 MEDIUM

A vulnerability was found in code-projects Student Information Management System 1.0 and classified as critical. Affected by this issue is the function cancel. The manipulation …

Apr 29, 2025
CVE-2025-4062
5.3 MEDIUM

A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by this vulnerability is the function cancel. The …

Apr 29, 2025
CVE-2025-3301

DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to …

Apr 29, 2025
CVE-2025-2817
8.8 HIGH

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged …

Apr 29, 2025
CVE-2025-4061
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0. Affected is the function add_item. The manipulation …

Apr 29, 2025
CVE-2025-4060
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. This issue affects some unknown processing of the file …

Apr 29, 2025
CVE-2025-4035
4.3 MEDIUM

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains …

Apr 29, 2025
CVE-2025-4059
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affects the function addrecord of the component Prison_Mgmt_Sys. The manipulation …

Apr 29, 2025
CVE-2025-4058
7.3 HIGH

A vulnerability classified as critical has been found in Projectworlds Online Examination System 1.0. This affects an unknown part of the file /Bloodgroop_process.php. The manipulation …

Apr 29, 2025
CVE-2025-3929
6.1 MEDIUM

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript …

Apr 29, 2025
CVE-2025-3891
7.5 HIGH

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by …

Apr 29, 2025
CVE-2025-30194
7.5 HIGH

When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that …

Apr 29, 2025
CVE-2025-1194
6.5 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability …

Apr 29, 2025
CVE-2024-58099
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported connectivity issues with Cilium's service …

Apr 29, 2025
CVE-2025-3452
4.3 MEDIUM

The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'secupress_reinstall_plugins_admin_ajax_cb' …

Apr 29, 2025
CVE-2025-2893
6.4 MEDIUM

The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown …

Apr 29, 2025
CVE-2024-12273
3.5 LOW

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 29, 2025
CVE-2025-46343
5.0 MEDIUM

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows …

Apr 29, 2025
CVE-2025-46338
6.1 MEDIUM

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to …

Apr 29, 2025
CVE-2025-46330
3.3 LOW

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code …

Apr 29, 2025
CVE-2025-46329
3.3 LOW

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging …

Apr 29, 2025
CVE-2025-46761

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46760

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46759

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46758

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46757

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46756

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46755

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46754

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46753

Rejected reason: Not used

Apr 29, 2025
CVE-2025-31203
6.5 MEDIUM

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.