CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24252
8.8 HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-24251
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, …

Apr 29, 2025
CVE-2025-24206
7.7 HIGH

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-24179
5.7 MEDIUM

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, …

Apr 29, 2025
CVE-2018-13372

Rejected reason: Not used

Apr 29, 2025
CVE-2017-7740

Rejected reason: Not used

Apr 29, 2025
CVE-2025-46328
3.3 LOW

snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When …

Apr 28, 2025
CVE-2025-46327
3.3 LOW

gosnowflake is the Snowflake Golang driver. Versions starting from 1.7.0 to before 1.13.3, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using …

Apr 28, 2025
CVE-2025-46326
3.3 LOW

snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When …

Apr 28, 2025
CVE-2025-4039
7.3 HIGH

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 28, 2025
CVE-2025-4038
5.3 MEDIUM

A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is the function Reservation …

Apr 28, 2025
CVE-2025-4037
4.4 MEDIUM

A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function moneyDeposit/moneyWithdraw. The manipulation leads to business …

Apr 28, 2025
CVE-2025-0049
3.5 LOW

When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server …

Apr 28, 2025
CVE-2024-11922
6.3 MEDIUM

Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails …

Apr 28, 2025
CVE-2024-10635
6.1 MEDIUM

Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending …

Apr 28, 2025
CVE-2025-4036
6.3 MEDIUM

A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBookChapter of the file src/main/java/io/github/xxyopen/novel/controller/author/AuthorController.java of the component …

Apr 28, 2025
CVE-2025-4034
7.3 HIGH

A vulnerability classified as critical was found in projectworlds Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /inser_doc_process.php. …

Apr 28, 2025
CVE-2025-45953
9.1 CRITICAL

A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of …

Apr 28, 2025
CVE-2025-45949
9.8 CRITICAL

A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - …

Apr 28, 2025
CVE-2025-45947
9.8 CRITICAL

An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - …

Apr 28, 2025
CVE-2025-3224
7.8 HIGH

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to …

Apr 28, 2025
CVE-2025-34491
8.8 HIGH

GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted …

Apr 28, 2025
CVE-2025-31651
9.8 CRITICAL

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a …

Apr 28, 2025
CVE-2025-31650
7.5 HIGH

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which …

Apr 28, 2025
CVE-2025-4033
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. Affected is an unknown function of the file /patient-search-report.php. …

Apr 28, 2025
CVE-2025-4032
5.0 MEDIUM

A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the function subprocess.run/subprocess.Popen of the file …

Apr 28, 2025
CVE-2025-34490
6.5 MEDIUM

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests …

Apr 28, 2025
CVE-2025-34489
7.8 HIGH

GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by sending a …

Apr 28, 2025
CVE-2025-4031
7.3 HIGH

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/aboutus.php. …

Apr 28, 2025
CVE-2025-4030
7.3 HIGH

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 28, 2025
CVE-2024-12706

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated …

Apr 28, 2025
CVE-2025-4029
5.3 MEDIUM

A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by this issue is the function addrecord of the …

Apr 28, 2025
CVE-2025-4028
7.3 HIGH

A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 28, 2025
CVE-2024-32499
4.9 MEDIUM

Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.

Apr 28, 2025
CVE-2023-42404
4.9 MEDIUM

OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.

Apr 28, 2025
CVE-2025-4027
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file …

Apr 28, 2025
CVE-2025-4026
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of …

Apr 28, 2025
CVE-2025-46614
3.3 LOW

In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive …

Apr 28, 2025
CVE-2025-43857
6.5 MEDIUM

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial …

Apr 28, 2025
CVE-2025-43854
6.1 MEDIUM

DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, …

Apr 28, 2025
CVE-2023-35817
5.0 MEDIUM

DevExpress before 23.1.3 allows AsyncDownloader SSRF.

Apr 28, 2025
CVE-2023-35816
3.5 LOW

DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.

Apr 28, 2025
CVE-2023-35815
3.5 LOW

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

Apr 28, 2025
CVE-2023-35814
3.5 LOW

DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

Apr 28, 2025
CVE-2022-41871
6.0 MEDIUM

SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user …

Apr 28, 2025
CVE-2015-4582
7.2 HIGH

The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.

Apr 28, 2025
CVE-2025-4025
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. …

Apr 28, 2025
CVE-2025-4024
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation …

Apr 28, 2025
CVE-2025-25776
5.0 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute …

Apr 28, 2025
CVE-2025-23377
4.2 MEDIUM

Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could …

Apr 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.