CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46674
3.5 LOW

NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.

Apr 27, 2025
CVE-2025-46673
4.9 MEDIUM

NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space …

Apr 27, 2025
CVE-2025-46672
3.5 LOW

NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.

Apr 27, 2025
CVE-2025-3955
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This affects an unknown part of the file /edit_rpatient.php.php. …

Apr 27, 2025
CVE-2025-46656
2.9 LOW

python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.

Apr 26, 2025
CVE-2025-3954
3.7 LOW

A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some unknown functionality of the component Referer …

Apr 26, 2025
CVE-2025-46655
4.9 MEDIUM

CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of …

Apr 26, 2025
CVE-2025-46654
4.9 MEDIUM

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that …

Apr 26, 2025
CVE-2025-46653
3.1 LOW

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as …

Apr 26, 2025
CVE-2025-46652
6.1 MEDIUM

In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is …

Apr 26, 2025
CVE-2025-46646
4.5 MEDIUM

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

Apr 26, 2025
CVE-2024-53636
6.4 MEDIUM

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the …

Apr 26, 2025
CVE-2025-2101
8.1 HIGH

The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via the 'template' parameter of the …

Apr 26, 2025
CVE-2024-13812
6.5 MEDIUM

The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.1.1. This is due …

Apr 26, 2025
CVE-2025-2851
8.0 HIGH

A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate …

Apr 26, 2025
CVE-2025-2850
3.5 LOW

A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 …

Apr 26, 2025
CVE-2025-2811
5.7 MEDIUM

A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 …

Apr 26, 2025
CVE-2025-3915
4.3 MEDIUM

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function …

Apr 26, 2025
CVE-2025-3914
8.8 HIGH

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in …

Apr 26, 2025
CVE-2025-3906
8.8 HIGH

The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wep_opcoes' …

Apr 26, 2025
CVE-2025-3491
7.2 HIGH

The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and …

Apr 26, 2025
CVE-2025-2907
9.8 CRITICAL

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to …

Apr 26, 2025
CVE-2025-2105
8.1 HIGH

The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of untrusted …

Apr 26, 2025
CVE-2025-1458
6.4 MEDIUM

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 26, 2025
CVE-2024-13808
8.8 HIGH

The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.9 via the …

Apr 26, 2025
CVE-2025-2801
7.3 HIGH

The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in …

Apr 26, 2025
CVE-2025-46333

z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from one surface to …

Apr 25, 2025
CVE-2025-32986
7.5 HIGH

NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.

Apr 25, 2025
CVE-2025-32985
9.8 CRITICAL

NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

Apr 25, 2025
CVE-2025-32984
6.1 MEDIUM

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.

Apr 25, 2025
CVE-2025-32983
7.5 HIGH

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

Apr 25, 2025
CVE-2025-32982
7.5 HIGH

NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.

Apr 25, 2025
CVE-2025-32981
7.1 HIGH

NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

Apr 25, 2025
CVE-2025-32980
9.8 CRITICAL

NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration.

Apr 25, 2025
CVE-2025-32979
6.5 MEDIUM

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

Apr 25, 2025
CVE-2025-28128
7.0 HIGH

An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

Apr 25, 2025
CVE-2025-3935
8.1 HIGH KEV

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control …

Apr 25, 2025
CVE-2024-30152
6.5 MEDIUM

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify …

Apr 25, 2025
CVE-2025-25775
9.8 CRITICAL

Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

Apr 25, 2025
CVE-2025-3928
8.8 HIGH KEV

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised …

Apr 25, 2025
CVE-2025-2070
5.0 MEDIUM

An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is …

Apr 25, 2025
CVE-2025-2069
5.0 MEDIUM

A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local …

Apr 25, 2025
CVE-2025-2068
5.0 MEDIUM

An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.

Apr 25, 2025
CVE-2024-56156
9.0 CRITICAL

Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This …

Apr 25, 2025
CVE-2021-32601

Rejected reason: Not used

Apr 25, 2025
CVE-2025-46618
3.5 LOW

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

Apr 25, 2025
CVE-2025-46433
4.9 MEDIUM

In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

Apr 25, 2025
CVE-2025-46432
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs

Apr 25, 2025
CVE-2025-43862
7.6 HIGH

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though …

Apr 25, 2025
CVE-2025-43016
5.4 MEDIUM

In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

Apr 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.