CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-42601

This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API endpoints. A remote attacker could exploit this …

Apr 23, 2025
CVE-2025-42600

This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of …

Apr 23, 2025
CVE-2025-1054
6.4 MEDIUM

The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the UI Counter, UI Icon Box, …

Apr 23, 2025
CVE-2024-10306
5.4 MEDIUM

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not …

Apr 23, 2025
CVE-2025-3530
7.5 HIGH

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due …

Apr 23, 2025
CVE-2025-3529
8.2 HIGH

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' …

Apr 23, 2025
CVE-2025-2595
5.3 MEDIUM

An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.

Apr 23, 2025
CVE-2025-0618
6.5 MEDIUM

A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protection event to the …

Apr 23, 2025
CVE-2025-1056
6.1 MEDIUM

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin …

Apr 23, 2025
CVE-2025-0926
5.9 MEDIUM

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing …

Apr 23, 2025
CVE-2025-46224

Rejected reason: Not used

Apr 23, 2025
CVE-2025-46223

Rejected reason: Not used

Apr 23, 2025
CVE-2025-46222

Rejected reason: Not used

Apr 23, 2025
CVE-2025-46221

Rejected reason: Not used

Apr 23, 2025
CVE-2025-46220

Rejected reason: Not used

Apr 23, 2025
CVE-2025-46219

Rejected reason: Not used

Apr 23, 2025
CVE-2025-46218

Rejected reason: Not used

Apr 23, 2025
CVE-2025-46217

Rejected reason: Not used

Apr 23, 2025
CVE-2025-46216

Rejected reason: Not used

Apr 23, 2025
CVE-2025-1021
7.5 HIGH

Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors.

Apr 23, 2025
CVE-2025-3441

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 22, 2025
CVE-2025-37088
6.8 MEDIUM

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster …

Apr 22, 2025
CVE-2025-27087
5.5 MEDIUM

A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.

Apr 22, 2025
CVE-2025-37087
9.8 CRITICAL

A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on …

Apr 22, 2025
CVE-2025-32965

xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4.2.2, 4.2.3, and 4.2.4 of xrpl.js were …

Apr 22, 2025
CVE-2025-29743
6.5 MEDIUM

D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

Apr 22, 2025
CVE-2025-26159
6.1 MEDIUM

Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can …

Apr 22, 2025
CVE-2025-31328
4.6 MEDIUM

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based …

Apr 22, 2025
CVE-2025-31327
4.3 MEDIUM

SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an …

Apr 22, 2025
CVE-2025-29621
7.3 HIGH

Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers …

Apr 22, 2025
CVE-2025-23253
2.5 LOW

NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a …

Apr 22, 2025
CVE-2024-53569
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web …

Apr 22, 2025
CVE-2024-53568
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts …

Apr 22, 2025
CVE-2025-43952
6.1 MEDIUM

A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts …

Apr 22, 2025
CVE-2025-43951
9.8 CRITICAL

LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.

Apr 22, 2025
CVE-2025-43950
7.8 HIGH

DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which …

Apr 22, 2025
CVE-2025-43949
9.8 CRITICAL

MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control …

Apr 22, 2025
CVE-2025-43948
7.3 HIGH

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for …

Apr 22, 2025
CVE-2025-43947
7.3 HIGH

Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such …

Apr 22, 2025
CVE-2025-43946
9.8 CRITICAL

TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).

Apr 22, 2025
CVE-2025-32964
4.6 MEDIUM

ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically …

Apr 22, 2025
CVE-2025-32963

MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default …

Apr 22, 2025
CVE-2025-32961
6.4 MEDIUM

The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTTP requests. Prior to version …

Apr 22, 2025
CVE-2025-32960
6.4 MEDIUM

The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and …

Apr 22, 2025
CVE-2025-32959
6.5 MEDIUM

CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file storage implementation does not restrict the size …

Apr 22, 2025
CVE-2025-32952
6.5 MEDIUM

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, …

Apr 22, 2025
CVE-2025-32951
6.4 MEDIUM

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, …

Apr 22, 2025
CVE-2025-32950
6.5 MEDIUM

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, …

Apr 22, 2025
CVE-2025-32788
4.3 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker …

Apr 22, 2025
CVE-2025-28039
9.8 CRITICAL

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

Apr 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.