CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-28102
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent …

Apr 21, 2025
CVE-2025-28099
4.3 MEDIUM

opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,

Apr 21, 2025
CVE-2025-23174
7.5 HIGH

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Apr 21, 2025
CVE-2025-43922
8.1 HIGH

The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.

Apr 21, 2025
CVE-2025-3857
7.5 HIGH

When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while …

Apr 21, 2025
CVE-2025-32793
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable …

Apr 21, 2025
CVE-2025-32431
9.1 CRITICAL

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-rc2. There is a potential vulnerability in …

Apr 21, 2025
CVE-2025-28367
6.5 MEDIUM

mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file …

Apr 21, 2025
CVE-2024-12543

User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter …

Apr 21, 2025
CVE-2025-2517

Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.

Apr 21, 2025
CVE-2025-2298

An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the system has access to, including system files and files …

Apr 21, 2025
CVE-2025-29660
9.8 CRITICAL

A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper …

Apr 21, 2025
CVE-2025-29659
9.8 CRITICAL

Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.

Apr 21, 2025
CVE-2025-29287
9.8 CRITICAL

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

Apr 21, 2025
CVE-2025-28121
6.1 MEDIUM

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary …

Apr 21, 2025
CVE-2024-42699
6.5 MEDIUM

Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the …

Apr 21, 2025
CVE-2024-12863

Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the …

Apr 21, 2025
CVE-2024-12862

Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to remove external collaborators.This issue affects …

Apr 21, 2025
CVE-2025-43916
3.4 LOW

Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent with RFC …

Apr 21, 2025
CVE-2024-41446
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 21, 2025
CVE-2025-32408
2.5 LOW

In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.

Apr 21, 2025
CVE-2025-3840

An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer component which is deployed for installation purposes …

Apr 21, 2025
CVE-2025-3838

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under …

Apr 21, 2025
CVE-2025-3837

An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the …

Apr 21, 2025
CVE-2025-25228
3.8 LOW

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area …

Apr 21, 2025
CVE-2025-0632

Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary …

Apr 21, 2025
CVE-2025-43973
6.8 MEDIUM

An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are …

Apr 21, 2025
CVE-2025-43972
6.8 MEDIUM

An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes …

Apr 21, 2025
CVE-2025-43971
8.6 HIGH

An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.

Apr 21, 2025
CVE-2025-43970
4.3 MEDIUM

An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or …

Apr 21, 2025
CVE-2025-43967
2.9 LOW

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.

Apr 21, 2025
CVE-2025-43966
2.9 LOW

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.

Apr 21, 2025
CVE-2025-43964
2.9 LOW

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

Apr 21, 2025
CVE-2025-43963
2.9 LOW

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.

Apr 21, 2025
CVE-2025-43962
2.9 LOW

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and …

Apr 21, 2025
CVE-2025-43961
2.9 LOW

In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.

Apr 21, 2025
CVE-2020-36845
5.3 MEDIUM

The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a …

Apr 20, 2025
CVE-2020-36844
6.1 MEDIUM

The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.

Apr 20, 2025
CVE-2025-43955
2.2 LOW

TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

Apr 20, 2025
CVE-2025-43954
4.9 MEDIUM

QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.

Apr 20, 2025
CVE-2025-3830
6.3 MEDIUM

A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUpload of the file …

Apr 20, 2025
CVE-2025-3829
7.3 HIGH

A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Apr 20, 2025
CVE-2025-3828
7.3 HIGH

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. …

Apr 20, 2025
CVE-2025-3827
7.3 HIGH

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/forgot-password.php. …

Apr 20, 2025
CVE-2025-3826
2.4 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file …

Apr 20, 2025
CVE-2025-3825
2.4 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown …

Apr 20, 2025
CVE-2025-3824
2.4 LOW

A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Apr 20, 2025
CVE-2025-3823
2.4 LOW

A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. …

Apr 20, 2025
CVE-2025-3822
2.4 LOW

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Apr 20, 2025
CVE-2025-3821
2.4 LOW

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the …

Apr 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.