CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43903
4.3 MEDIUM

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Apr 18, 2025
CVE-2025-3796
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The …

Apr 18, 2025
CVE-2025-32953
8.7 HIGH

z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubuntu.yml` workflow file uses `actions/upload-artifact@v4` to …

Apr 18, 2025
CVE-2025-29058
9.8 CRITICAL

An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.

Apr 18, 2025
CVE-2024-53591
9.8 CRITICAL

An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.

Apr 18, 2025
CVE-2025-3795
2.4 LOW

A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO …

Apr 18, 2025
CVE-2025-36625
4.3 MEDIUM

In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.

Apr 18, 2025
CVE-2025-32377
6.5 MEDIUM

Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa …

Apr 18, 2025
CVE-2025-28197
9.1 CRITICAL

Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.

Apr 18, 2025
CVE-2025-25985
2.6 LOW

An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini …

Apr 18, 2025
CVE-2025-25984
6.8 MEDIUM

An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.

Apr 18, 2025
CVE-2025-25983
3.4 LOW

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via …

Apr 18, 2025
CVE-2024-57493
5.5 MEDIUM

An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockopt function.

Apr 18, 2025
CVE-2025-28355
4.7 MEDIUM

Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the …

Apr 18, 2025
CVE-2025-24914
7.8 HIGH

When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could …

Apr 18, 2025
CVE-2025-29513
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.

Apr 18, 2025
CVE-2025-29512
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until …

Apr 18, 2025
CVE-2025-28242
9.8 CRITICAL

Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

Apr 18, 2025
CVE-2025-28238
9.8 CRITICAL

Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.

Apr 18, 2025
CVE-2025-28237
8.8 HIGH

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.

Apr 18, 2025
CVE-2025-28236
9.8 CRITICAL

Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This …

Apr 18, 2025
CVE-2025-28235
7.5 HIGH

An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator …

Apr 18, 2025
CVE-2025-28233
9.1 CRITICAL

Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, …

Apr 18, 2025
CVE-2025-28231
9.1 CRITICAL

Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.

Apr 18, 2025
CVE-2025-1697
7.8 HIGH

A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability …

Apr 18, 2025
CVE-2025-28059
7.5 HIGH

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale …

Apr 18, 2025
CVE-2024-41447
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 18, 2025
CVE-2025-32796
6.5 MEDIUM

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or …

Apr 18, 2025
CVE-2025-32795
6.5 MEDIUM

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted …

Apr 18, 2025
CVE-2025-32792

SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their global scope. Prior to version 1.12.0, web pages …

Apr 18, 2025
CVE-2025-32442
7.5 HIGH

Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, applications that specify different …

Apr 18, 2025
CVE-2025-32434
9.8 CRITICAL

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version …

Apr 18, 2025
CVE-2025-32389
6.5 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by …

Apr 18, 2025
CVE-2025-31120
5.3 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in …

Apr 18, 2025
CVE-2025-31118
7.1 HIGH

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does …

Apr 18, 2025
CVE-2025-30357
7.3 HIGH

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving …

Apr 18, 2025
CVE-2025-30158
7.1 HIGH

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post …

Apr 18, 2025
CVE-2025-29953
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to …

Apr 18, 2025
CVE-2025-29784
7.5 HIGH

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests …

Apr 18, 2025
CVE-2025-27599
6.5 MEDIUM

Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed …

Apr 18, 2025
CVE-2025-3792
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. …

Apr 18, 2025
CVE-2025-3791
5.3 MEDIUM

A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This vulnerability affects the function jx9MemObjStore of the file /data/src/benchmarks/unqlite/unqlite.c. The manipulation …

Apr 18, 2025
CVE-2025-37838
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition In …

Apr 18, 2025
CVE-2025-2950
5.4 MEDIUM

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM …

Apr 18, 2025
CVE-2025-29625
7.8 HIGH

A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overly long environment …

Apr 18, 2025
CVE-2025-29209
9.8 CRITICAL

TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.

Apr 18, 2025
CVE-2025-28232
9.1 CRITICAL

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

Apr 18, 2025
CVE-2025-28230
9.1 CRITICAL

Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.

Apr 18, 2025
CVE-2025-28229
9.8 CRITICAL

Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.

Apr 18, 2025
CVE-2025-28228
7.5 HIGH

A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access …

Apr 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.