CVE Database

10779+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24172
9.8 CRITICAL

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All …

Mar 31, 2025
CVE-2025-24167
9.8 CRITICAL

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. …

Mar 31, 2025
CVE-2025-31691
9.8 CRITICAL

Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.

Mar 31, 2025
CVE-2025-31685
9.1 CRITICAL

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.

Mar 31, 2025
CVE-2025-31681
9.8 CRITICAL

Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6.

Mar 31, 2025
CVE-2024-54809
9.8 CRITICAL

Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in …

Mar 31, 2025
CVE-2024-54808
9.8 CRITICAL

Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows …

Mar 31, 2025
CVE-2024-54807
9.8 CRITICAL

In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the …

Mar 31, 2025
CVE-2024-54806
9.8 CRITICAL

Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.

Mar 31, 2025
CVE-2024-54805
9.8 CRITICAL

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. …

Mar 31, 2025
CVE-2024-54804
9.8 CRITICAL

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname …

Mar 31, 2025
CVE-2024-54803
9.8 CRITICAL

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac …

Mar 31, 2025
CVE-2024-54802
9.8 CRITICAL

In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.

Mar 31, 2025
CVE-2025-30223
9.3 CRITICAL

Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability exists in Beego's RenderForm() function due …

Mar 31, 2025
CVE-2025-30095
9.0 CRITICAL

VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across …

Mar 31, 2025
CVE-2025-22941
9.8 CRITICAL

A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.

Mar 31, 2025
CVE-2025-22940
9.1 CRITICAL

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

Mar 31, 2025
CVE-2025-22939
9.8 CRITICAL

A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.

Mar 31, 2025
CVE-2025-22938
9.8 CRITICAL

Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.

Mar 31, 2025
CVE-2025-22937
9.8 CRITICAL

An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.

Mar 31, 2025
CVE-2025-29266
9.6 CRITICAL

Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in …

Mar 31, 2025
CVE-2025-26689
9.8 CRITICAL

Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to …

Mar 31, 2025
CVE-2025-25211
9.8 CRITICAL

Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker …

Mar 31, 2025
CVE-2025-3011
9.8 CRITICAL

SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Mar 31, 2025
CVE-2025-1268
9.4 CRITICAL

Out-of-bounds vulnerability in EMF Recode processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver …

Mar 31, 2025
CVE-2024-13804
9.8 CRITICAL

Unauthenticated RCE in HPE Insight Cluster Management Utility

Mar 30, 2025
CVE-2025-1861
9.8 CRITICAL

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response …

Mar 30, 2025
CVE-2025-2266
9.8 CRITICAL

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to …

Mar 29, 2025
CVE-2025-28091
9.1 CRITICAL

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

Mar 28, 2025
CVE-2025-28090
9.1 CRITICAL

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

Mar 28, 2025
CVE-2025-28089
9.1 CRITICAL

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

Mar 28, 2025
CVE-2025-28087
9.8 CRITICAL

Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.

Mar 28, 2025
CVE-2025-25579
9.8 CRITICAL

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

Mar 28, 2025
CVE-2025-28256
9.8 CRITICAL

An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

Mar 28, 2025
CVE-2025-22953
9.8 CRITICAL

A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter …

Mar 28, 2025
CVE-2024-56975
9.8 CRITICAL

InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.

Mar 28, 2025
CVE-2024-38988
9.8 CRITICAL

alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code …

Mar 28, 2025
CVE-2024-38985
9.8 CRITICAL

janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers …

Mar 28, 2025
CVE-2024-24292
9.8 CRITICAL

A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.

Mar 28, 2025
CVE-2025-30372
9.8 CRITICAL

Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after …

Mar 28, 2025
CVE-2025-22526
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performancestats allows Object Injection.This issue affects PHP/MySQL CPU performance statistics: from n/a through <= …

Mar 28, 2025
CVE-2025-22523
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scheduler Schedule schedule allows Blind SQL Injection.This issue affects Schedule: from …

Mar 28, 2025
CVE-2025-2859
9.8 CRITICAL

An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to …

Mar 28, 2025
CVE-2025-28219
9.8 CRITICAL

Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to …

Mar 28, 2025
CVE-2025-2294
9.8 CRITICAL

The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. …

Mar 28, 2025
CVE-2025-24383
9.1 CRITICAL

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker …

Mar 28, 2025
CVE-2025-22398
9.8 CRITICAL

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker …

Mar 28, 2025
CVE-2025-26898
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mar 27, 2025
CVE-2025-26873
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mar 27, 2025
CVE-2025-29306
9.8 CRITICAL

An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.

Mar 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.