CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3509
7.2 HIGH

A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, …

Apr 17, 2025
CVE-2025-3246
7.6 HIGH

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation …

Apr 17, 2025
CVE-2025-3124
4.3 MEDIUM

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise …

Apr 17, 2025
CVE-2025-29461
7.6 HIGH

An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.

Apr 17, 2025
CVE-2025-29460
7.6 HIGH

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of …

Apr 17, 2025
CVE-2025-29459
7.6 HIGH

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the …

Apr 17, 2025
CVE-2025-29458
7.6 HIGH

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this because of …

Apr 17, 2025
CVE-2025-29457
7.6 HIGH

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this because …

Apr 17, 2025
CVE-2025-29456
6.5 MEDIUM

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.

Apr 17, 2025
CVE-2025-29453
6.5 MEDIUM

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.

Apr 17, 2025
CVE-2024-42178
2.5 LOW

HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk …

Apr 17, 2025
CVE-2025-29455
6.5 MEDIUM

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.

Apr 17, 2025
CVE-2025-29454
6.5 MEDIUM

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.

Apr 17, 2025
CVE-2025-29452
7.6 HIGH

An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.

Apr 17, 2025
CVE-2025-29451
7.6 HIGH

An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.

Apr 17, 2025
CVE-2025-29450
6.5 MEDIUM

An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.

Apr 17, 2025
CVE-2025-29449
6.5 MEDIUM

An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.

Apr 17, 2025
CVE-2025-3765
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of …

Apr 17, 2025
CVE-2025-3764
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /edit-product.php. The …

Apr 17, 2025
CVE-2024-42177
2.6 LOW

HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt …

Apr 17, 2025
CVE-2025-3763
5.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the function main of the component Password Handler. The …

Apr 17, 2025
CVE-2025-3762
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Apr 17, 2025
CVE-2025-29316
6.2 MEDIUM

An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive information. NOTE: the Supplier disputes the Print …

Apr 17, 2025
CVE-2025-29722
6.3 MEDIUM

A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF …

Apr 17, 2025
CVE-2025-28101
6.5 MEDIUM

An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a …

Apr 17, 2025
CVE-2025-28009
9.8 CRITICAL

A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.

Apr 17, 2025
CVE-2025-26269
3.3 LOW

DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references …

Apr 17, 2025
CVE-2025-26268
3.3 LOW

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan …

Apr 17, 2025
CVE-2025-25455
7.5 HIGH

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.

Apr 17, 2025
CVE-2025-25454
7.5 HIGH

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.

Apr 17, 2025
CVE-2024-55211
8.4 HIGH

An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.

Apr 17, 2025
CVE-2024-53924
9.8 CRITICAL

Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the …

Apr 17, 2025
CVE-2021-47671
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the …

Apr 17, 2025
CVE-2021-47670
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, …

Apr 17, 2025
CVE-2021-47669
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: vxcan: vxcan_xmit: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. …

Apr 17, 2025
CVE-2021-47668
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. …

Apr 17, 2025
CVE-2020-36789
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls …

Apr 17, 2025
CVE-2025-32415
2.9 LOW

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be …

Apr 17, 2025
CVE-2025-2947
7.2 HIGH

IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to …

Apr 17, 2025
CVE-2025-29662
9.8 CRITICAL

A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.

Apr 17, 2025
CVE-2025-29661
7.2 HIGH

Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.

Apr 17, 2025
CVE-2025-29181
7.2 HIGH

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

Apr 17, 2025
CVE-2025-29180
7.2 HIGH

In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated …

Apr 17, 2025
CVE-2025-29039
7.2 HIGH

An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8

Apr 17, 2025
CVE-2024-40124
5.4 MEDIUM

Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.

Apr 17, 2025
CVE-2025-43015
8.3 HIGH

In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces

Apr 17, 2025
CVE-2025-43014
6.1 MEDIUM

In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation

Apr 17, 2025
CVE-2025-43013
6.9 MEDIUM

In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

Apr 17, 2025
CVE-2025-43012
8.3 HIGH

In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

Apr 17, 2025
CVE-2025-42921
4.2 MEDIUM

In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin

Apr 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.