CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-32835
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32834
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32833
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32832
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32831
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32830
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32829
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32828
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32827
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32826
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32825
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32824
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32823
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32822
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-32475
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-31353
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-31352
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-31351
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-31350
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-31349
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-31343
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-30032
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-30031
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-30030
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-30003
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-30002
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-2291
8.1 HIGH

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to …

Apr 16, 2025
CVE-2025-29905
8.8 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-27540
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-27539
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-27495
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-22872
6.5 MEDIUM

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result …

Apr 16, 2025
CVE-2024-53305
7.3 HIGH

An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query.

Apr 16, 2025
CVE-2024-53304
6.5 MEDIUM

An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands via posing as …

Apr 16, 2025
CVE-2024-53303
8.8 HIGH

A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 allows authenticated attackers to execute arbitrary code via …

Apr 16, 2025
CVE-2025-3739
5.9 MEDIUM

Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.

Apr 16, 2025
CVE-2025-3738
5.9 MEDIUM

Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.

Apr 16, 2025
CVE-2025-3737
5.9 MEDIUM

Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.

Apr 16, 2025
CVE-2025-3736
5.9 MEDIUM

Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.

Apr 16, 2025
CVE-2025-3735
5.9 MEDIUM

Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.

Apr 16, 2025
CVE-2025-3734
5.9 MEDIUM

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue affects Stage File Proxy: from 0.0.0 before 3.1.5.

Apr 16, 2025
CVE-2025-3733
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, …

Apr 16, 2025
CVE-2025-2564
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, …

Apr 16, 2025
CVE-2025-20236
8.8 HIGH

A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, …

Apr 16, 2025
CVE-2024-40074
4.8 MEDIUM

Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the …

Apr 16, 2025
CVE-2024-40073
9.8 CRITICAL

Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.

Apr 16, 2025
CVE-2024-40072
9.8 CRITICAL

Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.

Apr 16, 2025
CVE-2024-40071
9.8 CRITICAL

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code …

Apr 16, 2025
CVE-2024-40070
5.1 MEDIUM

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code …

Apr 16, 2025
CVE-2024-40069
5.4 MEDIUM

Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the …

Apr 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.