CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24850
5.3 MEDIUM

An attacker can export other users' plant information.

Apr 15, 2025
CVE-2025-24315
5.3 MEDIUM

Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

Apr 15, 2025
CVE-2025-24297
9.8 CRITICAL

Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.

Apr 15, 2025
CVE-2025-22269
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from …

Apr 15, 2025
CVE-2025-22268
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny …

Apr 15, 2025
CVE-2025-22263
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Global Gallery allows Reflected XSS. This issue affects Global Gallery: from n/a …

Apr 15, 2025
CVE-2024-49200
6.4 MEDIUM

An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. …

Apr 15, 2025
CVE-2025-32778

Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screenshot API of the Web Check project (Lissy93/web-check). …

Apr 15, 2025
CVE-2025-32021
2.2 LOW

Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code …

Apr 15, 2025
CVE-2025-31949
5.3 MEDIUM

An authenticated attacker can obtain any plant name by knowing the plant ID.

Apr 15, 2025
CVE-2025-31941
5.3 MEDIUM

An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.

Apr 15, 2025
CVE-2025-31933
5.3 MEDIUM

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

Apr 15, 2025
CVE-2025-31499
8.8 HIGH

Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly …

Apr 15, 2025
CVE-2025-31357
5.3 MEDIUM

An unauthenticated attacker can obtain a user's plant list by knowing the username.

Apr 15, 2025
CVE-2025-30740
6.5 MEDIUM

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable …

Apr 15, 2025
CVE-2025-30737
5.7 MEDIUM

Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). The supported version that is affected is 24.200. Difficult …

Apr 15, 2025
CVE-2025-30736
7.4 HIGH

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Difficult to exploit vulnerability allows …

Apr 15, 2025
CVE-2025-30735
8.1 HIGH

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page and Field Configuration). The supported version that is affected is …

Apr 15, 2025
CVE-2025-30733
6.5 MEDIUM

Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows unauthenticated …

Apr 15, 2025
CVE-2025-30732
6.1 MEDIUM

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows …

Apr 15, 2025
CVE-2025-30731
3.6 LOW

Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration). Supported versions that are affected are 12.2.3-12.2.14. Difficult to exploit vulnerability …

Apr 15, 2025
CVE-2025-30730
7.5 HIGH

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows …

Apr 15, 2025
CVE-2025-30729
5.5 MEDIUM

Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and …

Apr 15, 2025
CVE-2025-30728
7.5 HIGH

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker …

Apr 15, 2025
CVE-2025-30727
9.8 CRITICAL

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated …

Apr 15, 2025
CVE-2025-30726
5.3 MEDIUM

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows …

Apr 15, 2025
CVE-2025-30725
6.7 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Difficult to exploit vulnerability allows …

Apr 15, 2025
CVE-2025-30724
7.5 HIGH

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30723
5.4 MEDIUM

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30722
5.3 MEDIUM

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit …

Apr 15, 2025
CVE-2025-30721
4.0 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit …

Apr 15, 2025
CVE-2025-30720
6.1 MEDIUM

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Orders). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker …

Apr 15, 2025
CVE-2025-30719
6.1 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploitable vulnerability allows low …

Apr 15, 2025
CVE-2025-30718
5.4 MEDIUM

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30717
6.5 MEDIUM

Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows …

Apr 15, 2025
CVE-2025-30716
7.5 HIGH

Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable …

Apr 15, 2025
CVE-2025-30715
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable …

Apr 15, 2025
CVE-2025-30714
4.8 MEDIUM

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged …

Apr 15, 2025
CVE-2025-30713
5.4 MEDIUM

Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily …

Apr 15, 2025
CVE-2025-30712
8.1 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploitable vulnerability allows high …

Apr 15, 2025
CVE-2025-30711
5.4 MEDIUM

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30710
4.9 MEDIUM

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable …

Apr 15, 2025
CVE-2025-30709
6.1 MEDIUM

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable …

Apr 15, 2025
CVE-2025-30708
7.5 HIGH

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions that are affected are 12.2.4-12.2.14. Easily exploitable …

Apr 15, 2025
CVE-2025-30707
7.5 HIGH

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated …

Apr 15, 2025
CVE-2025-30706
7.5 HIGH

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged …

Apr 15, 2025
CVE-2025-30705
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30704
4.4 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to …

Apr 15, 2025
CVE-2025-30703
2.7 LOW

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows …

Apr 15, 2025
CVE-2025-30702
5.3 MEDIUM

Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.3-19.26. Easily exploitable vulnerability allows unauthenticated …

Apr 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.