CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29984
6.7 MEDIUM

Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, …

Apr 15, 2025
CVE-2025-29983
6.7 MEDIUM

Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access …

Apr 15, 2025
CVE-2025-3613
3.5 LOW

A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unknown code of the file /visualization. The manipulation of …

Apr 15, 2025
CVE-2025-3612
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part of the file /visualization of the component …

Apr 15, 2025
CVE-2025-3470
4.9 MEDIUM

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all …

Apr 15, 2025
CVE-2025-32997
4.0 MEDIUM

In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.

Apr 15, 2025
CVE-2025-32996
4.0 MEDIUM

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.

Apr 15, 2025
CVE-2025-32941

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32940

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32939

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32938

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32937

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32936

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32935

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32934

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32933

Rejected reason: Not used

Apr 15, 2025
CVE-2025-32987
6.0 MEDIUM

Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

Apr 15, 2025
CVE-2025-32428

Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by …

Apr 15, 2025
CVE-2025-31494
3.5 LOW

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The AutoGPT Platform's WebSocket API …

Apr 15, 2025
CVE-2025-31491
8.6 HIGH

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows …

Apr 15, 2025
CVE-2025-24797
9.4 CRITICAL

Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled …

Apr 15, 2025
CVE-2025-3593
6.3 MEDIUM

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Upload of the file /admin/upload/authorImg/. The …

Apr 14, 2025
CVE-2025-31490
7.5 HIGH

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows …

Apr 14, 2025
CVE-2025-3592
3.5 LOW

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/v1/link/edit. The manipulation …

Apr 14, 2025
CVE-2025-3591
3.5 LOW

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/v1/blog/edit. The …

Apr 14, 2025
CVE-2025-3590
6.3 MEDIUM

A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation …

Apr 14, 2025
CVE-2025-3589
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affected is an unknown function of the file /manage_class.php. …

Apr 14, 2025
CVE-2025-3588
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue affects the function apply of the file org/jsonschema2pojo/rules/SchemaRule.java of …

Apr 14, 2025
CVE-2023-27272
3.1 LOW

IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.

Apr 14, 2025
CVE-2022-43852
5.3 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.

Apr 14, 2025
CVE-2022-43851
5.9 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Apr 14, 2025
CVE-2022-43850
5.4 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Apr 14, 2025
CVE-2022-43847
5.4 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow …

Apr 14, 2025
CVE-2022-43840
4.3 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or …

Apr 14, 2025
CVE-2025-3587
6.3 MEDIUM

A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /getTeacherList. The manipulation leads to improper …

Apr 14, 2025
CVE-2025-1782

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Apr 14, 2025
CVE-2025-3585
6.3 MEDIUM

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP …

Apr 14, 2025
CVE-2025-3277
9.8 CRITICAL

An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes …

Apr 14, 2025
CVE-2025-29720
4.8 MEDIUM

Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.

Apr 14, 2025
CVE-2025-32931
9.1 CRITICAL

DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan …

Apr 14, 2025
CVE-2025-2572
5.6 MEDIUM

In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.

Apr 14, 2025
CVE-2025-22373

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SicommNet BASEC on SaaS allows Reflected XSS, XSS Through HTTP Query …

Apr 14, 2025
CVE-2025-22372

Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker …

Apr 14, 2025
CVE-2025-22371

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (SaaS Service) login page allows an unauthenticated remote attacker …

Apr 14, 2025
CVE-2025-3571
6.3 MEDIUM

A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnerability affects unknown code of the …

Apr 14, 2025
CVE-2025-3570
3.5 LOW

A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This affects the function Save of the file ContentController.java. The manipulation …

Apr 14, 2025
CVE-2025-32930

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.

Apr 14, 2025
CVE-2025-32914
7.4 HIGH

A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce …

Apr 14, 2025
CVE-2025-32912
6.5 MEDIUM

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.

Apr 14, 2025
CVE-2025-32910
6.5 MEDIUM

A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.

Apr 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.