CVE Database

10779+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1446
9.8 CRITICAL

The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL …

Mar 23, 2025
CVE-2025-2621
9.8 CRITICAL

A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of …

Mar 22, 2025
CVE-2025-2620
9.8 CRITICAL

A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the …

Mar 22, 2025
CVE-2025-2619
9.8 CRITICAL

A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component …

Mar 22, 2025
CVE-2025-2618
9.8 CRITICAL

A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file …

Mar 22, 2025
CVE-2025-30472
9.0 CRITICAL

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a …

Mar 22, 2025
CVE-2024-53351
9.8 CRITICAL

Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.

Mar 21, 2025
CVE-2025-29927
9.1 CRITICAL

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is …

Mar 21, 2025
CVE-2025-29814
9.3 CRITICAL

Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Mar 21, 2025
CVE-2025-2538
9.8 CRITICAL

A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated …

Mar 20, 2025
CVE-2025-26853
10.0 CRITICAL

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

Mar 20, 2025
CVE-2025-26852
10.0 CRITICAL

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.

Mar 20, 2025
CVE-2025-29980
9.8 CRITICAL

A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as …

Mar 20, 2025
CVE-2025-29922
9.6 CRITICAL

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting …

Mar 20, 2025
CVE-2025-29411
9.8 CRITICAL

An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a …

Mar 20, 2025
CVE-2024-48590
9.8 CRITICAL

Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.

Mar 20, 2025
CVE-2025-2311
9.0 CRITICAL

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication …

Mar 20, 2025
CVE-2024-9701
9.8 CRITICAL

A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python …

Mar 20, 2025
CVE-2024-9309
9.3 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability …

Mar 20, 2025
CVE-2024-9095
9.8 CRITICAL

In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export …

Mar 20, 2025
CVE-2024-9070
9.8 CRITICAL

A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the …

Mar 20, 2025
CVE-2024-9053
9.8 CRITICAL

vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which directly uses cloudpickle.loads() …

Mar 20, 2025
CVE-2024-8958
9.8 CRITICAL

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an …

Mar 20, 2025
CVE-2024-8954
9.8 CRITICAL

In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass authentication …

Mar 20, 2025
CVE-2024-8953
9.8 CRITICAL

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted …

Mar 20, 2025
CVE-2024-8898
9.8 CRITICAL

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete …

Mar 20, 2025
CVE-2024-8769
9.1 CRITICAL

A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, …

Mar 20, 2025
CVE-2024-8581
9.1 CRITICAL

A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does …

Mar 20, 2025
CVE-2024-8551
9.1 CRITICAL

A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read …

Mar 20, 2025
CVE-2024-8537
9.1 CRITICAL

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete …

Mar 20, 2025
CVE-2024-8502
9.8 CRITICAL

A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The …

Mar 20, 2025
CVE-2024-8487
9.8 CRITICAL

A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only …

Mar 20, 2025
CVE-2024-8196
9.8 CRITICAL

In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker …

Mar 20, 2025
CVE-2024-8156
9.8 CRITICAL

A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowing an attacker to inject arbitrary …

Mar 20, 2025
CVE-2024-8019
9.1 CRITICAL

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an …

Mar 20, 2025
CVE-2024-8017
9.0 CRITICAL

An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform …

Mar 20, 2025
CVE-2024-7957
9.1 CRITICAL

An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest version. The vulnerability arises from the load_credentials method, where user-controlled input …

Mar 20, 2025
CVE-2024-7776
9.1 CRITICAL

A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of …

Mar 20, 2025
CVE-2024-7760
9.6 CRITICAL

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin …

Mar 20, 2025
CVE-2024-7053
9.0 CRITICAL

A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack. The session cookie for all users …

Mar 20, 2025
CVE-2024-6829
9.1 CRITICAL

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitrary …

Mar 20, 2025
CVE-2024-5752
9.1 CRITICAL

A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the affected version beacf6edaa205a5a5370525407a6db45137873b3, the project name is not validated, allowing …

Mar 20, 2025
CVE-2024-4990
9.1 CRITICAL

In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a …

Mar 20, 2025
CVE-2024-12909
9.8 CRITICAL

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This …

Mar 20, 2025
CVE-2024-12450
9.8 CRITICAL

In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read …

Mar 20, 2025
CVE-2024-12433
9.8 CRITICAL

A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily …

Mar 20, 2025
CVE-2024-12044
9.8 CRITICAL

A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the `pickle.loads()` function in the `all_reduce_dict()` distributed …

Mar 20, 2025
CVE-2024-12029
9.8 CRITICAL

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files …

Mar 20, 2025
CVE-2024-11958
9.8 CRITICAL

A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version. The vulnerability arises from the construction of …

Mar 20, 2025
CVE-2024-11045
9.6 CRITICAL

A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.