CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41795
6.5 MEDIUM

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices is vulnerable to Cross-Site Request Forgery …

Apr 8, 2025
CVE-2024-41794
10.0 CRITICAL

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for remote access to the device operating …

Apr 8, 2025
CVE-2024-41793
8.6 HIGH

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an endpoint that allows to …

Apr 8, 2025
CVE-2024-41792
8.6 HIGH

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices contains a path traversal vulnerability. This …

Apr 8, 2025
CVE-2024-41791
7.3 HIGH

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not authenticate report creation requests. …

Apr 8, 2025
CVE-2024-41790
9.1 CRITICAL

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the region parameter …

Apr 8, 2025
CVE-2024-41789
9.1 CRITICAL

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language parameter …

Apr 8, 2025
CVE-2024-41788
9.1 CRITICAL

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the input parameters …

Apr 8, 2025
CVE-2025-3431
7.5 HIGH

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, …

Apr 8, 2025
CVE-2025-31333
4.3 MEDIUM

SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact …

Apr 8, 2025
CVE-2025-31332
6.6 MEDIUM

Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting …

Apr 8, 2025
CVE-2025-31331
4.3 MEDIUM

SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged …

Apr 8, 2025
CVE-2025-31330
9.9 CRITICAL

SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the …

Apr 8, 2025
CVE-2025-30017
4.4 MEDIUM

Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After …

Apr 8, 2025
CVE-2025-30016
9.8 CRITICAL

SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to …

Apr 8, 2025
CVE-2025-30015
4.1 MEDIUM

Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could …

Apr 8, 2025
CVE-2025-30014
7.7 HIGH

SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could allow an attacker with low privileges to read files …

Apr 8, 2025
CVE-2025-30013
6.7 MEDIUM

SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle …

Apr 8, 2025
CVE-2025-2882
5.3 MEDIUM

The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between 3.0.0 and 3.0.9 through the publicly accessible phpinfo.php script. …

Apr 8, 2025
CVE-2025-27437
4.3 MEDIUM

A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a …

Apr 8, 2025
CVE-2025-27435
4.2 MEDIUM

Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP …

Apr 8, 2025
CVE-2025-27429
9.9 CRITICAL

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of …

Apr 8, 2025
CVE-2025-27428
7.7 HIGH

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they …

Apr 8, 2025
CVE-2025-26657
5.3 MEDIUM

SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information causing low impact on …

Apr 8, 2025
CVE-2025-26654
6.8 MEDIUM

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 …

Apr 8, 2025
CVE-2025-26653
4.7 MEDIUM

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any …

Apr 8, 2025
CVE-2025-23186
8.5 HIGH

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can …

Apr 8, 2025
CVE-2025-3430
4.9 MEDIUM

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up to, and including, 2.1.3.6 due to …

Apr 8, 2025
CVE-2025-3429
4.9 MEDIUM

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to …

Apr 8, 2025
CVE-2025-3428
4.9 MEDIUM

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up to, and including, 2.1.3.6 due to …

Apr 8, 2025
CVE-2025-3427
4.9 MEDIUM

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up to, and including, 2.1.3.6 due to …

Apr 8, 2025
CVE-2019-25223
4.9 MEDIUM

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and …

Apr 8, 2025
CVE-2025-3413
6.3 MEDIUM

A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function code of the …

Apr 8, 2025
CVE-2025-3412
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown function of the file 2_training_platform/train-platform/src/main/java/top/aias/training/controller/InferController.java. The manipulation of …

Apr 8, 2025
CVE-2025-0361
4.3 MEDIUM

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated …

Apr 8, 2025
CVE-2024-47261
4.3 MEDIUM

51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow …

Apr 8, 2025
CVE-2025-3411
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some unknown processing of the file 3_api_platform/api-platform/src/main/java/top/aias/platform/controller/AsrController.java. The …

Apr 8, 2025
CVE-2025-3410
6.3 MEDIUM

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java. The manipulation of the argument …

Apr 8, 2025
CVE-2025-3409
6.3 MEDIUM

A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argument path_to_includes …

Apr 8, 2025
CVE-2025-2004
9.1 CRITICAL

The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpe_delete_file AJAX action in …

Apr 8, 2025
CVE-2025-20951
5.1 MEDIUM

Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege …

Apr 8, 2025
CVE-2025-20950
4.0 MEDIUM

Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.

Apr 8, 2025
CVE-2025-20948
5.5 MEDIUM

Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

Apr 8, 2025
CVE-2025-20947
5.5 MEDIUM

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. …

Apr 8, 2025
CVE-2025-20946
8.8 HIGH

Improper handling of exceptional conditions in pairing specific bluetooth devices in Galaxy Watch Bluetooth pairing prior to SMR Apr-2025 Release 1 allows local attackers to …

Apr 8, 2025
CVE-2025-20945
4.0 MEDIUM

Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

Apr 8, 2025
CVE-2025-20944
6.2 MEDIUM

Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.

Apr 8, 2025
CVE-2025-20943
6.4 MEDIUM

Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.

Apr 8, 2025
CVE-2025-20942
4.4 MEDIUM

Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.

Apr 8, 2025
CVE-2025-20941
6.2 MEDIUM

Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.