CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29594
6.1 MEDIUM

A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter …

Apr 7, 2025
CVE-2025-29482
6.2 MEDIUM

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.

Apr 7, 2025
CVE-2025-29481
6.2 MEDIUM

Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by …

Apr 7, 2025
CVE-2025-29480
5.5 MEDIUM

Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that …

Apr 7, 2025
CVE-2025-29479

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Apr 7, 2025
CVE-2025-29478
5.5 MEDIUM

An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.

Apr 7, 2025
CVE-2025-29087
3.2 LOW

In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If …

Apr 7, 2025
CVE-2024-46494
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter …

Apr 7, 2025
CVE-2025-3380
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. Affected by this issue is some unknown functionality of the …

Apr 7, 2025
CVE-2025-3379
7.3 HIGH

A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. Affected by this vulnerability is an unknown functionality of the component EPSV Command …

Apr 7, 2025
CVE-2025-3378
7.3 HIGH

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component EPRT Command Handler. The …

Apr 7, 2025
CVE-2025-3377
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component ENC …

Apr 7, 2025
CVE-2024-38797
4.6 MEDIUM

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent …

Apr 7, 2025
CVE-2025-3426

We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures …

Apr 7, 2025
CVE-2025-3376
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command …

Apr 7, 2025
CVE-2025-3375
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command …

Apr 7, 2025
CVE-2025-3425

The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing …

Apr 7, 2025
CVE-2025-3424

The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which …

Apr 7, 2025
CVE-2025-3374
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC …

Apr 7, 2025
CVE-2025-3373
7.3 HIGH

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component …

Apr 7, 2025
CVE-2025-28413
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

Apr 7, 2025
CVE-2025-28412
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

Apr 7, 2025
CVE-2025-28411
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

Apr 7, 2025
CVE-2025-28410
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has …

Apr 7, 2025
CVE-2025-28409
8.8 HIGH

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether …

Apr 7, 2025
CVE-2025-28408
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the …

Apr 7, 2025
CVE-2025-28407
8.8 HIGH

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether …

Apr 7, 2025
CVE-2025-28406
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

Apr 7, 2025
CVE-2025-28405
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

Apr 7, 2025
CVE-2025-28403
7.2 HIGH

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has …

Apr 7, 2025
CVE-2025-28402
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

Apr 7, 2025
CVE-2025-28401
6.7 MEDIUM

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter

Apr 7, 2025
CVE-2025-28400
6.7 MEDIUM

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method

Apr 7, 2025
CVE-2025-3372
7.3 HIGH

A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. …

Apr 7, 2025
CVE-2025-3371
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE …

Apr 7, 2025
CVE-2025-3248
9.8 CRITICAL KEV

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to …

Apr 7, 2025
CVE-2025-32014

estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an …

Apr 7, 2025
CVE-2025-31476
4.8 MEDIUM

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source …

Apr 7, 2025
CVE-2025-31475
5.5 MEDIUM

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom …

Apr 7, 2025
CVE-2025-31138
5.5 MEDIUM

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and …

Apr 7, 2025
CVE-2025-30373
6.5 MEDIUM

Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present …

Apr 7, 2025
CVE-2025-3370
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/admin-profile.php. The …

Apr 7, 2025
CVE-2025-3369
6.3 MEDIUM

A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Apr 7, 2025
CVE-2025-30195
7.5 HIGH

An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses …

Apr 7, 2025
CVE-2025-2251
6.2 MEDIUM

A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted …

Apr 7, 2025
CVE-2025-27686
2.7 LOW

Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an …

Apr 7, 2025
CVE-2025-3360
3.7 LOW

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

Apr 7, 2025
CVE-2025-3359
6.2 MEDIUM

A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.

Apr 7, 2025
CVE-2025-3353
7.3 HIGH

A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 7, 2025
CVE-2025-3352
7.3 HIGH

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

Apr 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.