CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3327
3.5 LOW

A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown processing of the file /common/upload/batch of the …

Apr 7, 2025
CVE-2025-3326
3.5 LOW

A vulnerability has been found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This vulnerability affects unknown code of the file /common/upload of the …

Apr 7, 2025
CVE-2025-3325
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part of the file /core/admin/pwd of the …

Apr 6, 2025
CVE-2025-3324
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality of the file …

Apr 6, 2025
CVE-2025-3323
6.3 MEDIUM

A vulnerability classified as critical was found in godcheese/code-projects Nimrod 0.8. Affected by this vulnerability is the function searchAllByName of the file ViewMenuCategoryRestController.java. The manipulation …

Apr 6, 2025
CVE-2025-32013
7.5 HIGH

LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. When processing …

Apr 6, 2025
CVE-2025-31492

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to …

Apr 6, 2025
CVE-2025-31488

Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are …

Apr 6, 2025
CVE-2025-2260
7.5 HIGH

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted packets. …

Apr 6, 2025
CVE-2025-2259
7.5 HIGH

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of …

Apr 6, 2025
CVE-2025-2258
7.5 HIGH

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent …

Apr 6, 2025
CVE-2025-3318
6.3 MEDIUM

A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. …

Apr 6, 2025
CVE-2025-3317
4.3 MEDIUM

A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation …

Apr 6, 2025
CVE-2025-3316
7.3 HIGH

A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 6, 2025
CVE-2025-3315
7.3 HIGH

A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Apr 6, 2025
CVE-2025-3314
7.3 HIGH

A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 6, 2025
CVE-2025-3313
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Men Salon Management System 1.0. Affected is an unknown function of the file /admin/add-customer.php. …

Apr 6, 2025
CVE-2025-3312
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon Management System 1.0. This issue affects some unknown processing of the …

Apr 6, 2025
CVE-2025-3311
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Men Salon Management System 1.0. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation …

Apr 6, 2025
CVE-2025-32370
7.2 HIGH

Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is …

Apr 6, 2025
CVE-2025-3310
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /admin/delete.php. The …

Apr 6, 2025
CVE-2025-3309
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 6, 2025
CVE-2025-32369
6.4 MEDIUM

Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.

Apr 6, 2025
CVE-2025-1264
6.5 MEDIUM

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to SQL Injection via the 'orderBy' parameter …

Apr 6, 2025
CVE-2025-3308
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 6, 2025
CVE-2025-3307
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Apr 6, 2025
CVE-2024-58133
4.0 MEDIUM

In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarting this node, concurrent writes by logger.go to a …

Apr 6, 2025
CVE-2024-58132
4.0 MEDIUM

In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal nodes to perform concurrent read and write operations …

Apr 6, 2025
CVE-2024-58131
4.0 MEDIUM

FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified …

Apr 6, 2025
CVE-2025-3306
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /don.php. …

Apr 6, 2025
CVE-2025-3305
4.3 MEDIUM

A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerability affects the function addInterceptors of the file MvcConfig.java of the …

Apr 5, 2025
CVE-2025-32366
4.8 MEDIUM

In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=ntohs(rr->rdlen) and memcpy(response+offset,*end,*rdlen) without a check …

Apr 5, 2025
CVE-2025-3304
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_not.php. …

Apr 5, 2025
CVE-2025-32365
4.0 MEDIUM

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

Apr 5, 2025
CVE-2025-32364
4.0 MEDIUM

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

Apr 5, 2025
CVE-2025-3303
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0. Affected by this issue is some unknown functionality …

Apr 5, 2025
CVE-2025-32360
4.2 MEDIUM

In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged …

Apr 5, 2025
CVE-2025-32359
4.8 MEDIUM

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their …

Apr 5, 2025
CVE-2025-32358
4.0 MEDIUM

In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are triggered as POST requests when certain conditions …

Apr 5, 2025
CVE-2025-32357
4.3 MEDIUM

In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that …

Apr 5, 2025
CVE-2024-56370
6.5 MEDIUM

Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically …

Apr 5, 2025
CVE-2024-52322
5.5 MEDIUM

WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically …

Apr 5, 2025
CVE-2024-58036
5.5 MEDIUM

Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically …

Apr 5, 2025
CVE-2024-57868
5.5 MEDIUM

Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically …

Apr 5, 2025
CVE-2024-57835
5.5 MEDIUM

Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. String::Random defaults to Perl's built-in predictable random number generator, the rand() function, which is not cryptographically …

Apr 5, 2025
CVE-2025-30401
6.7 MEDIUM

A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based …

Apr 5, 2025
CVE-2025-3299
7.3 HIGH

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Apr 5, 2025
CVE-2025-3298
4.3 MEDIUM

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Apr 5, 2025
CVE-2025-3297
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The …

Apr 5, 2025
CVE-2025-3296
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file …

Apr 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.