CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3181
7.3 HIGH

A vulnerability, which was classified as critical, has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this issue is some unknown …

Apr 3, 2025
CVE-2025-30370
7.4 HIGH

jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Git repository under a name that …

Apr 3, 2025
CVE-2025-0279
4.3 MEDIUM

HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, …

Apr 3, 2025
CVE-2025-0278
4.3 MEDIUM

HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug …

Apr 3, 2025
CVE-2025-3180
7.3 HIGH

A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the …

Apr 3, 2025
CVE-2025-3179
7.3 HIGH

A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. …

Apr 3, 2025
CVE-2025-3178
7.3 HIGH

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of …

Apr 3, 2025
CVE-2024-56528
7.5 HIGH

This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large …

Apr 3, 2025
CVE-2024-47217
6.5 MEDIUM

An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server …

Apr 3, 2025
CVE-2024-47215
7.5 HIGH

An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to …

Apr 3, 2025
CVE-2024-47214
7.5 HIGH

An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, …

Apr 3, 2025
CVE-2024-47213
7.5 HIGH

An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and …

Apr 3, 2025
CVE-2024-47212
7.5 HIGH

An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and …

Apr 3, 2025
CVE-2024-45199
8.8 HIGH

insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the …

Apr 3, 2025
CVE-2025-3177
5.0 MEDIUM

A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation …

Apr 3, 2025
CVE-2025-3176
7.3 HIGH

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. This affects an unknown part of the …

Apr 3, 2025
CVE-2025-31489

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be invalid, which …

Apr 3, 2025
CVE-2025-31485
7.5 HIGH

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL grant on a property might …

Apr 3, 2025
CVE-2025-31481
7.5 HIGH

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security …

Apr 3, 2025
CVE-2025-31161
9.8 CRITICAL KEV

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as …

Apr 3, 2025
CVE-2025-31119
7.6 HIGH

generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as …

Apr 3, 2025
CVE-2025-30406
9.0 CRITICAL KEV

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in …

Apr 3, 2025
CVE-2025-29570
7.8 HIGH

An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check of a binary named …

Apr 3, 2025
CVE-2025-29504
7.8 HIGH

Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.

Apr 3, 2025
CVE-2025-29462
9.8 CRITICAL

A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP …

Apr 3, 2025
CVE-2025-29064
9.8 CRITICAL

An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.

Apr 3, 2025
CVE-2025-26818
9.8 CRITICAL

Netwrix Password Secure through 9.2 allows command injection.

Apr 3, 2025
CVE-2025-26817
9.8 CRITICAL

Netwrix Password Secure 9.2.0.32454 allows OS command injection.

Apr 3, 2025
CVE-2024-45198
8.8 HIGH

insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process …

Apr 3, 2025
CVE-2025-3175
7.3 HIGH

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

Apr 3, 2025
CVE-2025-3174
7.3 HIGH

A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Apr 3, 2025
CVE-2025-3173
7.3 HIGH

A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the file …

Apr 3, 2025
CVE-2025-31487
7.7 HIGH

The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in …

Apr 3, 2025
CVE-2025-31486
5.3 MEDIUM

Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or …

Apr 3, 2025
CVE-2025-29647
9.8 CRITICAL

SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.

Apr 3, 2025
CVE-2024-22611
9.8 CRITICAL

OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.

Apr 3, 2025
CVE-2025-3172
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0. This issue affects some unknown processing of …

Apr 3, 2025
CVE-2025-3171
7.3 HIGH

A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerability affects unknown code of the file /approve_lawyer.php. The …

Apr 3, 2025
CVE-2025-3170
7.3 HIGH

A vulnerability classified as critical has been found in Project Worlds Online Lawyer Management System 1.0. This affects an unknown part of the file /admin_user.php. …

Apr 3, 2025
CVE-2025-31483

Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media …

Apr 3, 2025
CVE-2025-31127
5.3 MEDIUM

Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25.03.3, the entity in control of …

Apr 3, 2025
CVE-2025-31126
5.3 MEDIUM

Element X iOS is a Matrix iOS Client provided by Element. In Element X iOS version between 1.6.13 and 25.03.7, the entity in control of …

Apr 3, 2025
CVE-2025-3169
5.0 MEDIUM

A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Apr 3, 2025
CVE-2025-3168
7.3 HIGH

A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 3, 2025
CVE-2025-3167
6.5 MEDIUM

A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of …

Apr 3, 2025
CVE-2025-3166
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Product Management System 1.0. This vulnerability affects the function search_item of the component Search Product Menu. …

Apr 3, 2025
CVE-2025-32054
3.3 LOW

In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file

Apr 3, 2025
CVE-2025-31115

XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug …

Apr 3, 2025
CVE-2023-47639
5.3 MEDIUM

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are …

Apr 3, 2025
CVE-2025-3165
5.3 MEDIUM

A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of the file chitu/chitu/backend.py. The manipulation of the …

Apr 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.