CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3148
3.3 LOW

A vulnerability was found in codeprojects Product Management System 1.0 and classified as problematic. This issue affects some unknown processing of the component Login. The …

Apr 3, 2025
CVE-2025-3147
7.3 HIGH

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-subadmin.php. The …

Apr 3, 2025
CVE-2025-3146
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Bus Pass Management System 1.0. This affects an unknown part of the file /view-pass-detail.php. …

Apr 3, 2025
CVE-2025-3145
3.3 LOW

A vulnerability, which was classified as problematic, has been found in MindSpore 2.5.0. Affected by this issue is the function mindspore.numpy.fft.rfft2. The manipulation leads to …

Apr 3, 2025
CVE-2025-30485
6.2 MEDIUM

UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attaching to the affected product an external storage …

Apr 3, 2025
CVE-2025-3144
3.3 LOW

A vulnerability classified as problematic was found in MindSpore 2.5.0. Affected by this vulnerability is the function mindspore.numpy.fft.hfftn. The manipulation leads to memory corruption. It …

Apr 3, 2025
CVE-2025-3143
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The …

Apr 3, 2025
CVE-2025-3142
6.3 MEDIUM

A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 3, 2025
CVE-2025-31334
6.8 MEDIUM

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists …

Apr 3, 2025
CVE-2025-2055
6.8 MEDIUM

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users …

Apr 3, 2025
CVE-2025-3141
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 3, 2025
CVE-2025-3140
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 3, 2025
CVE-2025-3139
5.3 MEDIUM

A vulnerability was found in code-projects Bus Reservation System 1.0 and classified as critical. Affected by this issue is the function Login of the component …

Apr 3, 2025
CVE-2025-3138
7.3 HIGH

A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Apr 3, 2025
CVE-2025-3137
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file …

Apr 3, 2025
CVE-2025-3136
3.3 LOW

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation …

Apr 3, 2025
CVE-2025-2784
7.0 HIGH

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may …

Apr 3, 2025
CVE-2025-29991
2.2 LOW

Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV …

Apr 3, 2025
CVE-2025-3153
6.5 MEDIUM

Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are …

Apr 3, 2025
CVE-2025-3135
6.3 MEDIUM

A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The …

Apr 3, 2025
CVE-2025-3134
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation …

Apr 3, 2025
CVE-2025-3154

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.

Apr 2, 2025
CVE-2025-3123
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme …

Apr 2, 2025
CVE-2025-3130
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1.

Apr 2, 2025
CVE-2025-3129
4.8 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.

Apr 2, 2025
CVE-2025-3122
3.1 LOW

A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation …

Apr 2, 2025
CVE-2025-3121
3.3 LOW

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is …

Apr 2, 2025
CVE-2025-3120
6.3 MEDIUM

A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 2, 2025
CVE-2025-3119
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /tutor/courses/manage_course.php. …

Apr 2, 2025
CVE-2025-31484

conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Between 2025-02-10 and 2025-04-01, conda-forge infrastructure used the wrong token for …

Apr 2, 2025
CVE-2025-31479
8.2 HIGH

canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step …

Apr 2, 2025
CVE-2025-31477
9.8 CRITICAL

The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs …

Apr 2, 2025
CVE-2025-30218
5.9 MEDIUM

Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this …

Apr 2, 2025
CVE-2025-27608

Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified …

Apr 2, 2025
CVE-2025-0257
6.3 MEDIUM

HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its …

Apr 2, 2025
CVE-2025-3118
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. …

Apr 2, 2025
CVE-2025-30080
7.5 HIGH

Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software …

Apr 2, 2025
CVE-2025-2704
7.5 HIGH

OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets …

Apr 2, 2025
CVE-2025-29719
6.1 MEDIUM

SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.

Apr 2, 2025
CVE-2025-29085
9.8 CRITICAL

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

Apr 2, 2025
CVE-2025-29063
9.8 CRITICAL

An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled …

Apr 2, 2025
CVE-2025-29062
9.8 CRITICAL

An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead …

Apr 2, 2025
CVE-2025-22925
7.5 HIGH

OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the …

Apr 2, 2025
CVE-2025-22924
8.8 HIGH

OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.

Apr 2, 2025
CVE-2025-22923
8.8 HIGH

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to …

Apr 2, 2025
CVE-2024-38392
9.1 CRITICAL

Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted …

Apr 2, 2025
CVE-2024-37917
7.5 HIGH

Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.

Apr 2, 2025
CVE-2025-31286
4.6 MEDIUM

An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has …

Apr 2, 2025
CVE-2025-31285
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-31284
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then …

Apr 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.