CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31283
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-31282
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-20212
7.7 HIGH

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to …

Apr 2, 2025
CVE-2025-20203
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Apr 2, 2025
CVE-2025-20139
7.5 HIGH

A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service …

Apr 2, 2025
CVE-2025-20120
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to …

Apr 2, 2025
CVE-2025-0014
7.3 HIGH

Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Apr 2, 2025
CVE-2024-36337
7.9 HIGH

Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of confidentiality, integrity or availability.

Apr 2, 2025
CVE-2024-36336
7.9 HIGH

Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a loss of confidentiality, integrity, …

Apr 2, 2025
CVE-2024-36328
7.3 HIGH

Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of integrity or availability.

Apr 2, 2025
CVE-2025-0154
5.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers.

Apr 2, 2025
CVE-2024-56476
5.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.

Apr 2, 2025
CVE-2024-56475
5.4 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Apr 2, 2025
CVE-2024-56474
4.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Apr 2, 2025
CVE-2025-31728
5.5 MEDIUM

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe …

Apr 2, 2025
CVE-2025-31727
5.5 MEDIUM

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by …

Apr 2, 2025
CVE-2025-31726
5.5 MEDIUM

Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be …

Apr 2, 2025
CVE-2025-31725
5.5 MEDIUM

Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read …

Apr 2, 2025
CVE-2025-31724
4.3 MEDIUM

Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be …

Apr 2, 2025
CVE-2025-31723
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to change and reset the build queue order.

Apr 2, 2025
CVE-2025-31722
8.8 HIGH

In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute …

Apr 2, 2025
CVE-2025-31721
4.3 MEDIUM

A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an …

Apr 2, 2025
CVE-2025-31720
4.3 MEDIUM

A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy …

Apr 2, 2025
CVE-2024-56341
5.4 MEDIUM

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Apr 2, 2025
CVE-2024-25051
6.6 MEDIUM

IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on …

Apr 2, 2025
CVE-2025-21994
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field of smb_acl parse_dcal() validate num_aces to allocate posix_ace_state_array. …

Apr 2, 2025
CVE-2024-50597
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial …

Apr 2, 2025
CVE-2024-50596
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial …

Apr 2, 2025
CVE-2024-50595
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead …

Apr 2, 2025
CVE-2024-50594
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead …

Apr 2, 2025
CVE-2024-50385
6.5 MEDIUM

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to …

Apr 2, 2025
CVE-2024-50384
6.5 MEDIUM

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to …

Apr 2, 2025
CVE-2024-45064
8.5 HIGH

A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead …

Apr 2, 2025
CVE-2025-30090
7.2 HIGH

mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers, because JavaScript payloads are mishandled after $encoded has been set to …

Apr 2, 2025
CVE-2025-27556
5.8 MEDIUM

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, …

Apr 2, 2025
CVE-2025-21993
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic() When performing an iSCSI boot using IPv6, iscsistart …

Apr 2, 2025
CVE-2025-21992
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera The HP 5MP Camera (USB ID 0408:5473) …

Apr 2, 2025
CVE-2025-21991
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes Currently, load_microcode_amd() iterates over all NUMA …

Apr 2, 2025
CVE-2025-21990
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flags PRT BOs may not have …

Apr 2, 2025
CVE-2025-21989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix missing .is_two_pixels_per_container Starting from 6.11, AMDGPU driver, while being loaded with amdgpu.dc=1, due …

Apr 2, 2025
CVE-2025-21988
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending …

Apr 2, 2025
CVE-2025-21987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_buffer Otherwise an uninitialized value can be returned if amdgpu_res_cleared …

Apr 2, 2025
CVE-2025-1805
5.3 MEDIUM

Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.

Apr 2, 2025
CVE-2025-2842
4.3 MEDIUM

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo …

Apr 2, 2025
CVE-2025-2786
4.3 MEDIUM

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This …

Apr 2, 2025
CVE-2025-3099
6.1 MEDIUM

The Advanced Search by My Solr Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This …

Apr 2, 2025
CVE-2025-3098
6.1 MEDIUM

The Video Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.0.0.3 due …

Apr 2, 2025
CVE-2025-3097
6.1 MEDIUM

The wp Time Machine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.0. This is due to …

Apr 2, 2025
CVE-2025-3063
8.8 HIGH

The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability …

Apr 2, 2025
CVE-2025-2513
6.4 MEDIUM

The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Apr 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.