CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54805
9.8 CRITICAL

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. …

Mar 31, 2025
CVE-2024-54804
9.8 CRITICAL

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname …

Mar 31, 2025
CVE-2024-54803
9.8 CRITICAL

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac …

Mar 31, 2025
CVE-2024-54802
9.8 CRITICAL

In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.

Mar 31, 2025
CVE-2024-24456
5.9 MEDIUM

An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentially due to a buffer overflow.

Mar 31, 2025
CVE-2025-3010
3.3 LOW

A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this issue is the function glslang::TIntermediate::isConversionAllowed of the …

Mar 31, 2025
CVE-2025-3009
6.3 MEDIUM

A vulnerability classified as critical was found in Jinher Network OA C6. Affected by this vulnerability is an unknown functionality of the file /C6/JHSoft.Web.NetDisk/NetDiskProperty.aspx. The …

Mar 31, 2025
CVE-2025-31124
5.3 MEDIUM

Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. …

Mar 31, 2025
CVE-2025-31123
8.7 HIGH

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the …

Mar 31, 2025
CVE-2025-21893
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: keys: Fix UAF in key_put() Once a key's reference count has been reduced to 0, …

Mar 31, 2025
CVE-2025-3008
5.5 MEDIUM

A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/popen of the file /usr/nova/bin/netconfig of the …

Mar 31, 2025
CVE-2025-3007
5.5 MEDIUM

A vulnerability was found in Novastar CX40 up to 2.44.0. It has been rated as critical. This issue affects the function getopt of the file …

Mar 31, 2025
CVE-2025-31129
8.8 HIGH

Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 …

Mar 31, 2025
CVE-2025-31128

gifplayer is a customizable jquery plugin to play and stop animated gifs. gifplayer contains a cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 0.3.7.

Mar 31, 2025
CVE-2025-29908
5.3 MEDIUM

Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash collision vulnerability …

Mar 31, 2025
CVE-2025-3006
7.3 HIGH

A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /edit-category.php?id=8. …

Mar 31, 2025
CVE-2025-3005
3.5 LOW

A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is some unknown functionality of the component …

Mar 31, 2025
CVE-2025-3004
3.5 LOW

A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 31, 2025
CVE-2025-3003
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in ESAFENET CDG 3. Affected is an unknown function of the file /CDGServer3/UserAjax. The manipulation of …

Mar 31, 2025
CVE-2025-31125
5.3 MEDIUM KEV

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev …

Mar 31, 2025
CVE-2025-31122

scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to login to any account by changing the …

Mar 31, 2025
CVE-2025-31117
7.5 HIGH

OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified …

Mar 31, 2025
CVE-2025-31116
4.4 MEDIUM

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in …

Mar 31, 2025
CVE-2025-30369
2.7 LOW

Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but …

Mar 31, 2025
CVE-2025-30368
2.7 LOW

Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler …

Mar 31, 2025
CVE-2025-30223
9.3 CRITICAL

Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability exists in Beego's RenderForm() function due …

Mar 31, 2025
CVE-2025-30006
6.1 MEDIUM

Xorcom CompletePBX is vulnerable to a reflected cross-site scripting (XSS) in the administrative control panel. This issue affects CompletePBX: all versions up to and prior …

Mar 31, 2025
CVE-2025-30005
8.3 HIGH

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved …

Mar 31, 2025
CVE-2025-30004
8.8 HIGH

Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user. This …

Mar 31, 2025
CVE-2025-2794

An unsafe reflection vulnerability in Kentico Xperience allows an unauthenticated attacker to kill the current process, leading to a Denial-of-Service condition. This issue affects Xperience: …

Mar 31, 2025
CVE-2025-2292
6.5 MEDIUM

Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup and Restore functionality.This issue affects CompletePBX: through 5.2.35.

Mar 31, 2025
CVE-2025-3048
6.5 MEDIUM

After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks, the content of those symlinks are copied to …

Mar 31, 2025
CVE-2025-3047
6.5 MEDIUM

When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the …

Mar 31, 2025
CVE-2025-3002
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the …

Mar 31, 2025
CVE-2025-3001
5.3 MEDIUM

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs …

Mar 31, 2025
CVE-2025-30209
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the …

Mar 31, 2025
CVE-2025-30203
4.8 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds …

Mar 31, 2025
CVE-2025-30161
5.4 MEDIUM

OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of …

Mar 31, 2025
CVE-2025-30155
4.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce read permissions on parent trackers in the …

Mar 31, 2025
CVE-2025-30149
6.4 MEDIUM

OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script …

Mar 31, 2025
CVE-2025-29929
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protection on tracker hierarchy administration. An attacker …

Mar 31, 2025
CVE-2025-29772
6.1 MEDIUM

OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without …

Mar 31, 2025
CVE-2025-29766
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from …

Mar 31, 2025
CVE-2025-27149
2.7 LOW

Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in …

Mar 31, 2025
CVE-2025-27095
4.3 MEDIUM

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged …

Mar 31, 2025
CVE-2025-1449

A vulnerability exists in the Rockwell Automation Verve Asset Manager due to insufficient variable sanitizing. A portion of the administrative web interface for Verve's Legacy …

Mar 31, 2025
CVE-2025-3000
5.3 MEDIUM

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible …

Mar 31, 2025
CVE-2025-30095
9.0 CRITICAL

VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across …

Mar 31, 2025
CVE-2025-2999
5.3 MEDIUM

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to …

Mar 31, 2025
CVE-2025-22941
9.8 CRITICAL

A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.

Mar 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.