CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2961
4.3 MEDIUM

A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function render_mav of the file /aa of the component …

Mar 30, 2025
CVE-2024-13804
9.8 CRITICAL

Unauthenticated RCE in HPE Insight Cluster Management Utility

Mar 30, 2025
CVE-2025-2960
6.5 MEDIUM

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the …

Mar 30, 2025
CVE-2025-2959
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is the function sub_4019A0 of the file …

Mar 30, 2025
CVE-2025-2958
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Mar 30, 2025
CVE-2025-2957
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function sub_401DB0 of the file /usr/sbin/httpd of the …

Mar 30, 2025
CVE-2025-2956
6.5 MEDIUM

A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the …

Mar 30, 2025
CVE-2025-2955
5.3 MEDIUM

A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/ExportIbmsConfig.sh of …

Mar 30, 2025
CVE-2025-2954
3.3 LOW

A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of …

Mar 30, 2025
CVE-2025-2953
3.3 LOW

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to …

Mar 30, 2025
CVE-2025-2952
6.3 MEDIUM

A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /api/api.php?mod=upload&type=1. The …

Mar 30, 2025
CVE-2025-2951
6.3 MEDIUM

A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the file /api/data.php. The manipulation of …

Mar 30, 2025
CVE-2025-1861
9.8 CRITICAL

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response …

Mar 30, 2025
CVE-2025-1736
7.3 HIGH

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient …

Mar 30, 2025
CVE-2025-1734
5.3 MEDIUM

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the …

Mar 30, 2025
CVE-2025-1219
5.3 MEDIUM

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the …

Mar 30, 2025
CVE-2024-55895
2.7 LOW

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. …

Mar 29, 2025
CVE-2024-11180
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, …

Mar 29, 2025
CVE-2025-2840
5.3 MEDIUM

The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the …

Mar 29, 2025
CVE-2025-2803
7.3 HIGH

The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due to …

Mar 29, 2025
CVE-2025-2266
9.8 CRITICAL

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to …

Mar 29, 2025
CVE-2025-2249
8.8 HIGH

The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions …

Mar 29, 2025
CVE-2025-2006
8.8 HIGH

The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the file uploading …

Mar 29, 2025
CVE-2024-13557
6.5 MEDIUM

The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6. This is due …

Mar 29, 2025
CVE-2025-1217
3.1 LOW

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response …

Mar 29, 2025
CVE-2025-31374

Rejected reason: Not used

Mar 29, 2025
CVE-2025-31373

Rejected reason: Not used

Mar 29, 2025
CVE-2025-31372

Rejected reason: Not used

Mar 29, 2025
CVE-2025-31371

Rejected reason: Not used

Mar 29, 2025
CVE-2025-31370

Rejected reason: Not used

Mar 29, 2025
CVE-2025-31369

Rejected reason: Not used

Mar 29, 2025
CVE-2025-31368

Rejected reason: Not used

Mar 29, 2025
CVE-2025-31367

Rejected reason: Not used

Mar 29, 2025
CVE-2024-7577
4.4 MEDIUM

IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.

Mar 29, 2025
CVE-2024-51477
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.

Mar 29, 2025
CVE-2024-43186
5.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.

Mar 29, 2025
CVE-2025-2782

The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local …

Mar 28, 2025
CVE-2025-2781

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an …

Mar 28, 2025
CVE-2025-28097
5.5 MEDIUM

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

Mar 28, 2025
CVE-2025-28096
5.4 MEDIUM

OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

Mar 28, 2025
CVE-2025-28094
6.5 MEDIUM

shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

Mar 28, 2025
CVE-2025-28093
6.3 MEDIUM

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.

Mar 28, 2025
CVE-2025-28092
6.3 MEDIUM

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.

Mar 28, 2025
CVE-2025-28091
9.1 CRITICAL

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

Mar 28, 2025
CVE-2025-28090
9.1 CRITICAL

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

Mar 28, 2025
CVE-2025-28089
9.1 CRITICAL

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

Mar 28, 2025
CVE-2025-28087
9.8 CRITICAL

Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.

Mar 28, 2025
CVE-2025-25579
9.8 CRITICAL

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

Mar 28, 2025
CVE-2024-58130
7.2 HIGH

In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.

Mar 28, 2025
CVE-2024-58129
5.5 MEDIUM

In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct …

Mar 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.