CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24382
7.3 HIGH

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker …

Mar 28, 2025
CVE-2025-22398
9.8 CRITICAL

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker …

Mar 28, 2025
CVE-2024-49565
7.8 HIGH

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged …

Mar 28, 2025
CVE-2024-49564
7.8 HIGH

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged …

Mar 28, 2025
CVE-2024-49563
7.8 HIGH

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged …

Mar 28, 2025
CVE-2025-1860
7.7 HIGH

Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.

Mar 28, 2025
CVE-2025-31092
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows …

Mar 28, 2025
CVE-2025-30232
8.1 HIGH

A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.

Mar 28, 2025
CVE-2025-31101
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vault Group Pty Ltd VaultRE Contact Form 7 allows Stored XSS.This issue affects …

Mar 27, 2025
CVE-2025-31031
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Job Colors for WP Job Manager wp-job-manager-colors allows Stored XSS.This issue affects …

Mar 27, 2025
CVE-2025-2888
4.5 MEDIUM

During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the …

Mar 27, 2025
CVE-2025-2887
4.5 MEDIUM

During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an …

Mar 27, 2025
CVE-2025-2886
4.5 MEDIUM

Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the …

Mar 27, 2025
CVE-2025-2885
4.5 MEDIUM

Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended …

Mar 27, 2025
CVE-2025-2878
2.4 LOW

A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Mar 27, 2025
CVE-2025-28253

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Mar 27, 2025
CVE-2025-26956
7.6 HIGH

Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mar 27, 2025
CVE-2025-26898
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mar 27, 2025
CVE-2025-26890
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 HUSKY woocommerce-products-filter allows PHP Local File Inclusion.This issue …

Mar 27, 2025
CVE-2025-26874
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in memberspace MemberSpace memberspace allows Reflected XSS.This issue affects MemberSpace: from n/a through <= …

Mar 27, 2025
CVE-2025-26873
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mar 27, 2025
CVE-2025-26733
8.2 HIGH

Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mar 27, 2025
CVE-2025-22740
5.3 MEDIUM

Missing Authorization vulnerability in Automattic Sensei LMS sensei-lms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sensei LMS: from n/a through <= 4.24.4.

Mar 27, 2025
CVE-2025-22739
5.3 MEDIUM

Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through <= 4.2.7.5.

Mar 27, 2025
CVE-2024-55070
3.1 LOW

A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allows group managers to edit their own permissions.

Mar 27, 2025
CVE-2025-30093
8.1 HIGH

HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.

Mar 27, 2025
CVE-2025-29306
9.8 CRITICAL

An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.

Mar 27, 2025
CVE-2024-55073
7.6 HIGH

A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give …

Mar 27, 2025
CVE-2024-55072
5.4 MEDIUM

A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give …

Mar 27, 2025
CVE-2023-38272
5.9 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user …

Mar 27, 2025
CVE-2023-37405
6.5 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in …

Mar 27, 2025
CVE-2025-30367
9.8 CRITICAL

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.6 in the nextPage parameter of the …

Mar 27, 2025
CVE-2025-30366
5.4 MEDIUM

WeGIA is a Web manager for charitable institutions. Versions prior to 3.2.8 are vulnerable to stored cross-site scripting. This vulnerability allows unauthorized scripts to be …

Mar 27, 2025
CVE-2025-30365
9.8 CRITICAL

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/socio/sistema/controller/query_geracao_auto.php, specifically in …

Mar 27, 2025
CVE-2025-30364
9.8 CRITICAL

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/funcionario/remuneracao.php, in the …

Mar 27, 2025
CVE-2025-30363
5.4 MEDIUM

WeGIA is a Web manager for charitable institutions. A stored Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 3.2.6. This vulnerability allows unauthorized …

Mar 27, 2025
CVE-2025-30362
5.4 MEDIUM

WeGIA is a Web manager for charitable institutions. A stored Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 3.2.8. This vulnerability allows unauthorized …

Mar 27, 2025
CVE-2025-30361
9.8 CRITICAL

WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to change a …

Mar 27, 2025
CVE-2024-12905
7.5 HIGH

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when …

Mar 27, 2025
CVE-2023-53033
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits If the offset + length goes …

Mar 27, 2025
CVE-2023-53032
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix overflow before widen in the bitmap_ip_create() function. When first_ip is 0, last_ip …

Mar 27, 2025
CVE-2023-53031
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/imc-pmu: Fix use of mutex in IRQs disabled section Current imc-pmu code triggers a WARNING …

Mar 27, 2025
CVE-2023-53030
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Avoid use of GFP_KERNEL in atomic context Using GFP_KERNEL in preemption disable context, causing …

Mar 27, 2025
CVE-2023-53029
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix the use of GFP_KERNEL in atomic context on rt The commit 4af1b64f80fb ("octeontx2-pf: …

Mar 27, 2025
CVE-2023-53028
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "wifi: mac80211: fix memory leak in ieee80211_if_add()" This reverts commit 13e5afd3d773c6fc6ca2b89027befaaaa1ea7293. ieee80211_if_free() is already …

Mar 27, 2025
CVE-2023-53027

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 27, 2025
CVE-2023-53026
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix ib block iterator counter overflow When registering a new DMA MR after selecting …

Mar 27, 2025
CVE-2023-53025

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 27, 2025
CVE-2023-53024
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix pointer-leak due to insufficient speculative store bypass mitigation To mitigate Spectre v4, 2039f26f3aca …

Mar 27, 2025
CVE-2023-53023
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: nfc: Fix use-after-free in local_cleanup() Fix a use-after-free that occurs in kfree_skb() called from …

Mar 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.