CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30407
6.3 MEDIUM

Local privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39713.

Mar 26, 2025
CVE-2025-2838
6.5 MEDIUM

Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of …

Mar 26, 2025
CVE-2025-2837
8.8 HIGH

Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected …

Mar 26, 2025
CVE-2025-20233
2.5 LOW

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a …

Mar 26, 2025
CVE-2025-20232
5.7 MEDIUM

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.2312.208 and 9.1.2308.212, a low-privileged user that …

Mar 26, 2025
CVE-2025-20231
7.1 HIGH

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud …

Mar 26, 2025
CVE-2025-20229
8.0 HIGH

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does …

Mar 26, 2025
CVE-2025-20228
6.5 MEDIUM

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold …

Mar 26, 2025
CVE-2025-20227
4.3 MEDIUM

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user …

Mar 26, 2025
CVE-2025-20226
5.7 MEDIUM

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.111, and 9.1.2308.214, a low-privileged user that does …

Mar 26, 2025
CVE-2025-31160
2.9 LOW

atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by …

Mar 26, 2025
CVE-2025-2787
8.8 HIGH

KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete …

Mar 26, 2025
CVE-2024-55965
6.5 MEDIUM

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list …

Mar 26, 2025
CVE-2025-30073
7.5 HIGH

An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. The reference assigned to transactions can be reused. When completing a payment, the first or …

Mar 26, 2025
CVE-2025-28361
7.5 HIGH

Unauthorized stack overflow vulnerability in Telesquare TLR-2005KSH v.1.1.4 allows a remote attacker to obtain sensitive information via the systemutil.cgi component.

Mar 26, 2025
CVE-2025-26011
9.8 CRITICAL

Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword.

Mar 26, 2025
CVE-2025-26010
9.8 CRITICAL

Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.

Mar 26, 2025
CVE-2025-26009
7.5 HIGH

Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.

Mar 26, 2025
CVE-2025-26008
9.8 CRITICAL

In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost.

Mar 26, 2025
CVE-2025-26007
9.8 CRITICAL

Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.

Mar 26, 2025
CVE-2025-26006
9.8 CRITICAL

Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.

Mar 26, 2025
CVE-2025-26005
9.8 CRITICAL

Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.

Mar 26, 2025
CVE-2024-55964
9.8 CRITICAL

An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith …

Mar 26, 2025
CVE-2024-55963
6.5 MEDIUM

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing …

Mar 26, 2025
CVE-2025-29322
4.6 MEDIUM

A cross-site scripting (XSS) vulnerability in ScriptCase before v1.0.003 - Build 3 allows attackers to execute arbitrary code via a crafted payload to the "Connection …

Mar 26, 2025
CVE-2025-26004
9.8 CRITICAL

Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.

Mar 26, 2025
CVE-2025-26003
9.8 CRITICAL

Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

Mar 26, 2025
CVE-2025-26002
9.8 CRITICAL

Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.

Mar 26, 2025
CVE-2025-26001
7.5 HIGH

Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.

Mar 26, 2025
CVE-2025-25535
9.8 CRITICAL

HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request.

Mar 26, 2025
CVE-2025-30353
8.6 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow …

Mar 26, 2025
CVE-2025-30352
5.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query …

Mar 26, 2025
CVE-2025-30351
3.5 LOW

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user …

Mar 26, 2025
CVE-2025-2600
6.8 MEDIUM

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not …

Mar 26, 2025
CVE-2025-2562
5.4 MEDIUM

Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a …

Mar 26, 2025
CVE-2025-2528
3.6 LOW

Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one …

Mar 26, 2025
CVE-2025-2499
5.4 MEDIUM

Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass …

Mar 26, 2025
CVE-2024-41643
6.8 MEDIUM

An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.

Mar 26, 2025
CVE-2025-30350
5.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, …

Mar 26, 2025
CVE-2025-30225
5.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, …

Mar 26, 2025
CVE-2025-30217
7.5 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe Framework which could …

Mar 26, 2025
CVE-2025-30164
4.1 MEDIUM

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows …

Mar 26, 2025
CVE-2025-27609
5.4 MEDIUM

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an …

Mar 26, 2025
CVE-2025-2825

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference …

Mar 26, 2025
CVE-2025-2783
8.3 HIGH KEV

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape …

Mar 26, 2025
CVE-2025-2098

Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where …

Mar 26, 2025
CVE-2025-27406
7.6 HIGH

Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions …

Mar 26, 2025
CVE-2025-27405
7.6 HIGH

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an …

Mar 26, 2025
CVE-2025-30524
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in origincode Product Catalog displayproduct allows SQL Injection.This issue affects Product Catalog: …

Mar 26, 2025
CVE-2025-2820
6.5 MEDIUM

An authenticated attacker can compromise the availability of the device via the network

Mar 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.