CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30213
8.8 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific …

Mar 25, 2025
CVE-2025-30212
7.5 HIGH

Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could …

Mar 25, 2025
CVE-2025-2532
7.8 HIGH

Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. …

Mar 25, 2025
CVE-2025-2531
7.8 HIGH

Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Mar 25, 2025
CVE-2025-2530
7.8 HIGH

Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Mar 25, 2025
CVE-2025-27147
8.2 HIGH

The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, …

Mar 25, 2025
CVE-2025-26742
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for …

Mar 25, 2025
CVE-2024-55604
4.3 MEDIUM

Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of …

Mar 25, 2025
CVE-2025-30091

In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary …

Mar 25, 2025
CVE-2025-29635
7.2 HIGH KEV

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST …

Mar 25, 2025
CVE-2025-22230
7.8 HIGH

VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may …

Mar 25, 2025
CVE-2024-42533
9.8 CRITICAL

SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter.

Mar 25, 2025
CVE-2025-29932
4.1 MEDIUM

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

Mar 25, 2025
CVE-2025-27633
6.1 MEDIUM

The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-side code injection that might be used to compromise the confidentiality …

Mar 25, 2025
CVE-2025-27632
6.1 MEDIUM

A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple …

Mar 25, 2025
CVE-2025-27631
6.5 MEDIUM

The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that …

Mar 25, 2025
CVE-2025-1445
7.5 HIGH

A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes …

Mar 25, 2025
CVE-2024-12169
6.5 MEDIUM

A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart …

Mar 25, 2025
CVE-2024-11499
4.9 MEDIUM

A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can …

Mar 25, 2025
CVE-2024-10037
4.4 MEDIUM

A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted …

Mar 25, 2025
CVE-2022-1804
5.5 MEDIUM

accountsservice no longer drops permissions when writting .pam_environment

Mar 25, 2025
CVE-2025-2109
5.8 MEDIUM

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, …

Mar 25, 2025
CVE-2025-2757
6.3 MEDIUM

A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of …

Mar 25, 2025
CVE-2025-2756
6.3 MEDIUM

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of …

Mar 25, 2025
CVE-2025-2635
6.1 MEDIUM

The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg() function without appropriate escaping on the …

Mar 25, 2025
CVE-2025-2542
6.4 MEDIUM

The Your Simple SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Mar 25, 2025
CVE-2024-53679
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to …

Mar 25, 2025
CVE-2024-53678
8.8 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a …

Mar 25, 2025
CVE-2025-2755
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection …

Mar 25, 2025
CVE-2025-2754
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection …

Mar 25, 2025
CVE-2025-2753
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file …

Mar 25, 2025
CVE-2025-2559
4.9 MEDIUM

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT …

Mar 25, 2025
CVE-2025-2510
5.5 MEDIUM

The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter in all versions up to, and including, 1.0 …

Mar 25, 2025
CVE-2025-2319
8.8 HIGH

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is …

Mar 25, 2025
CVE-2024-13731
6.4 MEDIUM

The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert Box …

Mar 25, 2025
CVE-2024-13710
4.3 MEDIUM

The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is …

Mar 25, 2025
CVE-2024-13690
7.2 HIGH

The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submission parameters in all versions up to, and …

Mar 25, 2025
CVE-2025-2752
4.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h …

Mar 25, 2025
CVE-2025-2751
4.3 MEDIUM

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file …

Mar 25, 2025
CVE-2025-2750
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp …

Mar 25, 2025
CVE-2025-2744
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component …

Mar 25, 2025
CVE-2025-2743
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the file /admin-api/mp/material/upload-temporary of …

Mar 25, 2025
CVE-2025-2742
5.4 MEDIUM

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload …

Mar 25, 2025
CVE-2025-2740
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/eligibility.php. …

Mar 25, 2025
CVE-2025-2252
5.3 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Mar 25, 2025
CVE-2025-1320
4.3 MEDIUM

The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or …

Mar 25, 2025
CVE-2024-12623
6.4 MEDIUM

The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in all versions up to, and including, 0.10.6 …

Mar 25, 2025
CVE-2025-2739
7.3 HIGH

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

Mar 25, 2025
CVE-2025-2738
7.3 HIGH

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Mar 25, 2025
CVE-2025-2737
7.3 HIGH

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the …

Mar 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.