CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2729
8.0 HIGH

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. …

Mar 25, 2025
CVE-2025-2728
8.0 HIGH

A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code …

Mar 25, 2025
CVE-2025-2727
8.0 HIGH

A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file …

Mar 25, 2025
CVE-2025-2726
8.0 HIGH

A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up …

Mar 25, 2025
CVE-2025-2725
8.0 HIGH

A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected …

Mar 25, 2025
CVE-2025-2717
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of …

Mar 25, 2025
CVE-2025-24514
8.8 HIGH

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to …

Mar 25, 2025
CVE-2025-24513
4.8 MEDIUM

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory …

Mar 25, 2025
CVE-2025-1974
9.8 CRITICAL

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution …

Mar 25, 2025
CVE-2025-1098
8.8 HIGH

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This …

Mar 25, 2025
CVE-2025-1097
8.8 HIGH

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to …

Mar 25, 2025
CVE-2025-2716
2.7 LOW

A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unknown code of the component Samba Path Handler. The manipulation …

Mar 24, 2025
CVE-2025-2715
3.5 LOW

A vulnerability classified as problematic has been found in timschofield webERP up to 5.0.0.rc+13. This affects an unknown part of the file ConfirmDispatch_Invoice.php of the …

Mar 24, 2025
CVE-2025-2714
4.3 MEDIUM

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Mar 24, 2025
CVE-2025-2712
4.3 MEDIUM

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 24, 2025
CVE-2025-26512
9.9 CRITICAL

SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user …

Mar 24, 2025
CVE-2025-2711
4.3 MEDIUM

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop.jsp. The …

Mar 24, 2025
CVE-2025-2710
4.3 MEDIUM

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown processing of the file /menu.jsp. The manipulation …

Mar 24, 2025
CVE-2025-29315
9.8 CRITICAL

An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute …

Mar 24, 2025
CVE-2025-29314
8.1 HIGH

Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to access sensitive information via a man-in-the-middle attack.

Mar 24, 2025
CVE-2025-29313
7.5 HIGH

Use of incorrectly resolved name or reference in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to cause a Denial of …

Mar 24, 2025
CVE-2025-29312
9.1 CRITICAL

An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from …

Mar 24, 2025
CVE-2025-29311
7.5 HIGH

Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to …

Mar 24, 2025
CVE-2025-29310
9.8 CRITICAL

An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute …

Mar 24, 2025
CVE-2025-29135
9.8 CRITICAL

A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security …

Mar 24, 2025
CVE-2025-29100
9.8 CRITICAL

Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.

Mar 24, 2025
CVE-2025-2709
4.3 MEDIUM

A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation …

Mar 24, 2025
CVE-2025-2708
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-api/infra/file/upload of the component …

Mar 24, 2025
CVE-2025-2231
7.8 HIGH

PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange …

Mar 24, 2025
CVE-2025-30163
3.4 LOW

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node …

Mar 24, 2025
CVE-2025-30162
3.2 LOW

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and …

Mar 24, 2025
CVE-2025-2749
7.2 HIGH KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in …

Mar 24, 2025
CVE-2025-2748
6.1 MEDIUM

The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico …

Mar 24, 2025
CVE-2025-2747
9.8 CRITICAL KEV

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication …

Mar 24, 2025
CVE-2025-2746
9.8 CRITICAL KEV

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication …

Mar 24, 2025
CVE-2025-2707
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file …

Mar 24, 2025
CVE-2025-2706
6.3 MEDIUM

A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation …

Mar 24, 2025
CVE-2025-22223
5.3 MEDIUM

Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are …

Mar 24, 2025
CVE-2025-30208
5.3 MEDIUM

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files …

Mar 24, 2025
CVE-2025-30205
7.6 HIGH

kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in …

Mar 24, 2025
CVE-2025-30112
7.1 HIGH

On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, …

Mar 24, 2025
CVE-2025-29778
5.8 MEDIUM

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign …

Mar 24, 2025
CVE-2025-0255
7.2 HIGH

HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input …

Mar 24, 2025
CVE-2025-2705
7.3 HIGH

A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the …

Mar 24, 2025
CVE-2025-29294

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Mar 24, 2025
CVE-2025-23204
4.4 MEDIUM

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl …

Mar 24, 2025
CVE-2025-0256
4.3 MEDIUM

HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization …

Mar 24, 2025
CVE-2024-9103
6.1 MEDIUM

Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messages module) allows Stored XSS. This issue affects Email …

Mar 24, 2025
CVE-2023-25610
9.8 CRITICAL

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 …

Mar 24, 2025
CVE-2021-26105
6.8 MEDIUM

A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker …

Mar 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.