CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2602
6.3 MEDIUM

A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Mar 21, 2025
CVE-2025-2601
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the …

Mar 21, 2025
CVE-2025-25036
6.8 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8).

Mar 21, 2025
CVE-2025-25035
7.3 HIGH

Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 allows for Reflected XSS and Stored XSS.This issue affects JPlatform …

Mar 21, 2025
CVE-2025-30349
7.2 HIGH

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message …

Mar 21, 2025
CVE-2025-29230
8.6 HIGH

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.

Mar 21, 2025
CVE-2025-29227
6.3 MEDIUM

In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.

Mar 21, 2025
CVE-2025-29226
6.3 MEDIUM

In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.

Mar 21, 2025
CVE-2025-29223
6.3 MEDIUM

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.

Mar 21, 2025
CVE-2024-53351
9.8 CRITICAL

Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.

Mar 21, 2025
CVE-2024-53350
7.4 HIGH

Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escalation of privileges.

Mar 21, 2025
CVE-2024-53349
7.4 HIGH

Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in …

Mar 21, 2025
CVE-2024-53348
7.4 HIGH

LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.

Mar 21, 2025
CVE-2023-43029
6.8 MEDIUM

IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment.

Mar 21, 2025
CVE-2019-16151
4.7 MEDIUM

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker …

Mar 21, 2025
CVE-2025-30168
6.9 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd …

Mar 21, 2025
CVE-2025-30157
6.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a …

Mar 21, 2025
CVE-2025-2598
5.5 MEDIUM

When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property …

Mar 21, 2025
CVE-2025-2593
6.3 MEDIUM

A vulnerability has been found in FastCMS up to 0.1.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Mar 21, 2025
CVE-2025-29927
9.1 CRITICAL

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is …

Mar 21, 2025
CVE-2025-29641
7.3 HIGH

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' parameter.

Mar 21, 2025
CVE-2025-29640
5.4 MEDIUM

Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-report.php via the parameter searchdata..

Mar 21, 2025
CVE-2025-27612
5.9 MEDIUM

libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of capabilities to …

Mar 21, 2025
CVE-2025-24915
7.8 HIGH

When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. …

Mar 21, 2025
CVE-2021-25635
5.5 MEDIUM

An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify …

Mar 21, 2025
CVE-2025-2592
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the …

Mar 21, 2025
CVE-2025-2591
4.3 MEDIUM

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The …

Mar 21, 2025
CVE-2024-57490
7.7 HIGH

Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system administrator through …

Mar 21, 2025
CVE-2025-2590
2.4 LOW

A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic. Affected is the function UpdateRecruitmentById of the file …

Mar 21, 2025
CVE-2025-2589
5.5 MEDIUM

A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. …

Mar 21, 2025
CVE-2025-2597
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability could allow an attacker to execute malicious Javascript code via GET …

Mar 21, 2025
CVE-2025-2588
3.3 LOW

A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation …

Mar 21, 2025
CVE-2025-2587
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Jinher OA C6 1.0. This affects an unknown part of the file IncentivePlanFulfillAppprove.aspx. The manipulation …

Mar 21, 2025
CVE-2025-30179
4.3 MEDIUM

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass …

Mar 21, 2025
CVE-2025-27933
5.4 MEDIUM

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to …

Mar 21, 2025
CVE-2025-27715
3.3 LOW

Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining …

Mar 21, 2025
CVE-2025-25274
4.3 MEDIUM

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run …

Mar 21, 2025
CVE-2025-25068
7.5 HIGH

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers …

Mar 21, 2025
CVE-2025-24920
4.3 MEDIUM

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which …

Mar 21, 2025
CVE-2025-2584
5.0 MEDIUM

A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The …

Mar 21, 2025
CVE-2025-30348
5.8 MEDIUM

encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation …

Mar 21, 2025
CVE-2025-30347
4.0 MEDIUM

Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.

Mar 21, 2025
CVE-2025-30346
5.4 MEDIUM

Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

Mar 21, 2025
CVE-2025-2583
3.5 LOW

A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php. The manipulation …

Mar 21, 2025
CVE-2025-2582
3.5 LOW

A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The …

Mar 21, 2025
CVE-2024-13903
4.3 MEDIUM

A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of …

Mar 21, 2025
CVE-2025-30345
3.5 LOW

An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of …

Mar 21, 2025
CVE-2025-30344
5.3 MEDIUM

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists …

Mar 21, 2025
CVE-2025-30343
3.0 LOW

A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users …

Mar 21, 2025
CVE-2025-30342
5.4 MEDIUM

An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows …

Mar 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.