CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50053
6.3 MEDIUM

Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task …

Mar 21, 2025
CVE-2025-2581
4.3 MEDIUM

A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the function malloc of the component DICOM File …

Mar 21, 2025
CVE-2025-26336
8.3 HIGH

Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior …

Mar 21, 2025
CVE-2025-2585
8.8 HIGH

EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify, …

Mar 21, 2025
CVE-2025-29814
9.3 CRITICAL

Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Mar 21, 2025
CVE-2025-29807
8.7 HIGH

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mar 21, 2025
CVE-2023-28207
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may …

Mar 21, 2025
CVE-2024-54564
6.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file …

Mar 21, 2025
CVE-2024-54551
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, …

Mar 21, 2025
CVE-2024-44305
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root …

Mar 21, 2025
CVE-2024-44199
7.1 HIGH

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unexpected …

Mar 21, 2025
CVE-2025-2198

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 20, 2025
CVE-2025-30334
6.5 MEDIUM

In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash.

Mar 20, 2025
CVE-2025-2574

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

Mar 20, 2025
CVE-2025-2538
9.8 CRITICAL

A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated …

Mar 20, 2025
CVE-2025-25758
7.5 HIGH

An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

Mar 20, 2025
CVE-2025-26853
10.0 CRITICAL

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

Mar 20, 2025
CVE-2025-26852
10.0 CRITICAL

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.

Mar 20, 2025
CVE-2025-30160
7.5 HIGH

Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by …

Mar 20, 2025
CVE-2025-2557
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is some unknown functionality of the …

Mar 20, 2025
CVE-2025-29980
9.8 CRITICAL

A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as …

Mar 20, 2025
CVE-2025-29218
6.5 MEDIUM

Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial …

Mar 20, 2025
CVE-2025-29217
6.5 MEDIUM

Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial …

Mar 20, 2025
CVE-2025-2556
4.3 MEDIUM

A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknown functionality of the component Video Stream …

Mar 20, 2025
CVE-2025-2555
2.9 LOW

A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unknown function of the component FTP Credentials. …

Mar 20, 2025
CVE-2025-2553
4.3 MEDIUM

A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been rated as problematic. This issue affects some unknown processing of the file …

Mar 20, 2025
CVE-2025-29923
3.7 LOW

go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redis potentially responds out of order when …

Mar 20, 2025
CVE-2025-29922
9.6 CRITICAL

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting …

Mar 20, 2025
CVE-2025-29914
5.4 MEDIUM

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is made on an URI starting with …

Mar 20, 2025
CVE-2025-29215
6.5 MEDIUM

Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.

Mar 20, 2025
CVE-2025-2565
4.3 MEDIUM

The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through …

Mar 20, 2025
CVE-2025-2552
4.3 MEDIUM

A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/formTcpipSetup. …

Mar 20, 2025
CVE-2025-2551
4.3 MEDIUM

A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been classified as problematic. This affects an unknown part of the file /goform/formSetPortTr. …

Mar 20, 2025
CVE-2025-2550
4.3 MEDIUM

A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Mar 20, 2025
CVE-2025-2549
4.3 MEDIUM

A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 20, 2025
CVE-2025-2480
7.8 HIGH

Santesoft Sante DICOM Viewer Pro is vulnerable to an out-of-bounds write, which requires a user to open a malicious DCM file, resulting in execution of …

Mar 20, 2025
CVE-2025-29149
7.5 HIGH

Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.

Mar 20, 2025
CVE-2025-29121
7.5 HIGH

A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based …

Mar 20, 2025
CVE-2024-7598
3.1 LOW

A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The …

Mar 20, 2025
CVE-2024-57440
7.5 HIGH

D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webproc cgi

Mar 20, 2025
CVE-2025-2548
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file /goform/formSetDomainFilter. The …

Mar 20, 2025
CVE-2025-2547
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02. This issue affects some unknown processing of the file …

Mar 20, 2025
CVE-2025-29214
7.5 HIGH

Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.

Mar 20, 2025
CVE-2025-23120
8.8 HIGH

A vulnerability allowing remote code execution (RCE) for domain users.

Mar 20, 2025
CVE-2025-2546
4.3 MEDIUM

A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component …

Mar 20, 2025
CVE-2025-29411
9.8 CRITICAL

An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a …

Mar 20, 2025
CVE-2024-48591
6.1 MEDIUM

Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon …

Mar 20, 2025
CVE-2025-29412
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML …

Mar 20, 2025
CVE-2025-29410
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting …

Mar 20, 2025
CVE-2025-1496
6.5 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse.This issue affects Coslat Hotspot: before 6.26.0.R.20250227.

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.