CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0254
5.9 MEDIUM

HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially …

Mar 20, 2025
CVE-2024-48590
9.8 CRITICAL

Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.

Mar 20, 2025
CVE-2025-29101
7.5 HIGH

Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function.

Mar 20, 2025
CVE-2025-2539
7.5 HIGH

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all …

Mar 20, 2025
CVE-2025-2311
9.0 CRITICAL

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication …

Mar 20, 2025
CVE-2025-27888
5.4 MEDIUM

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open …

Mar 20, 2025
CVE-2025-1802
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in …

Mar 20, 2025
CVE-2024-13923
7.6 HIGH

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 …

Mar 20, 2025
CVE-2024-13922
2.7 LOW

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the …

Mar 20, 2025
CVE-2024-13921
7.2 HIGH

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 …

Mar 20, 2025
CVE-2024-13920
4.9 MEDIUM

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via …

Mar 20, 2025
CVE-2024-13558
7.5 HIGH

The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due …

Mar 20, 2025
CVE-2025-1796
8.8 HIGH

A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo-random number generator (PRNG) used …

Mar 20, 2025
CVE-2025-1474
5.5 MEDIUM

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, …

Mar 20, 2025
CVE-2025-1473
7.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a …

Mar 20, 2025
CVE-2025-1451
7.5 HIGH

A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or validate the length …

Mar 20, 2025
CVE-2025-1040
8.8 HIGH

AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from …

Mar 20, 2025
CVE-2025-0628
8.1 HIGH

An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided …

Mar 20, 2025
CVE-2025-0508
5.9 MEDIUM

A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows …

Mar 20, 2025
CVE-2025-0454
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname …

Mar 20, 2025
CVE-2025-0453
7.5 HIGH

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly …

Mar 20, 2025
CVE-2025-0452
8.2 HIGH

eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, …

Mar 20, 2025
CVE-2025-0330
7.5 HIGH

In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability …

Mar 20, 2025
CVE-2025-0317
7.5 HIGH

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can …

Mar 20, 2025
CVE-2025-0315
7.5 HIGH

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. …

Mar 20, 2025
CVE-2025-0312
7.5 HIGH

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama …

Mar 20, 2025
CVE-2025-0281
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can inject malicious JavaScript into the SAML IdP XML metadata, …

Mar 20, 2025
CVE-2025-0192
5.4 MEDIUM

A stored Cross-site Scripting (XSS) vulnerability exists in the latest version of wandb/openui. The vulnerability is present in the edit HTML functionality, where an attacker …

Mar 20, 2025
CVE-2025-0191
6.5 MEDIUM

A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-data …

Mar 20, 2025
CVE-2025-0190
7.5 HIGH

In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through …

Mar 20, 2025
CVE-2025-0189
7.5 HIGH

In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, …

Mar 20, 2025
CVE-2025-0188
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacker to construct a response link by saving the …

Mar 20, 2025
CVE-2025-0187
7.5 HIGH

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of …

Mar 20, 2025
CVE-2025-0185
8.8 HIGH

A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs …

Mar 20, 2025
CVE-2025-0184
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX files. If …

Mar 20, 2025
CVE-2025-0183
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts …

Mar 20, 2025
CVE-2025-0182
7.5 HIGH

A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of …

Mar 20, 2025
CVE-2024-9920
8.8 HIGH

In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangerous ones like .py, .sh, .bat, …

Mar 20, 2025
CVE-2024-9919
8.4 HIGH

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call …

Mar 20, 2025
CVE-2024-9900
6.1 MEDIUM

mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vulnerability arises due to improper sanitization of user input, allowing the …

Mar 20, 2025
CVE-2024-9880

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 20, 2025
CVE-2024-9847
8.0 HIGH

FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a …

Mar 20, 2025
CVE-2024-9701
9.8 CRITICAL

A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python …

Mar 20, 2025
CVE-2024-9699
5.4 MEDIUM

A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript …

Mar 20, 2025
CVE-2024-9617
6.5 MEDIUM

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of …

Mar 20, 2025
CVE-2024-9612
6.5 MEDIUM

In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be …

Mar 20, 2025
CVE-2024-9606
7.5 HIGH

In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the …

Mar 20, 2025
CVE-2024-9597
7.1 HIGH

A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability …

Mar 20, 2025
CVE-2024-9447
6.5 MEDIUM

An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to …

Mar 20, 2025
CVE-2024-9439
8.8 HIGH

SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.