CVE Database

10779+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1270
9.1 CRITICAL

Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and …

Feb 13, 2025
CVE-2024-13182
9.8 CRITICAL

The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect …

Feb 13, 2025
CVE-2024-10763
9.8 CRITICAL

The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes …

Feb 13, 2025
CVE-2025-0896
9.8 CRITICAL

Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by …

Feb 13, 2025
CVE-2025-25286
9.8 CRITICAL

Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution …

Feb 13, 2025
CVE-2024-7102
9.6 CRITICAL

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as …

Feb 13, 2025
CVE-2024-57604
9.8 CRITICAL

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

Feb 12, 2025
CVE-2024-57602
9.8 CRITICAL

An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.

Feb 12, 2025
CVE-2022-31631
9.1 CRITICAL

In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly …

Feb 12, 2025
CVE-2025-0108
9.1 CRITICAL KEV

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the …

Feb 12, 2025
CVE-2025-25343
9.8 CRITICAL

Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.

Feb 12, 2025
CVE-2025-25746
9.8 CRITICAL

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module.

Feb 12, 2025
CVE-2025-25744
9.8 CRITICAL

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module.

Feb 12, 2025
CVE-2025-25742
9.8 CRITICAL

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module.

Feb 12, 2025
CVE-2025-25182
9.4 CRITICAL

Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 …

Feb 12, 2025
CVE-2025-25351
9.8 CRITICAL

PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.

Feb 12, 2025
CVE-2025-25349
9.8 CRITICAL

PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.

Feb 12, 2025
CVE-2025-26361
9.1 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-26359
9.8 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-26347
9.8 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-26345
9.8 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-26344
9.8 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-26342
9.8 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-26341
9.8 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-26339
9.8 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-1100
9.8 CRITICAL

A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker …

Feb 12, 2025
CVE-2024-10960
9.9 CRITICAL

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in …

Feb 12, 2025
CVE-2024-13365
9.8 CRITICAL

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives …

Feb 12, 2025
CVE-2024-12213
9.8 CRITICAL

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin …

Feb 12, 2025
CVE-2024-13421
9.8 CRITICAL

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to …

Feb 12, 2025
CVE-2022-3180
9.8 CRITICAL

The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious …

Feb 11, 2025
CVE-2025-25530
9.8 CRITICAL

Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. …

Feb 11, 2025
CVE-2025-1044
9.8 CRITICAL

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is …

Feb 11, 2025
CVE-2025-24434
9.1 CRITICAL

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker …

Feb 11, 2025
CVE-2025-21198
9.0 CRITICAL

Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability

Feb 11, 2025
CVE-2025-1126
9.3 CRITICAL

A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.

Feb 11, 2025
CVE-2025-24973
9.3 CRITICAL

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the …

Feb 11, 2025
CVE-2025-22467
9.9 CRITICAL

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

Feb 11, 2025
CVE-2024-47908
9.1 CRITICAL

OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote …

Feb 11, 2025
CVE-2024-10644
9.1 CRITICAL

Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to …

Feb 11, 2025
CVE-2024-12366
9.8 CRITICAL

PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) …

Feb 11, 2025
CVE-2025-26410
9.8 CRITICAL

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking …

Feb 11, 2025
CVE-2025-0181
9.8 CRITICAL

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.8. This is due …

Feb 11, 2025
CVE-2025-0180
9.8 CRITICAL

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin …

Feb 11, 2025
CVE-2025-1144
9.8 CRITICAL

School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view specific pages and obtain database information as well as …

Feb 11, 2025
CVE-2025-24016
9.9 CRITICAL KEV

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an …

Feb 10, 2025
CVE-2024-13011
9.8 CRITICAL

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up …

Feb 10, 2025
CVE-2025-0316
9.8 CRITICAL

The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication …

Feb 8, 2025
CVE-2024-55215
9.8 CRITICAL

An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

Feb 7, 2025
CVE-2024-57707
9.8 CRITICAL

An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.

Feb 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.