CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42176
2.6 LOW

HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an …

Mar 19, 2025
CVE-2024-55551
8.3 HIGH

An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the …

Mar 19, 2025
CVE-2025-2512
9.8 CRITICAL

The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the …

Mar 19, 2025
CVE-2025-2511
4.9 MEDIUM

The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.6 due …

Mar 19, 2025
CVE-2024-45644
4.7 MEDIUM

IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

Mar 19, 2025
CVE-2024-13933
8.8 HIGH

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. …

Mar 19, 2025
CVE-2024-13442
9.8 CRITICAL

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.0. This is …

Mar 19, 2025
CVE-2024-12920
8.8 HIGH

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a …

Mar 19, 2025
CVE-2025-27018
6.3 MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql …

Mar 19, 2025
CVE-2024-13790
9.8 CRITICAL

The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Mar 19, 2025
CVE-2024-12137
7.6 HIGH

Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking.This issue affects ANKA JPD-00028: before V.01.01.

Mar 19, 2025
CVE-2024-12136
6.9 MEDIUM

Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass.This issue affects ANKA JPD-00028: before V.01.01.

Mar 19, 2025
CVE-2024-13412
7.5 HIGH

The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions …

Mar 19, 2025
CVE-2024-13410
9.8 CRITICAL

The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and including, 1.7.0, and in all versions …

Mar 19, 2025
CVE-2025-30236
8.6 HIGH

Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a …

Mar 19, 2025
CVE-2025-30235
3.5 LOW

Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed authentication attempts, but instead allows hundreds of …

Mar 19, 2025
CVE-2025-1232
8.8 HIGH

The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform …

Mar 19, 2025
CVE-2024-50631
7.5 HIGH

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, …

Mar 19, 2025
CVE-2024-50630
7.5 HIGH

Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain …

Mar 19, 2025
CVE-2024-50629
5.3 MEDIUM

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, …

Mar 19, 2025
CVE-2024-12922
9.8 CRITICAL

The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within …

Mar 19, 2025
CVE-2025-30234
8.3 HIGH

SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image …

Mar 19, 2025
CVE-2025-2290
5.3 MEDIUM

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability …

Mar 19, 2025
CVE-2024-12295
8.8 HIGH

The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is …

Mar 19, 2025
CVE-2024-11131
9.8 CRITICAL

A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models …

Mar 19, 2025
CVE-2024-10442
10.0 CRITICAL

Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote …

Mar 19, 2025
CVE-2024-10445
4.3 MEDIUM

Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 …

Mar 19, 2025
CVE-2024-10444
7.5 HIGH

Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication …

Mar 19, 2025
CVE-2024-10441
9.8 CRITICAL

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before …

Mar 19, 2025
CVE-2025-30140
7.5 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered …

Mar 18, 2025
CVE-2024-57151
6.8 MEDIUM

SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function

Mar 18, 2025
CVE-2024-12563
8.8 HIGH

The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This …

Mar 18, 2025
CVE-2025-30142
8.1 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism …

Mar 18, 2025
CVE-2025-30141
7.5 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream. It exposes API endpoints …

Mar 18, 2025
CVE-2025-30139
9.8 CRITICAL

An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials …

Mar 18, 2025
CVE-2025-30138
4.6 MEDIUM

An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized …

Mar 18, 2025
CVE-2025-30137
9.8 CRITICAL

An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application …

Mar 18, 2025
CVE-2025-29930

imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] parameter is manipulated to include malicious input (e.g., …

Mar 18, 2025
CVE-2025-29907
7.5 HIGH

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU …

Mar 18, 2025
CVE-2025-29790
5.4 MEDIUM

Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. …

Mar 18, 2025
CVE-2025-27080
6.0 MEDIUM

Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to …

Mar 18, 2025
CVE-2025-25042
4.3 MEDIUM

A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an …

Mar 18, 2025
CVE-2025-25040
3.3 LOW

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and …

Mar 18, 2025
CVE-2025-24801
8.5 HIGH

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the …

Mar 18, 2025
CVE-2025-24799
7.5 HIGH

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is …

Mar 18, 2025
CVE-2025-21619
9.8 CRITICAL

GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability …

Mar 18, 2025
CVE-2025-2487
4.9 MEDIUM

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the …

Mar 18, 2025
CVE-2025-26138
6.5 MEDIUM

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users …

Mar 18, 2025
CVE-2025-26137
7.5 HIGH

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by …

Mar 18, 2025
CVE-2025-25595
9.8 CRITICAL

A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a brute force attack.

Mar 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.