CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-56347
9.6 CRITICAL

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.

Mar 18, 2025
CVE-2024-56346
10.0 CRITICAL

IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.

Mar 18, 2025
CVE-2025-27688
7.8 HIGH

Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation …

Mar 18, 2025
CVE-2025-25589
8.1 HIGH

An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted …

Mar 18, 2025
CVE-2025-25586
4.2 MEDIUM

yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.

Mar 18, 2025
CVE-2025-25582
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

Mar 18, 2025
CVE-2024-57170
6.5 MEDIUM

SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences …

Mar 18, 2025
CVE-2024-57169
9.8 CRITICAL

A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote …

Mar 18, 2025
CVE-2025-30132
9.1 CRITICAL

An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, creating a security risk. During …

Mar 18, 2025
CVE-2025-30123
9.8 CRITICAL

An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to …

Mar 18, 2025
CVE-2025-30122
9.8 CRITICAL

An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for …

Mar 18, 2025
CVE-2025-30117
7.3 HIGH

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can …

Mar 18, 2025
CVE-2025-30116
7.5 HIGH

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. …

Mar 18, 2025
CVE-2025-30115
9.8 CRITICAL

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and …

Mar 18, 2025
CVE-2025-30114
9.1 CRITICAL

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on …

Mar 18, 2025
CVE-2025-30113
9.8 CRITICAL

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The …

Mar 18, 2025
CVE-2025-30111
7.5 HIGH

On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained …

Mar 18, 2025
CVE-2025-30110
6.5 MEDIUM

On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism relies solely on MAC address verification, …

Mar 18, 2025
CVE-2025-30109
6.5 MEDIUM

In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded …

Mar 18, 2025
CVE-2025-30107
7.5 HIGH

On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. A vulnerability in the …

Mar 18, 2025
CVE-2025-2491
2.4 LOW

A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit …

Mar 18, 2025
CVE-2025-25590
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.

Mar 18, 2025
CVE-2025-25585
7.3 HIGH

Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.

Mar 18, 2025
CVE-2025-25580
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.

Mar 18, 2025
CVE-2024-49822
4.1 MEDIUM

IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Mar 18, 2025
CVE-2024-44314
6.5 MEDIUM

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the …

Mar 18, 2025
CVE-2024-44313
8.1 HIGH

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to …

Mar 18, 2025
CVE-2025-30106
8.8 HIGH

On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi range …

Mar 18, 2025
CVE-2025-2490
2.4 LOW

A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file …

Mar 18, 2025
CVE-2025-2450
8.8 HIGH

NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Mar 18, 2025
CVE-2025-2449
8.8 HIGH

NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of …

Mar 18, 2025
CVE-2025-25500
7.5 HIGH

An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows …

Mar 18, 2025
CVE-2024-8997
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection.This issue affects EVC04 Configuration …

Mar 18, 2025
CVE-2024-21760
8.4 HIGH

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 …

Mar 18, 2025
CVE-2023-47539
9.8 CRITICAL

An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin …

Mar 18, 2025
CVE-2025-2495
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to upload XML files to the server with JavaScript …

Mar 18, 2025
CVE-2025-2494
9.8 CRITICAL

Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ …

Mar 18, 2025
CVE-2025-2493
7.5 HIGH

Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘/softdial/scheduler/load.php’ endpoint to …

Mar 18, 2025
CVE-2025-2489

Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application …

Mar 18, 2025
CVE-2025-1468
7.5 HIGH

An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.

Mar 18, 2025
CVE-2025-0694
6.6 MEDIUM

Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

Mar 18, 2025
CVE-2024-41975
5.3 MEDIUM

An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the …

Mar 18, 2025
CVE-2024-23943
9.1 CRITICAL

An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. …

Mar 18, 2025
CVE-2024-23942
7.1 HIGH

A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or …

Mar 18, 2025
CVE-2025-25220
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vulnerability …

Mar 18, 2025
CVE-2025-24306
7.2 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.0_1101. If this vulnerability …

Mar 18, 2025
CVE-2025-0755
8.4 HIGH

The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final …

Mar 18, 2025
CVE-2025-2262
7.3 HIGH

The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in …

Mar 18, 2025
CVE-2025-2473
7.3 HIGH

A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 18, 2025
CVE-2025-2472
7.3 HIGH

A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.