CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0600
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting Product Explorer in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Mar 17, 2025
CVE-2025-0599
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Mar 17, 2025
CVE-2025-0598
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting Relations in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to …

Mar 17, 2025
CVE-2025-0596
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting Bookmark Editor in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Mar 17, 2025
CVE-2025-0595
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Mar 17, 2025
CVE-2024-9055
4.2 MEDIUM

The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract …

Mar 17, 2025
CVE-2024-54027
8.2 HIGH

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and …

Mar 17, 2025
CVE-2021-32584
5.3 MEDIUM

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to …

Mar 17, 2025
CVE-2021-26087
4.3 MEDIUM

An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface …

Mar 17, 2025
CVE-2021-22126
6.7 MEDIUM

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may …

Mar 17, 2025
CVE-2020-9295
4.7 MEDIUM

FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version …

Mar 17, 2025
CVE-2020-29010
5.0 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to …

Mar 17, 2025
CVE-2019-6697
5.3 MEDIUM

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP …

Mar 17, 2025
CVE-2019-17659
3.7 LOW

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as …

Mar 17, 2025
CVE-2019-15706
4.1 MEDIUM

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version …

Mar 17, 2025
CVE-2025-2401

Buffer overflow vulnerability in Immunity Debugger affecting version 1.85, its exploitation could allow a local attacker to execute arbitrary code, due to the lack of …

Mar 17, 2025
CVE-2025-2378
7.3 HIGH

A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been classified as critical. This affects an unknown part of the file …

Mar 17, 2025
CVE-2025-2377
3.5 LOW

A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Mar 17, 2025
CVE-2025-2376
7.3 HIGH

A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCookieContent of …

Mar 17, 2025
CVE-2025-2375
3.5 LOW

A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unknown function of the file …

Mar 17, 2025
CVE-2023-52321

Rejected reason: This CVE Record has been withdrawn by its CNA.

Mar 17, 2025
CVE-2023-52320

Rejected reason: This CVE Record has been withdrawn by its CNA.

Mar 17, 2025
CVE-2023-52319

Rejected reason: This CVE Record has been withdrawn by its CNA.

Mar 17, 2025
CVE-2023-52318

Rejected reason: This CVE Record has been withdrawn by its CNA.

Mar 17, 2025
CVE-2023-52317

Rejected reason: This CVE Record has been withdrawn by its CNA.

Mar 17, 2025
CVE-2023-52316

Rejected reason: This CVE Record has been withdrawn by its CNA.

Mar 17, 2025
CVE-2025-2374
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This issue affects some unknown processing of …

Mar 17, 2025
CVE-2025-2373
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This vulnerability affects unknown code of the file /check_availability.php. The …

Mar 17, 2025
CVE-2025-2202

Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users …

Mar 17, 2025
CVE-2025-2372
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This affects an unknown part of the file /password-recovery.php …

Mar 17, 2025
CVE-2025-2371
3.5 LOW

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown …

Mar 17, 2025
CVE-2025-2201

Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as …

Mar 17, 2025
CVE-2025-2200

SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by …

Mar 17, 2025
CVE-2025-2199

SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the …

Mar 17, 2025
CVE-2024-12992
9.8 CRITICAL

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 …

Mar 17, 2025
CVE-2024-12971
8.8 HIGH

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

Mar 17, 2025
CVE-2025-2370
8.8 HIGH

A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been declared as critical. Affected by this vulnerability is the function setWiFiExtenderConfig of …

Mar 17, 2025
CVE-2025-2369
8.8 HIGH

A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been classified as critical. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. …

Mar 17, 2025
CVE-2025-2368
6.3 MEDIUM

A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the …

Mar 17, 2025
CVE-2025-2367
6.3 MEDIUM

A vulnerability has been found in Oiwtech OIW-2431APGN-HP 2.5.3-B20131128 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formScript of the component …

Mar 17, 2025
CVE-2025-2366
2.4 LOW

A vulnerability, which was classified as problematic, was found in gougucms 4.08.18. This affects the function add of the file /admin/department/add of the component Add …

Mar 17, 2025
CVE-2025-2365
6.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the …

Mar 17, 2025
CVE-2025-1724
7.4 HIGH

Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive …

Mar 17, 2025
CVE-2023-52315

Rejected reason: This CVE Record has been withdrawn by its CNA.

Mar 17, 2025
CVE-2025-2396
8.8 HIGH

The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby …

Mar 17, 2025
CVE-2025-2395
9.8 CRITICAL

The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in …

Mar 17, 2025
CVE-2025-2364
3.5 LOW

A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the file blogserver/src/main/java/org/sang/service/ArticleService.java. …

Mar 17, 2025
CVE-2025-2363
6.3 MEDIUM

A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation …

Mar 17, 2025
CVE-2025-2362
7.3 HIGH

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Mar 17, 2025
CVE-2025-2361
4.3 MEDIUM

A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The …

Mar 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.