CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2360
7.3 HIGH

A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the …

Mar 17, 2025
CVE-2025-2359
7.3 HIGH

A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS …

Mar 17, 2025
CVE-2025-2358
6.3 MEDIUM

A vulnerability was found in Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System 1.0. It has been rated as critical. This issue affects some …

Mar 17, 2025
CVE-2025-2357
6.3 MEDIUM

A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS Decoder. The …

Mar 17, 2025
CVE-2025-2356
3.7 LOW

A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the function deviceDelete of the component API …

Mar 17, 2025
CVE-2025-2355
3.3 LOW

A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic. Affected by this issue is some unknown functionality of the component …

Mar 17, 2025
CVE-2025-30089
5.4 MEDIUM

gurk (aka gurk-rs) through 0.6.3 mishandles ANSI escape sequences.

Mar 17, 2025
CVE-2025-2354
4.3 MEDIUM

A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 17, 2025
CVE-2025-2353
7.3 HIGH

A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2. Affected is an unknown function of the file …

Mar 17, 2025
CVE-2025-2352
2.4 LOW

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/indexConfigs/save of …

Mar 16, 2025
CVE-2025-2351
7.3 HIGH

A vulnerability classified as critical was found in DayCloud StudentManage 1.0. This vulnerability affects unknown code of the file /admin/adminScoreUrl of the component Login Endpoint. …

Mar 16, 2025
CVE-2025-2350
6.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown …

Mar 16, 2025
CVE-2025-2349
3.1 LOW

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as problematic. Affected by this vulnerability is an unknown …

Mar 16, 2025
CVE-2025-2348
4.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the …

Mar 16, 2025
CVE-2025-2347
6.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component …

Mar 16, 2025
CVE-2025-2346
5.6 MEDIUM

A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown …

Mar 16, 2025
CVE-2025-2345
9.8 CRITICAL

A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an …

Mar 16, 2025
CVE-2025-2344
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this …

Mar 16, 2025
CVE-2025-2343
7.5 HIGH

A vulnerability classified as critical was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this vulnerability is an …

Mar 16, 2025
CVE-2025-2342
5.3 MEDIUM

A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the …

Mar 16, 2025
CVE-2025-2341
3.1 LOW

A vulnerability was found in IROAD Dash Cam X5 up to 20250203. It has been rated as problematic. This issue affects some unknown processing of …

Mar 16, 2025
CVE-2025-2340
2.4 LOW

A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the function saveOptions of the file /options/save …

Mar 16, 2025
CVE-2025-2339
5.3 MEDIUM

A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs. The …

Mar 16, 2025
CVE-2025-2338
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulation leads …

Mar 16, 2025
CVE-2025-2337
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in tbeu matio 1.5.28. This issue affects the function Mat_VarPrint of the file src/mat.c. The …

Mar 16, 2025
CVE-2025-1624
3.5 LOW

The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1623
3.5 LOW

The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1622
3.5 LOW

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1621
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1620
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1619
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2024-13602
4.8 MEDIUM

The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 16, 2025
CVE-2024-13126
4.6 MEDIUM

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

Mar 16, 2025
CVE-2025-24856
4.2 MEDIUM

An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading …

Mar 16, 2025
CVE-2024-58103
5.8 MEDIUM

Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.

Mar 16, 2025
CVE-2025-30077
6.2 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits.

Mar 16, 2025
CVE-2025-30076
7.7 HIGH

Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.

Mar 16, 2025
CVE-2025-30074
7.8 HIGH

Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation routine.

Mar 16, 2025
CVE-2025-2335
3.5 LOW

A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknown code of the file /api/school/registerSchool of the component …

Mar 16, 2025
CVE-2022-49737
7.7 HIGH

In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by …

Mar 16, 2025
CVE-2025-2334
5.4 MEDIUM

A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat …

Mar 15, 2025
CVE-2025-0524

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 15, 2025
CVE-2025-27281
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cookforweb All In Menu all-in-menu allows Blind SQL Injection.This issue affects …

Mar 15, 2025
CVE-2025-26978
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster: from n/a through …

Mar 15, 2025
CVE-2025-26976
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= …

Mar 15, 2025
CVE-2025-26972
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.

Mar 15, 2025
CVE-2025-26969
8.3 HIGH

Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.

Mar 15, 2025
CVE-2025-26961
8.6 HIGH

Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Fresh Framework: from n/a through <= 1.70.0.

Mar 15, 2025
CVE-2025-26940
6.3 MEDIUM

Path Traversal vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.

Mar 15, 2025
CVE-2025-26924
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Ohio Extra: from n/a through <= …

Mar 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.