CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54445

Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all …

Mar 14, 2025
CVE-2024-29409
5.5 MEDIUM

File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.

Mar 14, 2025
CVE-2024-12245

Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all …

Mar 14, 2025
CVE-2024-12020
6.1 MEDIUM

There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a …

Mar 14, 2025
CVE-2024-12019

The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on …

Mar 14, 2025
CVE-2025-29774

xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.0.1, …

Mar 14, 2025
CVE-2025-29387
7.1 HIGH

In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

Mar 14, 2025
CVE-2025-29386
9.8 CRITICAL

In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

Mar 14, 2025
CVE-2025-29385
9.8 CRITICAL

In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

Mar 14, 2025
CVE-2025-29384
9.8 CRITICAL

In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

Mar 14, 2025
CVE-2025-27606
5.1 MEDIUM

Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user …

Mar 14, 2025
CVE-2025-26216

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Mar 14, 2025
CVE-2025-26215

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Mar 14, 2025
CVE-2025-1888
4.6 MEDIUM

The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within …

Mar 14, 2025
CVE-2024-55594
5.6 MEDIUM

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows …

Mar 14, 2025
CVE-2025-25873
5.5 MEDIUM

Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function

Mar 14, 2025
CVE-2025-25872
5.5 MEDIUM

An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

Mar 14, 2025
CVE-2025-25871
8.0 HIGH

An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

Mar 14, 2025
CVE-2024-40585
6.5 MEDIUM

An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and …

Mar 14, 2025
CVE-2023-48785
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on …

Mar 14, 2025
CVE-2023-45588
8.2 HIGH

An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local …

Mar 14, 2025
CVE-2023-33300
5.3 MEDIUM

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, …

Mar 14, 2025
CVE-2022-29059
2.7 LOW

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 …

Mar 14, 2025
CVE-2024-47573
6.5 MEDIUM

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 …

Mar 14, 2025
CVE-2024-46662
8.8 HIGH

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 …

Mar 14, 2025
CVE-2024-45643
5.9 MEDIUM

IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.

Mar 14, 2025
CVE-2024-45638
4.1 MEDIUM

IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.

Mar 14, 2025
CVE-2024-40590
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to …

Mar 14, 2025
CVE-2023-52927
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove …

Mar 14, 2025
CVE-2025-2268
7.5 HIGH

The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted request message is sent via …

Mar 14, 2025
CVE-2025-29776

Azle is a WebAssembly runtime for TypeScript and JavaScript on ICP. Calling `setTimer` in Azle versions `0.27.0`, `0.28.0`, and `0.29.0` causes an immediate infinite loop …

Mar 14, 2025
CVE-2025-29032
5.9 MEDIUM

Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.

Mar 14, 2025
CVE-2025-29031
9.8 CRITICAL

Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.

Mar 14, 2025
CVE-2025-29030
9.8 CRITICAL

Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.

Mar 14, 2025
CVE-2025-29029
9.8 CRITICAL

Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.

Mar 14, 2025
CVE-2025-2304

A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the 'updated_ajax' method of the UsersController …

Mar 14, 2025
CVE-2025-2000
9.8 CRITICAL

A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process …

Mar 14, 2025
CVE-2025-27595
9.8 CRITICAL

The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculated by an attacker. This impacts …

Mar 14, 2025
CVE-2025-27594
7.5 HIGH

The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby …

Mar 14, 2025
CVE-2025-27593
9.3 CRITICAL

The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target …

Mar 14, 2025
CVE-2025-26626
6.5 MEDIUM

The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software package. Versions prior to 1.5.0 …

Mar 14, 2025
CVE-2025-2232
9.8 CRITICAL

The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authentication bypass in all versions up …

Mar 14, 2025
CVE-2024-13773
7.3 HIGH

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Mar 14, 2025
CVE-2024-13772
5.6 MEDIUM

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, …

Mar 14, 2025
CVE-2024-13771
9.8 CRITICAL

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, …

Mar 14, 2025
CVE-2024-12810
8.8 HIGH

The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing …

Mar 14, 2025
CVE-2024-26006
7.5 HIGH

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below …

Mar 14, 2025
CVE-2025-1507
5.3 MEDIUM

The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() …

Mar 14, 2025
CVE-2024-8176
7.5 HIGH

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML …

Mar 14, 2025
CVE-2025-1526
6.4 MEDIUM

The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Display Widget (countdown feature) in all versions up …

Mar 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.