CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1984
5.2 MEDIUM

Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low-privileged user to gain SYSTEM-level access.

Mar 12, 2025
CVE-2025-1960
9.8 CRITICAL

CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized commands when a system’s default password …

Mar 12, 2025
CVE-2025-1683
7.8 HIGH

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged …

Mar 12, 2025
CVE-2025-0884

Unquoted Search Path or Element vulnerability in OpenText™ Service Manager. The vulnerability could allow a user to gain SYSTEM privileges through Privilege Escalation. This issue …

Mar 12, 2025
CVE-2025-0883

Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager. The vulnerability could reveal sensitive information retained by the browser. …

Mar 12, 2025
CVE-2025-0813
6.8 MEDIUM

CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights has physical access to the EPAS-UI computer …

Mar 12, 2025
CVE-2025-2240
7.5 HIGH

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. …

Mar 12, 2025
CVE-2025-29891
4.8 MEDIUM

Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended …

Mar 12, 2025
CVE-2025-27915
5.4 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client …

Mar 12, 2025
CVE-2025-27914
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing …

Mar 12, 2025
CVE-2025-22954
10.0 CRITICAL

GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.

Mar 12, 2025
CVE-2024-27763
5.3 MEDIUM

XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST …

Mar 12, 2025
CVE-2025-27794
6.8 MEDIUM

Flarum is open-source forum software. A session hijacking vulnerability exists in versions prior to 1.8.10 when an attacker-controlled authoritative subdomain under a parent domain (e.g., …

Mar 12, 2025
CVE-2025-27788
7.5 HIGH

JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of …

Mar 12, 2025
CVE-2025-25709
7.5 HIGH

An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the addUser and updateUser endpoints

Mar 12, 2025
CVE-2025-21590
4.4 MEDIUM KEV

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity …

Mar 12, 2025
CVE-2024-52362
4.3 MEDIUM

IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, …

Mar 12, 2025
CVE-2025-29904
5.3 MEDIUM

In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible

Mar 12, 2025
CVE-2025-29903
5.2 MEDIUM

In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible

Mar 12, 2025
CVE-2024-10838
9.1 CRITICAL

An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers …

Mar 12, 2025
CVE-2025-1527
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a …

Mar 12, 2025
CVE-2024-13872
7.5 HIGH

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules …

Mar 12, 2025
CVE-2024-13871
8.8 HIGH

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to …

Mar 12, 2025
CVE-2024-13870
5.7 MEDIUM

An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware …

Mar 12, 2025
CVE-2025-2239
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.

Mar 12, 2025
CVE-2025-21866
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC Erhard reported the …

Mar 12, 2025
CVE-2025-21865
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl(). Brad Spengler reported the list_del() corruption splat in …

Mar 12, 2025
CVE-2025-21864
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: drop secpath at the same time as we currently drop dst Xiumei reported hitting …

Mar 12, 2025
CVE-2025-21863
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: prevent opcode speculation sqe->opcode is used for different tables, make sure we santitise it …

Mar 12, 2025
CVE-2025-21862
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix incorrect initialization order Syzkaller reports the following bug: BUG: spinlock bad magic on …

Mar 12, 2025
CVE-2025-21861
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() If migration succeeded, we …

Mar 12, 2025
CVE-2025-21860
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: mm/zswap: fix inconsistency when zswap_store_page() fails Commit b7c0ccdfbafd ("mm: zswap: support large folios in zswap_store()") …

Mar 12, 2025
CVE-2025-21859
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: f_midi: f_midi_complete to call queue_work When using USB MIDI, a lock is attempted …

Mar 12, 2025
CVE-2025-21858
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: geneve: Fix use-after-free in geneve_find_dev(). syzkaller reported a use-after-free in geneve_find_dev() [0] without repro. geneve_configure() …

Mar 12, 2025
CVE-2025-21857
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix error handling causing NULL dereference tcf_exts_miss_cookie_base_alloc() calls xa_alloc_cyclic() which can return 1 …

Mar 12, 2025
CVE-2025-21856
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/ism: add release function for struct device According to device_release() in /drivers/base/core.c, a device without …

Mar 12, 2025
CVE-2025-21855
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Don't reference skb after sending to VIOS Previously, after successfully flushing the xmit buffer …

Mar 12, 2025
CVE-2025-21854
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sockmap, vsock: For connectible sockets allow only connected sockmap expects all vsocks to have a …

Mar 12, 2025
CVE-2025-21853
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: avoid holding freeze_mutex during mmap operation We use map->freeze_mutex to prevent races between map_freeze() …

Mar 12, 2025
CVE-2025-21852
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Add rx_skb of kfree_skb to raw_tp_null_args[]. Yan Zhai reported a BPF prog could trigger …

Mar 12, 2025
CVE-2025-21851
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix softlockup in arena_map_free on 64k page kernel On an aarch64 kernel with CONFIG_PAGE_SIZE_64KB=y, …

Mar 12, 2025
CVE-2025-21850
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: Fix crash when a namespace is disabled The namespace percpu counter protects pending I/O, …

Mar 12, 2025
CVE-2025-21849
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Use spin_lock_irqsave() in interruptible context spin_lock/unlock() functions used in interrupt contexts could result in …

Mar 12, 2025
CVE-2025-21848
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() Add check for the return value of nfp_app_ctrl_msg_alloc() in …

Mar 12, 2025
CVE-2025-21847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data() The nullity of sps->cstream should be …

Mar 12, 2025
CVE-2025-21846
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: acct: perform last write from workqueue In [1] it was reported that the acct(2) system …

Mar 12, 2025
CVE-2025-21845
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: sst: Fix SST write failure 'commit 18bcb4aa54ea ("mtd: spi-nor: sst: Factor out common …

Mar 12, 2025
CVE-2025-21844
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of …

Mar 12, 2025
CVE-2024-58089
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_delalloc_range() failed [BUG] When running btrfs with block size …

Mar 12, 2025
CVE-2024-58088
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock when freeing cgroup storage The following commit bc235cdb423a ("bpf: Prevent deadlock from …

Mar 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.