CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-58102
5.7 MEDIUM

An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested …

Mar 11, 2025
CVE-2025-2190
8.1 HIGH

The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks.

Mar 11, 2025
CVE-2025-2175
4.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the function _vbi_strndup_iconv. The manipulation …

Mar 11, 2025
CVE-2025-2174
5.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been declared as problematic. Affected by this vulnerability is the function vbi_strndup_iconv_ucs2 of the …

Mar 11, 2025
CVE-2025-2173
5.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The …

Mar 11, 2025
CVE-2025-26706
5.4 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

Mar 11, 2025
CVE-2025-26705
5.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2025-26704
6.4 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2025-26703
4.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

Mar 11, 2025
CVE-2025-26702
4.9 MEDIUM

Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

Mar 11, 2025
CVE-2024-13228
4.3 MEDIUM

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the …

Mar 11, 2025
CVE-2025-0629
4.8 MEDIUM

The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such …

Mar 11, 2025
CVE-2024-13864
7.1 HIGH

The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 11, 2025
CVE-2024-13862
7.1 HIGH

The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading …

Mar 11, 2025
CVE-2024-13853
6.1 MEDIUM

The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 11, 2025
CVE-2024-13836
7.1 HIGH

The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Mar 11, 2025
CVE-2024-13615
3.5 LOW

The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin through 1.3.6 does not sanitise and …

Mar 11, 2025
CVE-2024-13580
4.3 MEDIUM

The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Mar 11, 2025
CVE-2024-13574
7.1 HIGH

The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Mar 11, 2025
CVE-2024-13413
6.1 MEDIUM

The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all versions up to, and including, 1.0.24 due to …

Mar 11, 2025
CVE-2025-2169
7.3 HIGH

The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.0.4. …

Mar 11, 2025
CVE-2025-26707
5.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2025-1661
9.8 CRITICAL

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 …

Mar 11, 2025
CVE-2024-13436
6.1 MEDIUM

The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing …

Mar 11, 2025
CVE-2024-12010
7.2 HIGH

A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator …

Mar 11, 2025
CVE-2024-12009
7.2 HIGH

A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator …

Mar 11, 2025
CVE-2024-11253
7.2 HIGH

A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier could allow an …

Mar 11, 2025
CVE-2025-27436
4.3 MEDIUM

The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact …

Mar 11, 2025
CVE-2025-27434
8.8 HIGH

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged …

Mar 11, 2025
CVE-2025-27433
4.3 MEDIUM

The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank …

Mar 11, 2025
CVE-2025-27432
2.4 LOW

The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certain privileges to gain unauthorized access to each transaction. …

Mar 11, 2025
CVE-2025-27431
5.4 MEDIUM

User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload …

Mar 11, 2025
CVE-2025-27430
3.5 LOW

Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This …

Mar 11, 2025
CVE-2025-26661
8.8 HIGH

Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation …

Mar 11, 2025
CVE-2025-26660
4.3 MEDIUM

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This …

Mar 11, 2025
CVE-2025-26659
6.1 MEDIUM

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to …

Mar 11, 2025
CVE-2025-26658
6.8 MEDIUM

The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. …

Mar 11, 2025
CVE-2025-26656
4.3 MEDIUM

OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has …

Mar 11, 2025
CVE-2025-26655
3.1 LOW

SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially …

Mar 11, 2025
CVE-2025-25245
5.4 MEDIUM

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this …

Mar 11, 2025
CVE-2025-25244
5.7 MEDIUM

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the …

Mar 11, 2025
CVE-2025-25242
6.1 MEDIUM

SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no …

Mar 11, 2025
CVE-2025-23194
5.3 MEDIUM

SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to …

Mar 11, 2025
CVE-2025-23188
4.3 MEDIUM

An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond …

Mar 11, 2025
CVE-2025-23185
4.1 MEDIUM

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user …

Mar 11, 2025
CVE-2025-0071
4.9 MEDIUM

SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes …

Mar 11, 2025
CVE-2025-0062
4.7 MEDIUM

SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence reports. This code is then executed in the victim's browser …

Mar 11, 2025
CVE-2024-49823
6.5 MEDIUM

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using …

Mar 11, 2025
CVE-2024-41760
3.7 LOW

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations.

Mar 11, 2025
CVE-2024-22340
6.5 MEDIUM

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a …

Mar 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.