CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1828
8.8 HIGH

Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptographic functions. If the Provider is not specified and …

Mar 11, 2025
CVE-2025-27926
4.3 MEDIUM

In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.

Mar 10, 2025
CVE-2025-27925
8.5 HIGH

Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

Mar 10, 2025
CVE-2025-27924
5.4 MEDIUM

Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.

Mar 10, 2025
CVE-2025-27610
7.5 HIGH

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` …

Mar 10, 2025
CVE-2025-27910
8.0 HIGH

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a …

Mar 10, 2025
CVE-2025-25908
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Mar 10, 2025
CVE-2025-25907
8.8 HIGH

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a …

Mar 10, 2025
CVE-2025-2137
8.8 HIGH

Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a …

Mar 10, 2025
CVE-2025-2136
8.8 HIGH

Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 10, 2025
CVE-2025-2135
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Mar 10, 2025
CVE-2025-1920
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Mar 10, 2025
CVE-2025-0660
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin …

Mar 10, 2025
CVE-2024-56192
7.8 HIGH

In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Mar 10, 2025
CVE-2024-56191
8.4 HIGH

In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional …

Mar 10, 2025
CVE-2025-27913
7.5 HIGH

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with …

Mar 10, 2025
CVE-2022-48610
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2. An app …

Mar 10, 2025
CVE-2022-43454
7.8 HIGH

A double free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, …

Mar 10, 2025
CVE-2025-27616
8.5 HIGH

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webhook …

Mar 10, 2025
CVE-2025-27615
8.2 HIGH

umatiGateway is software for connecting OPC Unified Architecture servers with an MQTT broker utilizing JSON messages. The user interface may possibly be publicly accessible with …

Mar 10, 2025
CVE-2025-27136

LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's bucket creation endpoint is vulnerable to …

Mar 10, 2025
CVE-2025-26696
7.0 HIGH

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being …

Mar 10, 2025
CVE-2025-26695
5.3 MEDIUM

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of …

Mar 10, 2025
CVE-2025-25306
9.3 CRITICAL

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields …

Mar 10, 2025
CVE-2025-22603
8.1 HIGH

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Versions prior to autogpt-platform-beta-v0.4.2 contains …

Mar 10, 2025
CVE-2024-56188
5.1 MEDIUM

there is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no …

Mar 10, 2025
CVE-2024-56187
6.6 MEDIUM

In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the code. This could lead to …

Mar 10, 2025
CVE-2024-56186
5.1 MEDIUM

In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Mar 10, 2025
CVE-2024-56185
5.1 MEDIUM

In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband …

Mar 10, 2025
CVE-2024-56184
5.1 MEDIUM

In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local …

Mar 10, 2025
CVE-2024-54560
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. …

Mar 10, 2025
CVE-2024-54558
2.8 LOW

A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app …

Mar 10, 2025
CVE-2024-54546
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected system …

Mar 10, 2025
CVE-2024-54473
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to access …

Mar 10, 2025
CVE-2024-54469
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura …

Mar 10, 2025
CVE-2024-54467
6.5 MEDIUM

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, …

Mar 10, 2025
CVE-2024-54463
5.5 MEDIUM

This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without …

Mar 10, 2025
CVE-2024-44227
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be …

Mar 10, 2025
CVE-2024-44192
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS …

Mar 10, 2025
CVE-2024-44179
2.4 LOW

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and …

Mar 10, 2025
CVE-2025-1296
6.5 MEDIUM

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, …

Mar 10, 2025
CVE-2024-55199
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file …

Mar 10, 2025
CVE-2024-53307
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /mw/ endpoint of Evisions MAPS v6.10.2.267 allows attackers to execute arbitrary code in the context of a …

Mar 10, 2025
CVE-2024-52812
5.4 MEDIUM

LF Edge eKuiper is an internet-of-things data analytics and stream processing engine. Prior to version 2.0.8, auser with rights to modify the service (e.g. kuiperUser …

Mar 10, 2025
CVE-2025-24813
9.8 CRITICAL KEV

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet …

Mar 10, 2025
CVE-2025-25977
9.8 CRITICAL

An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.

Mar 10, 2025
CVE-2025-25940
9.8 CRITICAL

VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.

Mar 10, 2025
CVE-2025-25382
7.5 HIGH

An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

Mar 10, 2025
CVE-2024-52905
2.7 LOW

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.

Mar 10, 2025
CVE-2024-47109
5.3 MEDIUM

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further …

Mar 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.