CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-26936
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework allows Code Injection.This issue affects Fresh Framework: from n/a through <= …

Mar 10, 2025
CVE-2025-26933
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order Without Payment wc-place-order-without-payment allows …

Mar 10, 2025
CVE-2025-26916
9.0 CRITICAL

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pixflow Massive Dynamic massive-dynamic.This issue affects Massive Dynamic: from …

Mar 10, 2025
CVE-2025-26910
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1.

Mar 10, 2025
CVE-2025-25620
5.4 MEDIUM

Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.

Mar 10, 2025
CVE-2025-25614
8.8 HIGH

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

Mar 10, 2025
CVE-2024-12604
6.5 MEDIUM

Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery …

Mar 10, 2025
CVE-2025-2153
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 …

Mar 10, 2025
CVE-2025-2152
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the …

Mar 10, 2025
CVE-2025-26865
3.5 LOW

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a …

Mar 10, 2025
CVE-2025-25616
4.3 MEDIUM

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.

Mar 10, 2025
CVE-2025-25615
2.7 LOW

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.

Mar 10, 2025
CVE-2025-1497
9.8 CRITICAL

A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute …

Mar 10, 2025
CVE-2024-57492
5.5 MEDIUM

An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton.

Mar 10, 2025
CVE-2025-2151
6.3 MEDIUM

A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of …

Mar 10, 2025
CVE-2025-2149
2.5 LOW

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized …

Mar 10, 2025
CVE-2025-2148
5.0 MEDIUM

A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple …

Mar 10, 2025
CVE-2025-1945
9.8 CRITICAL

picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping specific bits …

Mar 10, 2025
CVE-2025-1944
6.5 MEDIUM

picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. …

Mar 10, 2025
CVE-2025-2147
5.3 MEDIUM

A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is …

Mar 10, 2025
CVE-2025-24387
4.8 MEDIUM

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS …

Mar 10, 2025
CVE-2024-13919
8.0 HIGH

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode …

Mar 10, 2025
CVE-2024-13918
8.0 HIGH

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode …

Mar 10, 2025
CVE-2025-27257
6.1 MEDIUM

Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature …

Mar 10, 2025
CVE-2025-27256
8.3 HIGH

Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the …

Mar 10, 2025
CVE-2025-27255
8.0 HIGH

Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable …

Mar 10, 2025
CVE-2025-27254
8.0 HIGH

CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry …

Mar 10, 2025
CVE-2025-27253
6.1 MEDIUM

A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker …

Mar 10, 2025
CVE-2025-2150
5.4 MEDIUM

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which …

Mar 10, 2025
CVE-2024-11638
8.8 HIGH

The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated …

Mar 10, 2025
CVE-2025-1926
4.3 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Mar 10, 2025
CVE-2024-43107
7.2 HIGH

Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to be sent to the Plugin. This issue …

Mar 10, 2025
CVE-2024-41724
8.7 HIGH

Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of …

Mar 10, 2025
CVE-2025-2133
2.4 LOW

A vulnerability classified as problematic was found in ftcms 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/index.php/news/edit. The manipulation of …

Mar 10, 2025
CVE-2025-2132
4.7 MEDIUM

A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/index.php/web/ajax_all_lists of the component Search. The …

Mar 9, 2025
CVE-2025-2131
2.4 LOW

A vulnerability was found in dayrui XunRuiCMS up to 4.6.3. It has been rated as problematic. This issue affects some unknown processing of the component …

Mar 9, 2025
CVE-2025-2130
3.5 LOW

A vulnerability was found in OpenXE up to 1.12. It has been declared as problematic. This vulnerability affects unknown code of the component Ticket Bearbeiten …

Mar 9, 2025
CVE-2025-26205

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Mar 9, 2025
CVE-2025-26204

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Mar 9, 2025
CVE-2025-2129
5.6 MEDIUM

A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default …

Mar 9, 2025
CVE-2025-2127
4.3 MEDIUM

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the …

Mar 9, 2025
CVE-2025-2126
6.3 MEDIUM

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file …

Mar 9, 2025
CVE-2025-2125
4.3 MEDIUM

A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao/?companyId=1 of …

Mar 9, 2025
CVE-2025-2124
3.5 LOW

A vulnerability, which was classified as problematic, was found in Control iD RH iD 25.2.25.0. This affects an unknown part of the file /v2/customerdb/person.svc/change_password of …

Mar 9, 2025
CVE-2025-2123
3.5 LOW

A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is the function get_var of the …

Mar 9, 2025
CVE-2025-2122
3.1 LOW

A vulnerability classified as problematic was found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected by this vulnerability is an unknown functionality of …

Mar 9, 2025
CVE-2025-27636
5.6 MEDIUM

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from …

Mar 9, 2025
CVE-2025-2121
6.3 MEDIUM

A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the component …

Mar 9, 2025
CVE-2025-2120
2.1 LOW

A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as problematic. This issue affects some unknown processing …

Mar 9, 2025
CVE-2025-2119
2.0 LOW

A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been declared as problematic. This vulnerability affects unknown code of …

Mar 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.