CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1979
6.4 MEDIUM

Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in …

Mar 6, 2025
CVE-2025-24864
7.8 HIGH

Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative …

Mar 6, 2025
CVE-2025-22447
7.8 HIGH

Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative …

Mar 6, 2025
CVE-2025-27625
4.3 MEDIUM

In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by …

Mar 5, 2025
CVE-2025-27624
5.4 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of …

Mar 5, 2025
CVE-2025-27623
4.3 MEDIUM

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, …

Mar 5, 2025
CVE-2025-27622
4.3 MEDIUM

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, …

Mar 5, 2025
CVE-2025-27508
7.5 HIGH

Emissary is a P2P based data-driven workflow engine. The ChecksumCalculator class within allows for hashing and checksum generation, but it includes or defaults to algorithms …

Mar 5, 2025
CVE-2025-27516
8.8 HIGH

Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker …

Mar 5, 2025
CVE-2025-25634
6.5 MEDIUM

A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to …

Mar 5, 2025
CVE-2025-25632
9.8 CRITICAL

Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.

Mar 5, 2025
CVE-2025-25362
9.8 CRITICAL

A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.

Mar 5, 2025
CVE-2024-57174
8.1 HIGH

A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the default DNS suffix. This allows attackers to register the unclaimed …

Mar 5, 2025
CVE-2025-27517

Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lead to remote code execution within Volt components. This vulnerability …

Mar 5, 2025
CVE-2024-51144
8.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0.

Mar 5, 2025
CVE-2025-2003
7.1 HIGH

Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.

Mar 5, 2025
CVE-2025-27515
9.8 CRITICAL

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially …

Mar 5, 2025
CVE-2025-27513
7.5 HIGH

OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate …

Mar 5, 2025
CVE-2024-48246
5.4 MEDIUM

Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.

Mar 5, 2025
CVE-2024-31525
7.2 HIGH

Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete …

Mar 5, 2025
CVE-2024-53458
7.5 HIGH

Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.

Mar 5, 2025
CVE-2025-20208
4.6 MEDIUM

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) …

Mar 5, 2025
CVE-2025-20206
7.1 HIGH

A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking …

Mar 5, 2025
CVE-2024-11035
2.5 LOW

Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a type of issue whereby sensitive information …

Mar 5, 2025
CVE-2025-27497

OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability that causes the server to become unresponsive to all …

Mar 5, 2025
CVE-2025-27412
6.1 MEDIUM

REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected cross-site scripting (XSS) on the page of …

Mar 5, 2025
CVE-2025-27411
5.4 MEDIUM

REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5.18.3.

Mar 5, 2025
CVE-2025-24521
4.9 MEDIUM

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues …

Mar 5, 2025
CVE-2025-24494
7.2 HIGH

Path traversal may allow remote code execution using privileged account (requires device admin account, cannot be performed by a regular user). In combination with the …

Mar 5, 2025
CVE-2025-23416
4.9 MEDIUM

Path traversal may lead to arbitrary file deletion. The score without least privilege principle violation is as calculated below. In combination with other issues it …

Mar 5, 2025
CVE-2025-22212
2.7 LOW

A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in …

Mar 5, 2025
CVE-2025-21095
4.9 MEDIUM

Path traversal may lead to arbitrary file download. The score without least privilege principle violation is as calculated below. In combination with other issues it …

Mar 5, 2025
CVE-2023-38693
9.8 CRITICAL

Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is …

Mar 5, 2025
CVE-2025-1714

Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker to enumerate valid user emails and …

Mar 5, 2025
CVE-2024-12799

Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user …

Mar 5, 2025
CVE-2024-13147
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection.This issue affects B2B …

Mar 5, 2025
CVE-2024-12097
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informatics E-Travel allows SQL Injection.This issue affects E-Travel: before 15.12.2024.

Mar 5, 2025
CVE-2024-11216
7.6 HIGH

Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking.This issue …

Mar 5, 2025
CVE-2025-1702
7.5 HIGH

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via …

Mar 5, 2025
CVE-2025-1463
4.3 MEDIUM

The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. This is due to improper …

Mar 5, 2025
CVE-2024-13471
7.5 HIGH

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in …

Mar 5, 2025
CVE-2024-13423
5.3 MEDIUM

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions …

Mar 5, 2025
CVE-2024-12650
5.4 MEDIUM

An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a …

Mar 5, 2025
CVE-2024-12281
9.8 CRITICAL

The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing …

Mar 5, 2025
CVE-2024-11951
9.8 CRITICAL

The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the …

Mar 5, 2025
CVE-2024-11153
5.3 MEDIUM

The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure …

Mar 5, 2025
CVE-2025-25015
9.9 CRITICAL

Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and …

Mar 5, 2025
CVE-2025-1515
9.8 CRITICAL

The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to …

Mar 5, 2025
CVE-2025-0956
8.1 HIGH

The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.4.0 via deserialization of …

Mar 5, 2025
CVE-2025-0954
6.5 MEDIUM

The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the json_import() and json_export() functions in …

Mar 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.