CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25426
7.2 HIGH

yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.

Mar 4, 2025
CVE-2025-1958
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The …

Mar 4, 2025
CVE-2025-1957
3.5 LOW

A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file /BBfile/Blood/o+.php. The manipulation of …

Mar 4, 2025
CVE-2025-1956
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component …

Mar 4, 2025
CVE-2025-26318
5.8 MEDIUM

hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.

Mar 4, 2025
CVE-2025-26136
9.8 CRITICAL

A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.

Mar 4, 2025
CVE-2025-1955
3.5 LOW

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some …

Mar 4, 2025
CVE-2025-1954
7.3 HIGH

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Mar 4, 2025
CVE-2024-9135
5.3 MEDIUM

On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result …

Mar 4, 2025
CVE-2024-8000
5.3 MEDIUM

On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in …

Mar 4, 2025
CVE-2021-41719
7.5 HIGH

Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive …

Mar 4, 2025
CVE-2020-23438
7.8 HIGH

Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.

Mar 4, 2025
CVE-2025-1953
2.6 LOW

A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go …

Mar 4, 2025
CVE-2025-1260
9.1 CRITICAL

On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result …

Mar 4, 2025
CVE-2025-1259
7.7 HIGH

On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result …

Mar 4, 2025
CVE-2025-1080
7.8 HIGH

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In …

Mar 4, 2025
CVE-2025-26202
4.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An …

Mar 4, 2025
CVE-2025-1969
4.3 MEDIUM

Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof …

Mar 4, 2025
CVE-2025-1952
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/password-recovery.php. …

Mar 4, 2025
CVE-2025-1949
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the …

Mar 4, 2025
CVE-2025-1947
6.3 MEDIUM

A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The …

Mar 4, 2025
CVE-2025-1946
6.3 MEDIUM

A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function exportPDF …

Mar 4, 2025
CVE-2020-3122
5.3 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain …

Mar 4, 2025
CVE-2019-1815
5.3 MEDIUM

A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals …

Mar 4, 2025
CVE-2024-41147
7.7 HIGH

An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker …

Mar 4, 2025
CVE-2024-10930
7.8 HIGH

An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

Mar 4, 2025
CVE-2025-27507
9.0 CRITICAL

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow …

Mar 4, 2025
CVE-2025-27402
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An …

Mar 4, 2025
CVE-2025-27401
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited …

Mar 4, 2025
CVE-2025-27156
4.1 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the …

Mar 4, 2025
CVE-2025-27155
6.1 MEDIUM

Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone …

Mar 4, 2025
CVE-2025-27150
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from …

Mar 4, 2025
CVE-2025-26182
6.5 MEDIUM

An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file

Mar 4, 2025
CVE-2025-26091
4.6 MEDIUM

A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web …

Mar 4, 2025
CVE-2025-27111
7.5 HIGH

Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by …

Mar 4, 2025
CVE-2025-26320
6.5 MEDIUM

t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.

Mar 4, 2025
CVE-2025-23368
8.1 HIGH

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time …

Mar 4, 2025
CVE-2025-1425

A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad …

Mar 4, 2025
CVE-2025-1424

A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the device. This …

Mar 4, 2025
CVE-2024-50707
10.0 CRITICAL

Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP GET …

Mar 4, 2025
CVE-2024-50704
10.0 CRITICAL

Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request.

Mar 4, 2025
CVE-2024-11957

Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to …

Mar 4, 2025
CVE-2024-9149
8.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection.This issue affects E-Commerce …

Mar 4, 2025
CVE-2024-50706
9.8 CRITICAL

Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.

Mar 4, 2025
CVE-2024-50705
7.1 HIGH

Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.

Mar 4, 2025
CVE-2025-27426
5.4 MEDIUM

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for …

Mar 4, 2025
CVE-2025-27425
4.3 MEDIUM

Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation …

Mar 4, 2025
CVE-2025-27424
4.3 MEDIUM

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox …

Mar 4, 2025
CVE-2025-1943
8.2 HIGH

Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Mar 4, 2025
CVE-2025-1942
9.8 CRITICAL

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed …

Mar 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.