CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1941
9.1 CRITICAL

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was …

Mar 4, 2025
CVE-2025-1940
7.1 HIGH

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching …

Mar 4, 2025
CVE-2025-1939
3.9 LOW

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a …

Mar 4, 2025
CVE-2025-1938
6.5 MEDIUM

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and …

Mar 4, 2025
CVE-2025-1937
7.5 HIGH

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of …

Mar 4, 2025
CVE-2025-1936
7.3 HIGH

jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the …

Mar 4, 2025
CVE-2025-1935
4.3 MEDIUM

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in …

Mar 4, 2025
CVE-2025-1934
6.5 MEDIUM

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting …

Mar 4, 2025
CVE-2025-1933
7.6 HIGH

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them …

Mar 4, 2025
CVE-2025-1932
8.1 HIGH

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox …

Mar 4, 2025
CVE-2025-1931
7.5 HIGH

It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was …

Mar 4, 2025
CVE-2025-1930
8.8 HIGH

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led …

Mar 4, 2025
CVE-2025-1925
5.3 MEDIUM

A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of …

Mar 4, 2025
CVE-2025-22226
7.1 HIGH KEV

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a …

Mar 4, 2025
CVE-2025-22225
8.2 HIGH KEV

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an …

Mar 4, 2025
CVE-2025-22224
9.3 CRITICAL KEV

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a …

Mar 4, 2025
CVE-2025-0958
5.4 MEDIUM

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9. This makes …

Mar 4, 2025
CVE-2025-0370
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, …

Mar 4, 2025
CVE-2025-26849
4.3 MEDIUM

There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain …

Mar 4, 2025
CVE-2025-0512
6.4 MEDIUM

The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and …

Mar 4, 2025
CVE-2025-0433
6.4 MEDIUM

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Mar 4, 2025
CVE-2024-9618
6.4 MEDIUM

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Mar 4, 2025
CVE-2024-13724
4.3 MEDIUM

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in …

Mar 4, 2025
CVE-2024-13682
4.3 MEDIUM

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 4, 2025
CVE-2025-27521
6.8 MEDIUM

Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58050
6.2 MEDIUM

Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58049
5.0 MEDIUM

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58048
6.7 MEDIUM

Multi-thread problem vulnerability in the package management module Impact: Successful exploitation of this vulnerability may affect availability.

Mar 4, 2025
CVE-2024-58047
5.0 MEDIUM

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58046
6.2 MEDIUM

Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58045
8.6 HIGH

Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.

Mar 4, 2025
CVE-2024-58044
8.4 HIGH

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

Mar 4, 2025
CVE-2024-58043
7.3 HIGH

Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-48248
8.6 HIGH KEV

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across …

Mar 4, 2025
CVE-2025-0360
7.8 HIGH

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to …

Mar 4, 2025
CVE-2025-0359
8.5 HIGH

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access …

Mar 4, 2025
CVE-2024-47262
5.3 MEDIUM

Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing …

Mar 4, 2025
CVE-2024-47260
6.5 MEDIUM

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for …

Mar 4, 2025
CVE-2024-47259
3.5 LOW

Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for …

Mar 4, 2025
CVE-2024-13685
5.3 MEDIUM

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value …

Mar 4, 2025
CVE-2025-1906
4.7 MEDIUM

A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. …

Mar 4, 2025
CVE-2025-1905
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The …

Mar 4, 2025
CVE-2025-1904
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of …

Mar 4, 2025
CVE-2025-1307
9.8 CRITICAL

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up …

Mar 4, 2025
CVE-2025-1306
8.8 HIGH

The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or …

Mar 4, 2025
CVE-2025-24309
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only …

Mar 4, 2025
CVE-2025-24301
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited …

Mar 4, 2025
CVE-2025-23420
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only …

Mar 4, 2025
CVE-2025-23418
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Mar 4, 2025
CVE-2025-23414
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited …

Mar 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.