CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23409
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited …

Mar 4, 2025
CVE-2025-23240
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only …

Mar 4, 2025
CVE-2025-23234
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

Mar 4, 2025
CVE-2025-22897
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

Mar 4, 2025
CVE-2025-22847
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Mar 4, 2025
CVE-2025-22841
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Mar 4, 2025
CVE-2025-22837
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

Mar 4, 2025
CVE-2025-22835
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only …

Mar 4, 2025
CVE-2025-22443
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Mar 4, 2025
CVE-2025-21098
5.5 MEDIUM

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.

Mar 4, 2025
CVE-2025-21097
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

Mar 4, 2025
CVE-2025-21089
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Mar 4, 2025
CVE-2025-21084
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be …

Mar 4, 2025
CVE-2025-20626
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited …

Mar 4, 2025
CVE-2025-20091
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited …

Mar 4, 2025
CVE-2025-20081
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited …

Mar 4, 2025
CVE-2025-20042
5.5 MEDIUM

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.

Mar 4, 2025
CVE-2025-20024
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only …

Mar 4, 2025
CVE-2025-20021
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Mar 4, 2025
CVE-2025-20011
3.3 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

Mar 4, 2025
CVE-2025-1903
7.3 HIGH

A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Mar 4, 2025
CVE-2025-1902
7.3 HIGH

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. …

Mar 4, 2025
CVE-2025-1901
7.3 HIGH

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file …

Mar 4, 2025
CVE-2025-1900
7.3 HIGH

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 4, 2025
CVE-2025-1639
8.8 HIGH

The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() …

Mar 4, 2025
CVE-2025-1321
6.5 MEDIUM

The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode in all versions up to, and including, …

Mar 4, 2025
CVE-2025-0912
9.8 CRITICAL

The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input …

Mar 4, 2025
CVE-2025-0587
3.8 LOW

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only …

Mar 4, 2025
CVE-2024-13686
4.3 MEDIUM

The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all …

Mar 4, 2025
CVE-2025-1899
6.5 MEDIUM

A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setPptpUserList. …

Mar 4, 2025
CVE-2025-1898
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affected is an unknown function of the file /goform/openSchedWifi. The manipulation of …

Mar 4, 2025
CVE-2025-1897
6.5 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. This issue affects some unknown processing of the file /goform/SetNetControlList. The …

Mar 4, 2025
CVE-2025-1896
6.5 MEDIUM

A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability affects unknown code of the file /goform/SetStaticRouteCfg. The manipulation of the argument …

Mar 4, 2025
CVE-2025-1895
6.5 MEDIUM

A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file /goform/setMacFilterCfg. The manipulation of the …

Mar 4, 2025
CVE-2025-1894
7.3 HIGH

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 4, 2025
CVE-2025-1893
4.3 MEDIUM

A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the …

Mar 4, 2025
CVE-2025-1892
2.4 LOW

A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component …

Mar 4, 2025
CVE-2025-1695
5.3 MEDIUM

In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase …

Mar 4, 2025
CVE-2025-27221
3.2 LOW

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is …

Mar 4, 2025
CVE-2025-27220
4.0 MEDIUM

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

Mar 4, 2025
CVE-2025-27219
5.8 MEDIUM

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method …

Mar 4, 2025
CVE-2025-1891
4.3 MEDIUM

A vulnerability was found in shishuocms 1.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The …

Mar 4, 2025
CVE-2025-1890
6.3 MEDIUM

A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of …

Mar 4, 2025
CVE-2024-55064
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, …

Mar 3, 2025
CVE-2025-1882
5.0 MEDIUM

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown …

Mar 3, 2025
CVE-2025-1881
4.3 MEDIUM

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been declared as problematic. Affected by this vulnerability is an unknown …

Mar 3, 2025
CVE-2025-1880
2.0 LOW

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the …

Mar 3, 2025
CVE-2025-1879
2.4 LOW

A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component …

Mar 3, 2025
CVE-2024-5888
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51966
4.9 MEDIUM

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges …

Mar 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.