CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51963
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51962
8.7 HIGH

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when …

Mar 3, 2025
CVE-2024-51961
7.5 HIGH

There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that …

Mar 3, 2025
CVE-2024-51960
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51959
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51958
4.9 MEDIUM

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges …

Mar 3, 2025
CVE-2024-51957
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51956
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51954
8.5 HIGH

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a …

Mar 3, 2025
CVE-2024-51953
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51952
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51951
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51950
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51949
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51948
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51947
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51946
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51945
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51944
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51942
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-10904
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2025-27501
8.6 HIGH

OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed …

Mar 3, 2025
CVE-2025-27500
8.2 HIGH

OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed …

Mar 3, 2025
CVE-2025-27499
6.1 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in …

Mar 3, 2025
CVE-2025-26206
9.0 CRITICAL

Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component

Mar 3, 2025
CVE-2025-25967
8.8 HIGH

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as …

Mar 3, 2025
CVE-2025-25939
6.1 MEDIUM

Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.

Mar 3, 2025
CVE-2025-1889
9.8 CRITICAL

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses …

Mar 3, 2025
CVE-2025-1878
3.1 LOW

A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability affects unknown code of the component …

Mar 3, 2025
CVE-2025-1877
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the component HTTP POST Request Handler. …

Mar 3, 2025
CVE-2024-30154
5.3 MEDIUM

HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that …

Mar 3, 2025
CVE-2025-27371
6.9 MEDIUM

In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the …

Mar 3, 2025
CVE-2025-27370
6.9 MEDIUM

OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt authentication mechanism is used, a malicious Authorization Server …

Mar 3, 2025
CVE-2025-0686
6.4 MEDIUM

A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses user-controlled parameters from the filesystem …

Mar 3, 2025
CVE-2025-0685
6.4 MEDIUM

A flaw was found in grub2. When reading data from a jfs filesystem, grub's jfs filesystem module uses user-controlled parameters from the filesystem geometry to …

Mar 3, 2025
CVE-2025-0684
6.4 MEDIUM

A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses user-controlled parameters from the filesystem …

Mar 3, 2025
CVE-2024-53384
5.1 MEDIUM

A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components

Mar 3, 2025
CVE-2024-51091
5.4 MEDIUM

Cross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary code via the seajs package

Mar 3, 2025
CVE-2023-49031
5.1 MEDIUM

Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information …

Mar 3, 2025
CVE-2025-27498

aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag …

Mar 3, 2025
CVE-2025-27423
7.1 HIGH

Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or …

Mar 3, 2025
CVE-2025-27422
7.5 HIGH

FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible …

Mar 3, 2025
CVE-2025-27421
7.5 HIGH

Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server's Server-Sent Events (SSE) implementation. …

Mar 3, 2025
CVE-2025-25303

The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vulnerable to SSRF attacks. The pdf.mjs script uses …

Mar 3, 2025
CVE-2025-25302
6.5 MEDIUM

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows …

Mar 3, 2025
CVE-2025-25301
7.5 HIGH

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image …

Mar 3, 2025
CVE-2025-1876
7.3 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DAP-1562 1.10. Affected by this issue is the function http_request_parse of the component …

Mar 3, 2025
CVE-2025-0678
7.8 HIGH

A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to …

Mar 3, 2025
CVE-2025-0289
7.8 HIGH

Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, …

Mar 3, 2025
CVE-2025-0288
7.8 HIGH

Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled …

Mar 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.