CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1875
9.8 CRITICAL

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php.

Mar 3, 2025
CVE-2025-1874
9.8 CRITICAL

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.

Mar 3, 2025
CVE-2025-1873
9.8 CRITICAL

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.

Mar 3, 2025
CVE-2025-1872
9.8 CRITICAL

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php.

Mar 3, 2025
CVE-2025-1871
9.8 CRITICAL

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php.

Mar 3, 2025
CVE-2025-1870
9.8 CRITICAL

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php.

Mar 3, 2025
CVE-2025-1869
9.8 CRITICAL

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.

Mar 3, 2025
CVE-2025-21424
7.8 HIGH

Memory corruption while calling the NPU driver APIs concurrently.

Mar 3, 2025
CVE-2025-1868
6.8 MEDIUM

Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scanner. It occurs when these applications initiate a network scan, inadvertently …

Mar 3, 2025
CVE-2025-0475
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. …

Mar 3, 2025
CVE-2024-53034
7.8 HIGH

Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.

Mar 3, 2025
CVE-2024-53033
7.8 HIGH

Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.

Mar 3, 2025
CVE-2024-53032
7.8 HIGH

Memory corruption may occur in keyboard virtual device due to guest VM interaction.

Mar 3, 2025
CVE-2024-53031
7.8 HIGH

Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.

Mar 3, 2025
CVE-2024-53030
7.8 HIGH

Memory corruption while processing input message passed from FE driver.

Mar 3, 2025
CVE-2024-53029
7.8 HIGH

Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.

Mar 3, 2025
CVE-2024-53028
7.8 HIGH

Memory corruption may occur while processing message from frontend during allocation.

Mar 3, 2025
CVE-2024-53027
7.5 HIGH

Transient DOS may occur while processing the country IE.

Mar 3, 2025
CVE-2024-53025
5.5 MEDIUM

Transient DOS can occur while processing UCI command.

Mar 3, 2025
CVE-2024-53024
7.8 HIGH

Memory corruption in display driver while detaching a device.

Mar 3, 2025
CVE-2024-53023
7.8 HIGH

Memory corruption may occur while accessing a variable during extended back to back tests.

Mar 3, 2025
CVE-2024-53022
7.8 HIGH

Memory corruption may occur during communication between primary and guest VM.

Mar 3, 2025
CVE-2024-53014
7.8 HIGH

Memory corruption may occur while validating ports and channels in Audio driver.

Mar 3, 2025
CVE-2024-53012
7.8 HIGH

Memory corruption may occur due to improper input validation in clock device.

Mar 3, 2025
CVE-2024-53011
7.9 HIGH

Information disclosure may occur due to improper permission and access controls to Video Analytics engine.

Mar 3, 2025
CVE-2024-49836
7.8 HIGH

Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.

Mar 3, 2025
CVE-2024-45580
7.8 HIGH

Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.

Mar 3, 2025
CVE-2024-43062
7.8 HIGH

Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.

Mar 3, 2025
CVE-2024-43061
7.8 HIGH

Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

Mar 3, 2025
CVE-2024-43060
7.8 HIGH

Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.

Mar 3, 2025
CVE-2024-43059
7.8 HIGH

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

Mar 3, 2025
CVE-2024-43057
7.8 HIGH

Memory corruption while processing command in Glink linux.

Mar 3, 2025
CVE-2024-43056
5.5 MEDIUM

Transient DOS during hypervisor virtual I/O operation in a virtual machine.

Mar 3, 2025
CVE-2024-43055
7.8 HIGH

Memory corruption while processing camera use case IOCTL call.

Mar 3, 2025
CVE-2024-43051
5.5 MEDIUM

Information disclosure while deriving keys for a session for any Widevine use case.

Mar 3, 2025
CVE-2024-38426
5.4 MEDIUM

While processing the authentication message in UE, improper authentication may lead to information disclosure.

Mar 3, 2025
CVE-2024-24778
6.5 MEDIUM

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: …

Mar 3, 2025
CVE-2024-10925
5.3 MEDIUM

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user …

Mar 3, 2025
CVE-2024-8186
5.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could …

Mar 3, 2025
CVE-2025-25280
5.3 MEDIUM

Buffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by Century Systems Co., Ltd. If this vulnerability …

Mar 3, 2025
CVE-2025-24846
7.5 HIGH

Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker …

Mar 3, 2025
CVE-2025-24654
7.1 HIGH

Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07.

Mar 3, 2025
CVE-2025-1867

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in ithewei libhv allows HTTP Response Smuggling.This issue affects libhv: through 1.3.3.

Mar 3, 2025
CVE-2025-1866

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in warmcat libwebsockets allows Pointer Manipulation, potentially leading to out-of-bounds memory access. This …

Mar 3, 2025
CVE-2025-1864
9.8 CRITICAL

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9.

Mar 3, 2025
CVE-2025-1859
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file /login.php. …

Mar 3, 2025
CVE-2025-1858
7.3 HIGH

A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of …

Mar 3, 2025
CVE-2025-1857
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. …

Mar 3, 2025
CVE-2025-1856
7.3 HIGH

A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mar 3, 2025
CVE-2025-1723
8.1 HIGH

Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only …

Mar 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.