CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1855
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Mar 3, 2025
CVE-2025-1854
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/del_member.php. …

Mar 3, 2025
CVE-2024-53386
4.9 MEDIUM

Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can …

Mar 3, 2025
CVE-2024-53382
4.9 MEDIUM

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript …

Mar 3, 2025
CVE-2025-1853
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component …

Mar 3, 2025
CVE-2025-1852
8.8 HIGH

A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation …

Mar 3, 2025
CVE-2025-1851
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC7 up to 15.03.06.44. This affects the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The …

Mar 3, 2025
CVE-2025-1850
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by this issue is some unknown functionality of …

Mar 3, 2025
CVE-2025-27590
9.0 CRITICAL

In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is …

Mar 3, 2025
CVE-2025-1849
6.3 MEDIUM

A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is an unknown functionality of the file /import_data_todb. …

Mar 3, 2025
CVE-2025-1848
6.3 MEDIUM

A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is an unknown function of the file /import_data_check. The manipulation …

Mar 3, 2025
CVE-2025-20653
6.5 MEDIUM

In da, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure, if an attacker …

Mar 3, 2025
CVE-2025-20652
4.6 MEDIUM

In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if …

Mar 3, 2025
CVE-2025-20651
4.1 MEDIUM

In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an …

Mar 3, 2025
CVE-2025-20650
6.8 MEDIUM

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Mar 3, 2025
CVE-2025-20649
6.5 MEDIUM

In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with …

Mar 3, 2025
CVE-2025-20648
5.5 MEDIUM

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Mar 3, 2025
CVE-2025-20647
6.5 MEDIUM

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE …

Mar 3, 2025
CVE-2025-20646
9.8 CRITICAL

In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege …

Mar 3, 2025
CVE-2025-20645
7.8 HIGH

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Mar 3, 2025
CVE-2025-20644
6.5 MEDIUM

In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has …

Mar 3, 2025
CVE-2025-1847
6.3 MEDIUM

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads …

Mar 3, 2025
CVE-2025-1846
5.4 MEDIUM

A vulnerability was found in zj1983 zz up to 2024-8. It has been declared as problematic. This vulnerability affects the function deleteLocalFile of the file …

Mar 3, 2025
CVE-2025-1845
6.3 MEDIUM

A vulnerability has been found in ESAFENET DSM 3.1.2 and classified as critical. Affected by this vulnerability is the function examExportPDF of the file /admin/plan/examExportPDF. …

Mar 3, 2025
CVE-2025-1844
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. Affected is an unknown function of the file /CDGServer3/logManagement/backupLogDetail.jsp. The manipulation of …

Mar 3, 2025
CVE-2025-27585
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts …

Mar 3, 2025
CVE-2025-27584
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts …

Mar 3, 2025
CVE-2025-27583
9.1 CRITICAL

Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, …

Mar 3, 2025
CVE-2025-25953
6.5 MEDIUM

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated …

Mar 3, 2025
CVE-2025-25952
6.5 MEDIUM

An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to …

Mar 3, 2025
CVE-2025-25951
7.5 HIGH

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive …

Mar 3, 2025
CVE-2025-25950
8.1 HIGH

Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, …

Mar 3, 2025
CVE-2025-25949
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts …

Mar 3, 2025
CVE-2025-25948
9.1 CRITICAL

Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, …

Mar 3, 2025
CVE-2025-1843
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20250211. This issue affects the function select of the file com/xq/tmall/dao/ProductMapper.java. …

Mar 3, 2025
CVE-2025-1842
4.3 MEDIUM

A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. This vulnerability affects unknown code of the file /login.php. The manipulation …

Mar 3, 2025
CVE-2025-27579
5.4 MEDIUM

In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka stratumUser) for a Bitaxe Bitcoin …

Mar 3, 2025
CVE-2025-1841
7.3 HIGH

A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the file /CDGServer3/logManagement/ClientSortLog.jsp. The manipulation of the …

Mar 3, 2025
CVE-2025-1840
7.3 HIGH

A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Mar 3, 2025
CVE-2025-1836
4.3 MEDIUM

A vulnerability was found in Incorta 2023.4.3. It has been classified as problematic. Affected is an unknown function of the component Edit Insight Handler. The …

Mar 2, 2025
CVE-2025-1835
6.3 MEDIUM

A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /app/controller/Api.php. The manipulation …

Mar 2, 2025
CVE-2025-1834
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The …

Mar 2, 2025
CVE-2025-1833
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. Affected by this issue is the function sendNotice of …

Mar 2, 2025
CVE-2025-1832
6.3 MEDIUM

A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is the function getUserList of the file src/main/java/com/futvan/z/system/zrole/ZroleAction.java. …

Mar 2, 2025
CVE-2025-1831
6.3 MEDIUM

A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is the function GetDBUser of the file src/main/java/com/futvan/z/system/zorg/ZorgAction.java. The manipulation …

Mar 2, 2025
CVE-2025-1830
2.4 LOW

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown processing of the component …

Mar 2, 2025
CVE-2025-1829
6.3 MEDIUM

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknatCfg of the file /cgi-bin/cstecgi.cgi. The …

Mar 2, 2025
CVE-2025-1821
6.3 MEDIUM

A vulnerability was found in zj1983 zz up to 2024-8 and classified as critical. Affected by this issue is the function getUserOrgForUserId of the file …

Mar 2, 2025
CVE-2024-36353
6.5 MEDIUM

Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over memory values potentially leading to …

Mar 2, 2025
CVE-2025-1820
6.3 MEDIUM

A vulnerability has been found in zj1983 zz up to 2024-8 and classified as critical. Affected by this vulnerability is the function getOaWid of the …

Mar 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.