CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53876
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53875
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53874
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53873
3.3 LOW

NVIDIA CUDA toolkit for Windows contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF …

Feb 25, 2025
CVE-2024-53872
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53871
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53870
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-27246
4.3 MEDIUM

Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Feb 25, 2025
CVE-2024-27245
4.3 MEDIUM

Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Feb 25, 2025
CVE-2024-27239
4.3 MEDIUM

Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Feb 25, 2025
CVE-2024-0148
7.6 HIGH

NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to …

Feb 25, 2025
CVE-2025-27146
2.7 LOW

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command …

Feb 25, 2025
CVE-2025-27142
8.8 HIGH

LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over their local network without needing an …

Feb 25, 2025
CVE-2025-27139
6.8 MEDIUM

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences …

Feb 25, 2025
CVE-2025-27110
7.5 HIGH

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying …

Feb 25, 2025
CVE-2024-45426
4.9 MEDIUM

Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

Feb 25, 2025
CVE-2024-45425
4.9 MEDIUM

Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

Feb 25, 2025
CVE-2024-45424
5.3 MEDIUM

Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.

Feb 25, 2025
CVE-2024-45421
8.5 HIGH

Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Feb 25, 2025
CVE-2024-45418
5.4 MEDIUM

Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege …

Feb 25, 2025
CVE-2024-45417
6.0 MEDIUM

Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of …

Feb 25, 2025
CVE-2025-27135
9.8 CRITICAL

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from …

Feb 25, 2025
CVE-2024-36259
7.5 HIGH

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based …

Feb 25, 2025
CVE-2025-25192
6.5 MEDIUM

GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive …

Feb 25, 2025
CVE-2025-23046
7.5 HIGH

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider …

Feb 25, 2025
CVE-2024-12368
8.1 HIGH

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of …

Feb 25, 2025
CVE-2025-1204

The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings …

Feb 25, 2025
CVE-2025-1068
7.3 HIGH

There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to …

Feb 25, 2025
CVE-2025-1067
7.3 HIGH

There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to …

Feb 25, 2025
CVE-2025-26601
7.8 HIGH

A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, …

Feb 25, 2025
CVE-2025-26600
7.8 HIGH

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while …

Feb 25, 2025
CVE-2025-26599
7.8 HIGH

An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. …

Feb 25, 2025
CVE-2025-26598
7.8 HIGH

An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns …

Feb 25, 2025
CVE-2025-26597
7.8 HIGH

A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table …

Feb 25, 2025
CVE-2025-26596
7.8 HIGH

A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which …

Feb 25, 2025
CVE-2025-26595
7.8 HIGH

A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names …

Feb 25, 2025
CVE-2025-26594
7.8 HIGH

A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client …

Feb 25, 2025
CVE-2025-23024
4.3 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all …

Feb 25, 2025
CVE-2025-21627
6.5 MEDIUM

GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected …

Feb 25, 2025
CVE-2025-21626
5.8 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive …

Feb 25, 2025
CVE-2024-11955
4.3 MEDIUM

A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Feb 25, 2025
CVE-2025-27000
5.4 MEDIUM

Missing Authorization vulnerability in George Pattichis Simple Photo Feed simple-photo-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Photo Feed: from n/a …

Feb 25, 2025
CVE-2025-26995
5.4 MEDIUM

Missing Authorization vulnerability in Anton Vanyukov Market Exporter market-exporter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Market Exporter: from n/a through <= …

Feb 25, 2025
CVE-2025-26993
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Reflected XSS.This issue affects Atarim: from n/a through …

Feb 25, 2025
CVE-2025-26991
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ollybach WPPizza wppizza allows Reflected XSS.This issue affects WPPizza: from n/a through <= …

Feb 25, 2025
CVE-2025-26987
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Reflected XSS.This issue affects Frontend …

Feb 25, 2025
CVE-2025-26985
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File …

Feb 25, 2025
CVE-2025-26983
4.3 MEDIUM

Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Recipe Card …

Feb 25, 2025
CVE-2025-26981
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accessiBe Web Accessibility By accessiBe accessibe allows Reflected XSS.This issue affects Web Accessibility …

Feb 25, 2025
CVE-2025-26980
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Stored XSS.This issue affects Wired …

Feb 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.