CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25667
9.8 CRITICAL

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.

Feb 20, 2025
CVE-2025-25664
9.8 CRITICAL

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.

Feb 20, 2025
CVE-2025-25663
9.8 CRITICAL

A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to …

Feb 20, 2025
CVE-2025-25662
9.8 CRITICAL

Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.

Feb 20, 2025
CVE-2025-22973
7.5 HIGH

An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly …

Feb 20, 2025
CVE-2024-7131

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 20, 2025
CVE-2024-54756
9.8 CRITICAL

A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted …

Feb 20, 2025
CVE-2025-25960
6.1 MEDIUM

Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background …

Feb 20, 2025
CVE-2025-25958
5.4 MEDIUM

Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.

Feb 20, 2025
CVE-2025-27098
5.8 MEDIUM

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and …

Feb 20, 2025
CVE-2025-27097
7.5 HIGH

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and …

Feb 20, 2025
CVE-2025-25299

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in …

Feb 20, 2025
CVE-2025-24893
9.8 CRITICAL KEV

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution …

Feb 20, 2025
CVE-2025-1265
9.9 CRITICAL

An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code execution on affected system.

Feb 20, 2025
CVE-2025-0352
7.5 HIGH

Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing the API …

Feb 20, 2025
CVE-2025-27096
9.8 CRITICAL

WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovered in the WeGIA application, personalizacao_upload.php endpoint. …

Feb 20, 2025
CVE-2025-26618

Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. OTP is a set of …

Feb 20, 2025
CVE-2024-7141

Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.

Feb 20, 2025
CVE-2023-51339
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2023-51338
5.4 MEDIUM

PHPJabbers Meeting Room Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters of index.php page.

Feb 20, 2025
CVE-2023-51337
5.4 MEDIUM

PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.

Feb 20, 2025
CVE-2023-51336
8.8 HIGH

PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to …

Feb 20, 2025
CVE-2025-27091
7.5 HIGH

OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding functions of OpenH264 codec library could allow …

Feb 20, 2025
CVE-2025-25973
6.5 MEDIUM

A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted …

Feb 20, 2025
CVE-2025-25968
6.0 MEDIUM

DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, …

Feb 20, 2025
CVE-2025-1258

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 20, 2025
CVE-2024-55457
6.5 MEDIUM

MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary …

Feb 20, 2025
CVE-2024-54961
6.5 MEDIUM

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current …

Feb 20, 2025
CVE-2024-54960
6.5 MEDIUM

A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.

Feb 20, 2025
CVE-2024-54959
6.1 MEDIUM

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

Feb 20, 2025
CVE-2024-54958
6.1 MEDIUM

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts …

Feb 20, 2025
CVE-2024-46933
7.7 HIGH

An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading …

Feb 20, 2025
CVE-2023-51335
6.5 MEDIUM

PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

Feb 20, 2025
CVE-2023-51334
5.3 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2023-51333
8.8 HIGH

PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient …

Feb 20, 2025
CVE-2025-26311
6.5 MEDIUM

Multiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in util/parser.c of libming v0.4.8, which allow attackers to cause …

Feb 20, 2025
CVE-2025-26310
6.5 MEDIUM

Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming v0.4.8, which allow attackers to cause …

Feb 20, 2025
CVE-2025-26309
6.5 MEDIUM

A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26308
6.5 MEDIUM

A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26307
6.5 MEDIUM

A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26306
6.5 MEDIUM

A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26305
8.2 HIGH

A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26304
8.2 HIGH

A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.

Feb 20, 2025
CVE-2024-57716
7.5 HIGH

An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.

Feb 20, 2025
CVE-2025-0161
7.8 HIGH

IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restrictions on code …

Feb 20, 2025
CVE-2023-51332
4.3 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of …

Feb 20, 2025
CVE-2023-51331
6.5 MEDIUM

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient …

Feb 20, 2025
CVE-2023-51330
5.4 MEDIUM

PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.

Feb 20, 2025
CVE-2023-51327
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2023-51326
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.