CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49780
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to …

Feb 20, 2025
CVE-2024-49355
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing …

Feb 20, 2025
CVE-2024-43196
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof …

Feb 20, 2025
CVE-2025-24947
5.3 MEDIUM

A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a …

Feb 20, 2025
CVE-2025-24946
5.3 MEDIUM

The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attackers to cause a considerable CPU load …

Feb 20, 2025
CVE-2025-23020
5.3 MEDIUM

An issue was discovered in Kwik before 0.10.1. A hash collision vulnerability (in the hash table used to manage connections) allows remote attackers to cause …

Feb 20, 2025
CVE-2025-1492
7.8 HIGH

Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture …

Feb 20, 2025
CVE-2025-1293
8.2 HIGH

Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, …

Feb 20, 2025
CVE-2025-1223
6.1 MEDIUM

An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

Feb 20, 2025
CVE-2025-1222
6.1 MEDIUM

An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

Feb 20, 2025
CVE-2025-0112

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to …

Feb 20, 2025
CVE-2024-6697
6.5 MEDIUM

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may …

Feb 20, 2025
CVE-2024-6696
4.9 MEDIUM

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in …

Feb 20, 2025
CVE-2024-37363
6.5 MEDIUM

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862) Hitachi Vantara Pentaho Business …

Feb 20, 2025
CVE-2024-37362
6.3 MEDIUM

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522) Hitachi Vantara Pentaho …

Feb 20, 2025
CVE-2024-37361
9.9 CRITICAL

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 …

Feb 20, 2025
CVE-2024-12284
8.8 HIGH

Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

Feb 20, 2025
CVE-2025-27092
7.5 HIGH

GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path traversal vulnerability was discovered in GHOSTS version 8.0.0.0 …

Feb 19, 2025
CVE-2025-25947
5.5 MEDIUM

An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a …

Feb 19, 2025
CVE-2025-25946
5.5 MEDIUM

An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution …

Feb 19, 2025
CVE-2025-25945
6.5 MEDIUM

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.

Feb 19, 2025
CVE-2025-25944
7.3 HIGH

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment …

Feb 19, 2025
CVE-2025-25943
7.8 HIGH

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.

Feb 19, 2025
CVE-2025-25942
6.5 MEDIUM

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in …

Feb 19, 2025
CVE-2025-24989
8.2 HIGH KEV

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This …

Feb 19, 2025
CVE-2025-21355
8.6 HIGH

Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network

Feb 19, 2025
CVE-2024-5706
8.8 HIGH

The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier …

Feb 19, 2025
CVE-2024-5705
8.8 HIGH

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the …

Feb 19, 2025
CVE-2024-37360
4.4 MEDIUM

Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The software does not neutralize or incorrectly neutralize …

Feb 19, 2025
CVE-2024-37359
8.6 HIGH

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently …

Feb 19, 2025
CVE-2024-10339

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 19, 2025
CVE-2023-51305
5.4 MEDIUM

PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

Feb 19, 2025
CVE-2025-27090
5.3 MEDIUM

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse …

Feb 19, 2025
CVE-2025-25196
9.8 CRITICAL

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < …

Feb 19, 2025
CVE-2023-51303
6.1 MEDIUM

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

Feb 19, 2025
CVE-2023-51302
8.8 HIGH

PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient …

Feb 19, 2025
CVE-2023-51301
7.5 HIGH

A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount …

Feb 19, 2025
CVE-2023-51300
6.1 MEDIUM

PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

Feb 19, 2025
CVE-2023-51299
6.1 MEDIUM

PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

Feb 19, 2025
CVE-2023-51298
4.7 MEDIUM

PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient …

Feb 19, 2025
CVE-2023-51297
6.5 MEDIUM

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email …

Feb 19, 2025
CVE-2025-0677
6.4 MEDIUM

A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer …

Feb 19, 2025
CVE-2025-0624
7.6 HIGH

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user …

Feb 19, 2025
CVE-2023-51296
6.1 MEDIUM

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary …

Feb 19, 2025
CVE-2023-51293
7.5 HIGH

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount …

Feb 19, 2025
CVE-2023-46272
8.8 HIGH

Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation …

Feb 19, 2025
CVE-2023-46271
9.8 CRITICAL

Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on …

Feb 19, 2025
CVE-2020-35546
9.1 CRITICAL

Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

Feb 19, 2025
CVE-2020-13481
6.1 MEDIUM

Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information.

Feb 19, 2025
CVE-2025-24806

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. If users are allowed …

Feb 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.