CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57257
2.0 LOW

A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.

Feb 18, 2025
CVE-2024-57256
7.1 HIGH

An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with …

Feb 18, 2025
CVE-2024-57255
7.1 HIGH

An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a …

Feb 18, 2025
CVE-2024-57254
7.1 HIGH

An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem.

Feb 18, 2025
CVE-2024-13743
6.4 MEDIUM

The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_video shortcode in all versions up to, and including, …

Feb 18, 2025
CVE-2025-25896
5.7 MEDIUM

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the destination, netmask, and gateway parameters. This vulnerability allows attackers to cause a Denial …

Feb 18, 2025
CVE-2025-25895
8.0 HIGH

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulnerability allows attackers to execute arbitrary operating system (OS) …

Feb 18, 2025
CVE-2025-25894
8.0 HIGH

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters. This vulnerability allows attackers to execute arbitrary operating …

Feb 18, 2025
CVE-2025-25893
8.0 HIGH

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers …

Feb 18, 2025
CVE-2025-25892
5.7 MEDIUM

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip parameters. This vulnerability allows attackers to cause a …

Feb 18, 2025
CVE-2025-25891
5.7 MEDIUM

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gateway parameters. This vulnerability allows attackers to cause a …

Feb 18, 2025
CVE-2025-25469
6.5 MEDIUM

FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.

Feb 18, 2025
CVE-2025-25468
6.5 MEDIUM

FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.

Feb 18, 2025
CVE-2025-25467
9.8 CRITICAL

Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.

Feb 18, 2025
CVE-2025-22921
6.5 MEDIUM

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

Feb 18, 2025
CVE-2024-56171
7.8 HIGH

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be …

Feb 18, 2025
CVE-2025-26617
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26616
7.5 HIGH

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26615
10.0 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26614
8.8 HIGH

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26613
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the …

Feb 18, 2025
CVE-2025-26612
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26611
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26610
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26609
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26608
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26607
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26606
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26605
8.8 HIGH

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-27016
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Drivr Lite – Google Drive Plugin allows Stored XSS. This issue affects …

Feb 18, 2025
CVE-2025-27013
5.3 MEDIUM

Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MediCenter - Health Medical …

Feb 18, 2025
CVE-2025-26623
9.8 CRITICAL

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer …

Feb 18, 2025
CVE-2025-26604
8.3 HIGH

Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, …

Feb 18, 2025
CVE-2025-22663
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Path Traversal.This issue affects Paid …

Feb 18, 2025
CVE-2025-22657
7.5 HIGH

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.0.9.

Feb 18, 2025
CVE-2025-22656
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Oscar Alvarez Cookie Monster cookie-monster allows PHP Local File …

Feb 18, 2025
CVE-2025-22654
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious Files.This issue affects Simplified: from n/a through <= 1.0.6.

Feb 18, 2025
CVE-2025-22650
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget smartarget-contact-us allows Stored XSS.This issue affects Smartarget: from n/a through …

Feb 18, 2025
CVE-2025-22645
5.3 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Password Brute Forcing.This issue affects Real Estate Manager: from n/a …

Feb 18, 2025
CVE-2025-22639
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerce distance-rate-shipping-for-woocommerce-pro allows Blind SQL Injection.This …

Feb 18, 2025
CVE-2025-0622
6.4 MEDIUM

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw …

Feb 18, 2025
CVE-2024-56000
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.

Feb 18, 2025
CVE-2024-45783
4.4 MEDIUM

A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERRNO value. This issue …

Feb 18, 2025
CVE-2024-45781
6.7 MEDIUM

A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as …

Feb 18, 2025
CVE-2024-45776
6.7 MEDIUM

When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may …

Feb 18, 2025
CVE-2024-45775
5.2 MEDIUM

A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check …

Feb 18, 2025
CVE-2025-26603
4.2 MEDIUM

Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to …

Feb 18, 2025
CVE-2025-26465
6.8 MEDIUM

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit …

Feb 18, 2025
CVE-2025-25305
7.0 HIGH

Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks …

Feb 18, 2025
CVE-2025-25284

The ZOO-Project is an open source processing platform, released under MIT/X11 Licence. A vulnerability in ZOO-Project's WPS (Web Processing Service) implementation allows unauthorized access to …

Feb 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.