CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24895
9.1 CRITICAL

CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: 1. …

Feb 18, 2025
CVE-2025-24894
9.1 CRITICAL

SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider …

Feb 18, 2025
CVE-2025-21608
5.3 MEDIUM

Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client …

Feb 18, 2025
CVE-2024-57056
5.4 MEDIUM

Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a …

Feb 18, 2025
CVE-2024-57055
5.0 MEDIUM

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue …

Feb 18, 2025
CVE-2024-45774
6.7 MEDIUM

A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its …

Feb 18, 2025
CVE-2025-26620

Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition when requesting access tokens using …

Feb 18, 2025
CVE-2025-26058
4.2 MEDIUM

Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication …

Feb 18, 2025
CVE-2025-25300

smartbanner.js is a customizable smart app banner for iOS and Android. Prior to version 1.14.1, clicking on smartbanner `View` link and navigating to 3rd party …

Feb 18, 2025
CVE-2024-56883
8.1 HIGH

Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage …

Feb 18, 2025
CVE-2024-56882
5.4 MEDIUM

Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the …

Feb 18, 2025
CVE-2024-51505
8.0 HIGH

An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race condition to escalate privileges.

Feb 18, 2025
CVE-2024-50609
7.5 HIGH

An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can …

Feb 18, 2025
CVE-2024-50608
7.5 HIGH

An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, …

Feb 18, 2025
CVE-2024-4028
3.8 LOW

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource …

Feb 18, 2025
CVE-2024-49589
6.5 MEDIUM

Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied …

Feb 18, 2025
CVE-2024-39328
6.8 MEDIUM

Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment …

Feb 18, 2025
CVE-2022-41545
6.4 MEDIUM

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header …

Feb 18, 2025
CVE-2024-55460
9.8 CRITICAL

A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code …

Feb 18, 2025
CVE-2024-39327
9.9 CRITICAL

Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.

Feb 18, 2025
CVE-2025-22207

Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.

Feb 18, 2025
CVE-2025-21703
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netem: Update sch->q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, …

Feb 18, 2025
CVE-2025-21702
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's …

Feb 18, 2025
CVE-2024-57050

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11714. Reason: This candidate is a reservation duplicate of CVE-2018-11714. Notes: All CVE users should reference …

Feb 18, 2025
CVE-2024-57049
9.8 CRITICAL

A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under …

Feb 18, 2025
CVE-2024-57046
8.8 HIGH

A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the …

Feb 18, 2025
CVE-2024-57045
9.8 CRITICAL

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain …

Feb 18, 2025
CVE-2024-13689
6.3 MEDIUM

The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the …

Feb 18, 2025
CVE-2025-1414
6.5 MEDIUM

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Feb 18, 2025
CVE-2025-1269
4.8 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.

Feb 18, 2025
CVE-2025-1035
5.7 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This …

Feb 18, 2025
CVE-2025-0817
7.2 HIGH

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to …

Feb 18, 2025
CVE-2025-0521
7.2 HIGH

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, …

Feb 18, 2025
CVE-2024-13797
7.3 HIGH

The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. …

Feb 18, 2025
CVE-2024-13783
4.3 MEDIUM

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, …

Feb 18, 2025
CVE-2024-13691
6.5 MEDIUM

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, …

Feb 18, 2025
CVE-2024-13681
7.5 HIGH

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, …

Feb 18, 2025
CVE-2024-13667
5.4 MEDIUM

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to …

Feb 18, 2025
CVE-2025-1023
9.8 CRITICAL

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability …

Feb 18, 2025
CVE-2025-0981
6.1 MEDIUM

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) …

Feb 18, 2025
CVE-2024-13369
6.5 MEDIUM

The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up …

Feb 18, 2025
CVE-2024-13718
4.3 MEDIUM

The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Feb 18, 2025
CVE-2024-13395
6.4 MEDIUM

The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode in all versions up to, and including, 1.7.1 due …

Feb 18, 2025
CVE-2024-13316
5.3 MEDIUM

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access …

Feb 18, 2025
CVE-2024-12860
9.8 CRITICAL

The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, …

Feb 18, 2025
CVE-2025-0864
6.1 MEDIUM

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in …

Feb 18, 2025
CVE-2025-0425

Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of the "bestinformed Server" to which …

Feb 18, 2025
CVE-2025-0424

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is …

Feb 18, 2025
CVE-2025-0423

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is …

Feb 18, 2025
CVE-2025-0422

An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the application. (Remote Code Execution) For this, the user …

Feb 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.