CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22960
8.0 HIGH

A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access exposed log files (/logs/debug/xteLog*), potentially …

Feb 13, 2025
CVE-2024-57782
6.8 MEDIUM

An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.

Feb 13, 2025
CVE-2024-56908
6.8 MEDIUM

In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in …

Feb 13, 2025
CVE-2024-54951
5.4 MEDIUM

Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU …

Feb 13, 2025
CVE-2024-53311
5.5 MEDIUM

A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that …

Feb 13, 2025
CVE-2024-53310
5.5 MEDIUM

A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed …

Feb 13, 2025
CVE-2024-53309
5.5 MEDIUM

A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" …

Feb 13, 2025
CVE-2024-37603
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG …

Feb 13, 2025
CVE-2024-37602
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple Car Play function …

Feb 13, 2025
CVE-2024-37601
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of …

Feb 13, 2025
CVE-2024-37600
6.8 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects …

Feb 13, 2025
CVE-2024-12054
5.4 MEDIUM

ZF Roll Stability Support Plus (RSSPlus) is vulnerable to an authentication bypass vulnerability targeting deterministic RSSPlus SecurityAccess service seeds, which may allow an attacker to …

Feb 13, 2025
CVE-2023-34406
3.3 LOW

An issue was discovered on Mercedes Benz NTG 6. A possible integer overflow exists in the user data import/export function of NTG (New Telematics Generation) …

Feb 13, 2025
CVE-2023-34404
4.9 MEDIUM

Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. …

Feb 13, 2025
CVE-2023-34403
4.9 MEDIUM

Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. …

Feb 13, 2025
CVE-2023-34402
7.7 HIGH

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside file is encapsulate another file, which service will drop during processing. …

Feb 13, 2025
CVE-2023-34401
3.7 LOW

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary …

Feb 13, 2025
CVE-2025-26473
7.5 HIGH

The Mojave Inverter uses the GET method for sensitive information.

Feb 13, 2025
CVE-2025-25281
7.5 HIGH

An attacker may modify the URL to discover sensitive information about the target network.

Feb 13, 2025
CVE-2025-25195
4.3 MEDIUM

Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) demotes channels to being "inactive" after they have not received …

Feb 13, 2025
CVE-2025-25067
9.8 CRITICAL

mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

Feb 13, 2025
CVE-2025-24865
10.0 CRITICAL

The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload …

Feb 13, 2025
CVE-2025-24861
7.5 HIGH

An attacker may inject commands via specially-crafted post requests.

Feb 13, 2025
CVE-2025-24836
7.1 HIGH

With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent …

Feb 13, 2025
CVE-2025-23421
6.4 MEDIUM

An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by …

Feb 13, 2025
CVE-2025-23411
6.3 MEDIUM

mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick …

Feb 13, 2025
CVE-2025-22896
8.6 HIGH

mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.

Feb 13, 2025
CVE-2025-20615
6.2 MEDIUM

The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to …

Feb 13, 2025
CVE-2025-1283
9.8 CRITICAL

The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.

Feb 13, 2025
CVE-2024-57378
7.3 HIGH

Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing …

Feb 13, 2025
CVE-2023-34400
7.5 HIGH

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to define header inside the …

Feb 13, 2025
CVE-2023-34399
9.8 CRITICAL

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The …

Feb 13, 2025
CVE-2023-34398
7.5 HIGH

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The …

Feb 13, 2025
CVE-2023-34397
7.5 HIGH

Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will be …

Feb 13, 2025
CVE-2025-1127
9.1 CRITICAL

The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the …

Feb 13, 2025
CVE-2024-11347
7.3 HIGH

Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Forced Integer Overflow.The vulnerability can be leveraged by …

Feb 13, 2025
CVE-2024-11346
7.3 HIGH

: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue …

Feb 13, 2025
CVE-2024-11345
7.3 HIGH

A heap-based memory vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute …

Feb 13, 2025
CVE-2024-11344
7.3 HIGH

A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute …

Feb 13, 2025
CVE-2025-24889
4.5 MEDIUM

The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to versions 0.14.1 …

Feb 13, 2025
CVE-2025-24888
8.1 HIGH

The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to version 0.14.1, …

Feb 13, 2025
CVE-2025-25389
9.8 CRITICAL

A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactno …

Feb 13, 2025
CVE-2025-25388
9.8 CRITICAL

A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the editid …

Feb 13, 2025
CVE-2025-25387
7.2 HIGH

A SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the propertytype …

Feb 13, 2025
CVE-2025-26511
8.8 HIGH

Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible …

Feb 13, 2025
CVE-2025-25901
7.5 HIGH

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 parameters at /userRpm/WanSlaacCfgRpm.htm. This vulnerability allows attackers to cause …

Feb 13, 2025
CVE-2025-25900
4.9 MEDIUM

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /userRpm/PPPoEv6CfgRpm.htm. This vulnerability allows attackers to cause a …

Feb 13, 2025
CVE-2025-25899
3.5 LOW

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'gw' parameter at /userRpm/WanDynamicIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of …

Feb 13, 2025
CVE-2025-25898
7.5 HIGH

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSecurityRpm.htm. This vulnerability allows attackers to cause a Denial of …

Feb 13, 2025
CVE-2025-25897
7.5 HIGH

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of …

Feb 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.