CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-26491

Rejected reason: This CVE ID is a duplicate of CVE-2025-26494.

Feb 11, 2025
CVE-2025-26490

Rejected reason: This CVE ID is a duplicate of CVE-2025-26495.

Feb 11, 2025
CVE-2025-24956
6.2 MEDIUM

A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial …

Feb 11, 2025
CVE-2025-24812
6.5 MEDIUM

A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0) (All versions < …

Feb 11, 2025
CVE-2025-24811
7.5 HIGH

A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0), SIMATIC …

Feb 11, 2025
CVE-2025-24532
4.3 MEDIUM

A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All …

Feb 11, 2025
CVE-2025-24499
7.2 HIGH

A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All …

Feb 11, 2025
CVE-2025-23403
7.0 HIGH

A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The affected device do not properly restrict the user …

Feb 11, 2025
CVE-2025-23363
7.4 HIGH

A vulnerability has been identified in Teamcenter V14.1 (All versions), Teamcenter V14.2 (All versions), Teamcenter V14.3 (All versions < V14.3.0.14), Teamcenter V2312 (All versions < …

Feb 11, 2025
CVE-2025-0862
4.9 MEDIUM

The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘after’ parameter in all versions up to, and …

Feb 11, 2025
CVE-2025-0526
5.4 MEDIUM

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked …

Feb 11, 2025
CVE-2025-0513
5.4 MEDIUM

In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error …

Feb 11, 2025
CVE-2024-54090
5.9 MEDIUM

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). …

Feb 11, 2025
CVE-2024-54089
7.5 HIGH

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). …

Feb 11, 2025
CVE-2024-54015
7.5 HIGH

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC …

Feb 11, 2025
CVE-2024-53977
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows …

Feb 11, 2025
CVE-2024-53651
4.6 MEDIUM

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC …

Feb 11, 2025
CVE-2024-53648
6.8 MEDIUM

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All …

Feb 11, 2025
CVE-2024-45386
8.8 HIGH

A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo …

Feb 11, 2025
CVE-2024-23814
5.3 MEDIUM

The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving specially crafted messages …

Feb 11, 2025
CVE-2024-13506
6.4 MEDIUM

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter …

Feb 11, 2025
CVE-2023-37482
5.3 MEDIUM

The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit …

Feb 11, 2025
CVE-2025-26411
8.8 HIGH

An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to …

Feb 11, 2025
CVE-2025-26410
9.8 CRITICAL

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking …

Feb 11, 2025
CVE-2025-26409
6.8 MEDIUM

A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader …

Feb 11, 2025
CVE-2025-26408
6.1 MEDIUM

The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the …

Feb 11, 2025
CVE-2025-0525
7.5 HIGH

In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an …

Feb 11, 2025
CVE-2025-1182
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component …

Feb 11, 2025
CVE-2025-0589
5.3 MEDIUM

In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API …

Feb 11, 2025
CVE-2025-1181
5.0 MEDIUM

A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. …

Feb 11, 2025
CVE-2025-1180
3.1 LOW

A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. …

Feb 11, 2025
CVE-2024-52612
6.8 MEDIUM

SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. This vulnerability requires authentication by …

Feb 11, 2025
CVE-2024-52611
3.5 LOW

The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the data does not provide anything sensitive, the information could …

Feb 11, 2025
CVE-2024-52606
3.5 LOW

SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of a malicious web request.

Feb 11, 2025
CVE-2024-45718
4.6 MEDIUM

Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a low- privileged account is required …

Feb 11, 2025
CVE-2024-28989
5.5 MEDIUM

SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.

Feb 11, 2025
CVE-2024-13643
8.8 HIGH

The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. This vulnerability can lead to privilege …

Feb 11, 2025
CVE-2025-1179
5.0 MEDIUM

A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file …

Feb 11, 2025
CVE-2025-1178
5.6 MEDIUM

A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file …

Feb 11, 2025
CVE-2025-0181
9.8 CRITICAL

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.8. This is due …

Feb 11, 2025
CVE-2025-0180
9.8 CRITICAL

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin …

Feb 11, 2025
CVE-2025-1177
6.3 MEDIUM

A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import_add of the file dayrui/Fcms/Control/Admin/Linkage.php. The manipulation …

Feb 11, 2025
CVE-2025-1176
5.0 MEDIUM

A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component …

Feb 11, 2025
CVE-2024-13570
6.1 MEDIUM

The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 11, 2025
CVE-2024-13544
4.8 MEDIUM

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files …

Feb 11, 2025
CVE-2024-13543
6.1 MEDIUM

The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 11, 2025
CVE-2025-1211
6.5 MEDIUM

Versions of the package hackney before 1.21.0 are vulnerable to Server-side Request Forgery (SSRF) due to improper parsing of URLs by URI built-in module and …

Feb 11, 2025
CVE-2025-1174
2.4 LOW

A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file process_book_add.php …

Feb 11, 2025
CVE-2025-1173
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file process_users_del.php. …

Feb 11, 2025
CVE-2024-12599
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions …

Feb 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.