CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-3928

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3919

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3913

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3911

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3908

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3549

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3483

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3448

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3437

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3402

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-3185

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-2965

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-2238

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-1266

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2023-1171

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2022-2283

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2025-25243
8.6 HIGH

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the …

Feb 11, 2025
CVE-2025-25241
5.4 MEDIUM

Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker …

Feb 11, 2025
CVE-2025-24876
8.1 HIGH

The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session …

Feb 11, 2025
CVE-2025-24875
6.8 MEDIUM

SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying …

Feb 11, 2025
CVE-2025-24874
6.8 MEDIUM

SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in …

Feb 11, 2025
CVE-2025-24872
4.3 MEDIUM

The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build …

Feb 11, 2025
CVE-2025-24870
6.0 MEDIUM

SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within …

Feb 11, 2025
CVE-2025-24869
4.3 MEDIUM

SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This …

Feb 11, 2025
CVE-2025-24868
7.1 HIGH

The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to …

Feb 11, 2025
CVE-2025-24867
6.1 MEDIUM

SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft …

Feb 11, 2025
CVE-2025-23193
5.3 MEDIUM

SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a …

Feb 11, 2025
CVE-2025-23191
3.1 LOW

Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an …

Feb 11, 2025
CVE-2025-23190
4.3 MEDIUM

Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not …

Feb 11, 2025
CVE-2025-23189
4.3 MEDIUM

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a …

Feb 11, 2025
CVE-2025-23187
5.3 MEDIUM

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a …

Feb 11, 2025
CVE-2025-1165
7.3 HIGH

A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of …

Feb 11, 2025
CVE-2025-0064
8.7 HIGH

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a …

Feb 11, 2025
CVE-2025-0054
5.4 MEDIUM

SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user …

Feb 11, 2025
CVE-2024-11890

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 11, 2025
CVE-2025-1164
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of …

Feb 11, 2025
CVE-2025-1163
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Vehicle Parking Management System 1.0. This vulnerability affects the function login of the component Authentication. The …

Feb 11, 2025
CVE-2025-25194
4.0 MEDIUM

Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation …

Feb 10, 2025
CVE-2025-1162
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\_parse/load\_user-profile.php. The manipulation of …

Feb 10, 2025
CVE-2025-1160
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Feb 10, 2025
CVE-2025-25193
5.5 MEDIUM

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially …

Feb 10, 2025
CVE-2025-25190

The ZOO-Project is an open source processing platform. The ZOO-Project Web Processing Service (WPS) Server contains a Cross-Site Scripting (XSS) vulnerability in its EchoProcess service …

Feb 10, 2025
CVE-2025-25189

The ZOO-Project is an open source processing platform. A reflected Cross-Site Scripting vulnerability exists in the ZOO-Project Web Processing Service (WPS) publish.py CGI script prior …

Feb 10, 2025
CVE-2025-24970
7.5 HIGH

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is …

Feb 10, 2025
CVE-2025-1159
3.5 LOW

A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 10, 2025
CVE-2025-1158
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation …

Feb 10, 2025
CVE-2025-1157
6.3 MEDIUM

A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /model/model_recuperar_senha.php. The …

Feb 10, 2025
CVE-2025-1156
7.3 HIGH

A vulnerability has been found in Pix Software Vivaz 6.0.10 and classified as critical. This vulnerability affects unknown code of the file /servlet?act=login. The manipulation …

Feb 10, 2025
CVE-2025-1002
5.7 MEDIUM

MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position …

Feb 10, 2025
CVE-2025-24016
9.9 CRITICAL KEV

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an …

Feb 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.