CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10334
7.3 HIGH

A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used. An attacker who successfully exploited the vulnerability …

Feb 10, 2025
CVE-2025-1193
8.1 HIGH

Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and …

Feb 10, 2025
CVE-2025-1148
3.1 LOW

A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of …

Feb 10, 2025
CVE-2025-1147
3.1 LOW

A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c …

Feb 10, 2025
CVE-2024-11621
8.8 HIGH

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle …

Feb 10, 2025
CVE-2025-1175
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in Kelio Visio 1, Kelio Visio X7 and Kelio Visio X4, in versions between 3.2C and 5.1K. This vulnerability could …

Feb 10, 2025
CVE-2024-8685
4.3 MEDIUM

Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint …

Feb 10, 2025
CVE-2024-8684
8.3 HIGH

OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to execute OS commands on the …

Feb 10, 2025
CVE-2025-25247
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 …

Feb 10, 2025
CVE-2025-1099

This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could …

Feb 10, 2025
CVE-2025-21685
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev race The yt2_1380_fc_serdev_probe() function calls devm_serdev_device_open() before setting the client ops …

Feb 9, 2025
CVE-2025-21684
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpio: xilinx: Convert gpio_lock to raw spinlock irq_chip functions may be called in raw spinlock …

Feb 9, 2025
CVE-2024-57949
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity() The following call-chain leads to enabling interrupts in a …

Feb 9, 2025
CVE-2024-13440
8.2 HIGH

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due …

Feb 9, 2025
CVE-2025-0169
6.4 MEDIUM

The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.4 due to …

Feb 8, 2025
CVE-2025-0517

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 8, 2025
CVE-2025-0316
9.8 CRITICAL

The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication …

Feb 8, 2025
CVE-2024-8377

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 8, 2025
CVE-2024-6909

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 8, 2025
CVE-2024-5183

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 8, 2025
CVE-2023-4927

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 8, 2025
CVE-2024-54176
4.3 MEDIUM

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14 and 7.3 …

Feb 8, 2025
CVE-2025-1117
7.3 HIGH

A vulnerability, which was classified as critical, was found in CoinRemitter 0.0.1/0.0.2 on OpenCart. This affects an unknown part. The manipulation of the argument coin …

Feb 8, 2025
CVE-2024-13850
5.5 MEDIUM

The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.0 due to …

Feb 8, 2025
CVE-2025-1116
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on OpenCart. Affected by this issue …

Feb 8, 2025
CVE-2025-1115
3.3 LOW

A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the function sys_device_close/sys_device_control/sys_device_find/sys_device_init/sys_device_open/sys_device_read/sys_device_register/sys_device_write/sys_event_delete/sys_event_recv/sys_event_send/sys_mb_delete/sys_mb_recv/sys_mb_send/sys_mb_send_wait/sys_mq_recv/sys_mq_send/sys_mq_urgent/sys_mutex_delete/sys_mutex_release/sys_mutex_take/sys_rt_timer_control/sys_rt_timer_delete/sys_rt_timer_start/sys_rt_timer_stop/sys_sem_delete/sys_sem_release/sys_sem_take/sys_shmat/sys_shmdt/sys_thread_create/sys_thread_delete/sys_thread_startup/sys_timer_delete/sys_timer_gettime/sys_timer_settime of the file rt-thread/components/lwp/lwp_syscall.c. The …

Feb 8, 2025
CVE-2025-25187
7.8 HIGH

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is …

Feb 7, 2025
CVE-2025-24028
7.8 HIGH

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is …

Feb 7, 2025
CVE-2025-1114
3.5 LOW

A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /admin/categories/save of the component Add Category …

Feb 7, 2025
CVE-2024-55630
3.3 LOW

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer …

Feb 7, 2025
CVE-2025-24366
7.5 HIGH

SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands via SSH. Besides a set of default …

Feb 7, 2025
CVE-2025-1113
6.3 MEDIUM

A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file …

Feb 7, 2025
CVE-2024-57606
7.5 HIGH

SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain sensitive information via the getTotalData component.

Feb 7, 2025
CVE-2024-57357
8.0 HIGH

An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code via function sub_4256CC, which allows command injection by …

Feb 7, 2025
CVE-2024-57279
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager <= ce92321, specifically in the /setup/index.php endpoint via the returnto parameter. …

Feb 7, 2025
CVE-2024-57278
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in QingScan <=v1.8.0. The vulnerability is caused by improper input sanitization of the query parameter, allowing …

Feb 7, 2025
CVE-2024-55272
7.5 HIGH

An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.

Feb 7, 2025
CVE-2024-55215
9.8 CRITICAL

An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

Feb 7, 2025
CVE-2025-25183
2.6 LOW

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Maliciously constructed statements can lead to hash collisions, resulting in cache reuse, which …

Feb 7, 2025
CVE-2025-24980
5.3 MEDIUM

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via …

Feb 7, 2025
CVE-2021-41528

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited …

Feb 7, 2025
CVE-2021-41527

An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to bypass the 2FA. …

Feb 7, 2025
CVE-2021-27017
6.6 MEDIUM

Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

Feb 7, 2025
CVE-2025-1106
5.4 MEDIUM

A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path …

Feb 7, 2025
CVE-2025-1105
4.3 MEDIUM

A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat …

Feb 7, 2025
CVE-2025-0307

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 7, 2025
CVE-2025-1104
7.3 HIGH

A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by …

Feb 7, 2025
CVE-2024-7425
6.8 MEDIUM

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user …

Feb 7, 2025
CVE-2022-26389
7.7 HIGH

An improper access control vulnerability may allow privilege escalation.This issue affects: * ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; * ELI 280/BUR280/MLBUR 280 Resting …

Feb 7, 2025
CVE-2022-26388
6.4 MEDIUM

A use of hard-coded password vulnerability may allow authentication abuse.This issue affects ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: …

Feb 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.