CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21283
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 6, 2025
CVE-2025-21279
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 6, 2025
CVE-2025-21267
4.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Feb 6, 2025
CVE-2025-21253
5.3 MEDIUM

Microsoft Edge for IOS and Android Spoofing Vulnerability

Feb 6, 2025
CVE-2025-21177
8.7 HIGH

Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.

Feb 6, 2025
CVE-2025-1083
3.1 LOW

A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. …

Feb 6, 2025
CVE-2025-1082
3.5 LOW

A vulnerability classified as problematic has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected is an unknown function of the file /api/admin/question/edit of the component …

Feb 6, 2025
CVE-2024-57609
8.6 HIGH

An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of …

Feb 6, 2025
CVE-2024-57392
7.5 HIGH

Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the …

Feb 6, 2025
CVE-2024-56889
7.5 HIGH

Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id …

Feb 6, 2025
CVE-2024-55241
8.8 HIGH

An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the modelsbyom.py component.

Feb 6, 2025
CVE-2024-54909
8.1 HIGH

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead …

Feb 6, 2025
CVE-2024-53586
5.3 MEDIUM

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads …

Feb 6, 2025
CVE-2024-48589
6.3 MEDIUM

Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php

Feb 6, 2025
CVE-2024-25883
5.3 MEDIUM

The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.

Feb 6, 2025
CVE-2020-36085
6.3 MEDIUM

Stored Cross Site Scripting(XSS) vulnerability in Egavilan Media Resumes Management and Job Application Website 1.0 allows remote attackers to inject arbitrary code via First and …

Feb 6, 2025
CVE-2025-23094
7.3 HIGH

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and …

Feb 6, 2025
CVE-2025-1081
3.1 LOW

A vulnerability was found in Bharti Airtel Xstream Fiber up to 20250123. It has been rated as problematic. This issue affects some unknown processing of …

Feb 6, 2025
CVE-2025-1004
5.3 MEDIUM

Certain HP LaserJet Pro printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer via IPP …

Feb 6, 2025
CVE-2025-0158
5.5 MEDIUM

IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.

Feb 6, 2025
CVE-2024-56467
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 6, 2025
CVE-2024-54171
7.1 HIGH

IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to …

Feb 6, 2025
CVE-2025-23093
8.8 HIGH

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct …

Feb 6, 2025
CVE-2025-22936
5.7 MEDIUM

An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi …

Feb 6, 2025
CVE-2024-57673
5.5 MEDIUM

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

Feb 6, 2025
CVE-2024-57672
5.5 MEDIUM

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing module.

Feb 6, 2025
CVE-2024-57426
7.3 HIGH

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where …

Feb 6, 2025
CVE-2024-52892
6.1 MEDIUM

IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in …

Feb 6, 2025
CVE-2024-47258
8.1 HIGH

2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N …

Feb 6, 2025
CVE-2024-47256
6.0 MEDIUM

Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to read hardcoded AES passphrase, which may be used …

Feb 6, 2025
CVE-2024-13417
4.6 MEDIUM

Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it gets back to fully working …

Feb 6, 2025
CVE-2025-24787
8.6 HIGH

WhoDB is an open source database management tool. In affected versions the application is vulnerable to parameter injection in database connection strings, which allows an …

Feb 6, 2025
CVE-2025-24786
10.0 CRITICAL

WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal …

Feb 6, 2025
CVE-2025-22992
9.8 CRITICAL

A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input …

Feb 6, 2025
CVE-2024-57668
8.8 HIGH

In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.

Feb 6, 2025
CVE-2024-57523
4.5 MEDIUM

Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests …

Feb 6, 2025
CVE-2024-13416
4.3 MEDIUM

Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has released an updated …

Feb 6, 2025
CVE-2025-24981
9.3 CRITICAL

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the …

Feb 6, 2025
CVE-2025-23217

mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmweb 11.1.1 …

Feb 6, 2025
CVE-2025-22867
7.5 HIGH

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of …

Feb 6, 2025
CVE-2024-57610
7.5 HIGH

A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account …

Feb 6, 2025
CVE-2024-36558
7.5 HIGH

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.

Feb 6, 2025
CVE-2024-36557
6.6 MEDIUM

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious …

Feb 6, 2025
CVE-2024-36556
9.1 CRITICAL

Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hardcoded password vulnerability.

Feb 6, 2025
CVE-2024-36555
9.8 CRITICAL

Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device …

Feb 6, 2025
CVE-2024-36554
9.8 CRITICAL

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending …

Feb 6, 2025
CVE-2024-36553
8.1 HIGH

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.

Feb 6, 2025
CVE-2025-22866
4.0 MEDIUM

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars …

Feb 6, 2025
CVE-2025-1078
5.3 MEDIUM

A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection …

Feb 6, 2025
CVE-2024-57599
4.8 MEDIUM

Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in …

Feb 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.