CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57430
9.8 CRITICAL

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting …

Feb 6, 2025
CVE-2024-57429
5.4 MEDIUM

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an …

Feb 6, 2025
CVE-2024-57428
9.3 CRITICAL

A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat …

Feb 6, 2025
CVE-2024-57427
6.1 MEDIUM

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a …

Feb 6, 2025
CVE-2024-43779
7.7 HIGH

An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults …

Feb 6, 2025
CVE-2024-39272
9.0 CRITICAL

A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an …

Feb 6, 2025
CVE-2024-39033
7.5 HIGH

In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.

Feb 6, 2025
CVE-2024-13614
5.3 MEDIUM

Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small …

Feb 6, 2025
CVE-2022-40916
9.8 CRITICAL

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

Feb 6, 2025
CVE-2022-40490
4.8 MEDIUM

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via …

Feb 6, 2025
CVE-2025-0994
8.8 HIGH KEV

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an …

Feb 6, 2025
CVE-2023-5878

Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who …

Feb 6, 2025
CVE-2022-31764
8.5 HIGH

The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects …

Feb 6, 2025
CVE-2025-1076
4.8 MEDIUM

A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload …

Feb 6, 2025
CVE-2025-1074
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component …

Feb 6, 2025
CVE-2024-24911
5.3 MEDIUM

In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the …

Feb 6, 2025
CVE-2024-57962
6.1 MEDIUM

Vulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this vulnerability may affect availability.

Feb 6, 2025
CVE-2024-57961
6.8 MEDIUM

Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57960
7.7 HIGH

Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-57959
6.1 MEDIUM

Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57958
5.7 MEDIUM

Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57957
6.6 MEDIUM

Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-57956
2.8 LOW

Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.

Feb 6, 2025
CVE-2024-57955
6.1 MEDIUM

Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-57954
6.2 MEDIUM

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-12602
6.2 MEDIUM

Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2025-0982
10.0 CRITICAL

Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed …

Feb 6, 2025
CVE-2024-45626
6.5 MEDIUM

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in …

Feb 6, 2025
CVE-2024-37358
8.6 HIGH

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could …

Feb 6, 2025
CVE-2025-0859
6.5 MEDIUM

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up …

Feb 6, 2025
CVE-2025-24845
5.5 MEDIUM

Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially …

Feb 6, 2025
CVE-2025-24483
5.5 MEDIUM

NULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of …

Feb 6, 2025
CVE-2025-23236
8.8 HIGH

Buffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege of the Windows system …

Feb 6, 2025
CVE-2025-22894
8.8 HIGH

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the …

Feb 6, 2025
CVE-2025-20094
8.8 HIGH

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the …

Feb 6, 2025
CVE-2025-22890
8.8 HIGH

Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege of the …

Feb 6, 2025
CVE-2024-13487
7.3 HIGH

The The CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooCommerce 9.x plugin for WordPress is …

Feb 6, 2025
CVE-2025-0522
4.7 MEDIUM

The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Feb 6, 2025
CVE-2024-51547
9.8 CRITICAL

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: …

Feb 6, 2025
CVE-2025-0799
6.5 MEDIUM

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system …

Feb 6, 2025
CVE-2024-51450
9.1 CRITICAL

IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted …

Feb 6, 2025
CVE-2024-49814
7.8 HIGH

IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.

Feb 6, 2025
CVE-2025-1066
9.8 CRITICAL

OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.

Feb 6, 2025
CVE-2024-49800
4.3 MEDIUM

IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

Feb 6, 2025
CVE-2024-49798
4.3 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information …

Feb 6, 2025
CVE-2024-49797
5.9 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker …

Feb 6, 2025
CVE-2024-49796
5.4 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web …

Feb 6, 2025
CVE-2024-49795
4.3 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that …

Feb 6, 2025
CVE-2024-49794
4.3 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that …

Feb 6, 2025
CVE-2024-49793
5.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.