CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49792
5.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025
CVE-2024-49791
6.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025
CVE-2024-56473
5.3 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper …

Feb 5, 2025
CVE-2024-56472
6.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the …

Feb 5, 2025
CVE-2024-56471
5.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from …

Feb 5, 2025
CVE-2024-56470
5.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from …

Feb 5, 2025
CVE-2024-38318
4.8 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Feb 5, 2025
CVE-2024-38317
4.8 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the …

Feb 5, 2025
CVE-2024-38316
4.3 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in …

Feb 5, 2025
CVE-2024-57699
7.5 HIGH

A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a …

Feb 5, 2025
CVE-2024-57598
6.5 MEDIUM

A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial …

Feb 5, 2025
CVE-2024-57520
9.8 CRITICAL

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier …

Feb 5, 2025
CVE-2024-57086
7.5 HIGH

A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57085
7.5 HIGH

A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57084
7.5 HIGH

A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57082
6.5 MEDIUM

A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57081
7.5 HIGH

A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57080
7.5 HIGH

A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57079
7.5 HIGH

A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57078
7.5 HIGH

A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57077
9.1 CRITICAL

The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter …

Feb 5, 2025
CVE-2024-57076
7.5 HIGH

A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57075
7.5 HIGH

A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57074
7.5 HIGH

A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57072
7.5 HIGH

A prototype pollution in the lib.requireFromString function of module-from-string v3.3.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57071
7.5 HIGH

A prototype pollution in the lib.combine function of php-parser v3.2.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57069
7.5 HIGH

A prototype pollution in the lib function of expand-object v0.4.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57068
7.5 HIGH

A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57067
7.5 HIGH

A prototype pollution in the lib.parse function of dot-qs v0.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57066
7.5 HIGH

A prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57065
7.5 HIGH

A prototype pollution in the lib.createPath function of utile v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-57064
7.5 HIGH

A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. NOTE: …

Feb 5, 2025
CVE-2024-57063
7.5 HIGH

A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-54853
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads …

Feb 5, 2025
CVE-2024-48394
7.8 HIGH

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit …

Feb 5, 2025
CVE-2020-36084
9.8 CRITICAL

SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.

Feb 5, 2025
CVE-2025-24805
5.5 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is …

Feb 5, 2025
CVE-2025-24804
4.3 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, …

Feb 5, 2025
CVE-2025-24803
5.4 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, …

Feb 5, 2025
CVE-2025-24372
7.3 HIGH

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted file, a user could potentially upload …

Feb 5, 2025
CVE-2025-24497
7.5 HIGH

When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical …

Feb 5, 2025
CVE-2025-24326
7.5 HIGH

When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization. Note: Software versions …

Feb 5, 2025
CVE-2025-24320
8.0 HIGH

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the …

Feb 5, 2025
CVE-2025-24319
6.5 MEDIUM

When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes …

Feb 5, 2025
CVE-2025-24312
7.5 HIGH

When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed …

Feb 5, 2025
CVE-2025-23419
4.3 MEDIUM

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication …

Feb 5, 2025
CVE-2025-23415
3.1 LOW

An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks …

Feb 5, 2025
CVE-2025-23413
4.4 MEDIUM

When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. …

Feb 5, 2025
CVE-2025-23412
7.5 HIGH

When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached End …

Feb 5, 2025
CVE-2025-23239
8.7 HIGH

When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A …

Feb 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.