CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6386
6.5 MEDIUM

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior …

Feb 5, 2025
CVE-2023-52925
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't fail inserts if duplicate has expired nftables selftests fail: run-tests.sh testcases/sets/0044interval_overlap_0 Expected: …

Feb 5, 2025
CVE-2023-52924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between commit/abort and …

Feb 5, 2025
CVE-2024-13829
5.3 MEDIUM

The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Feb 5, 2025
CVE-2025-25246
8.1 HIGH

NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.

Feb 5, 2025
CVE-2025-1026
8.6 HIGH

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in …

Feb 5, 2025
CVE-2025-1025
7.5 HIGH

Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.

Feb 5, 2025
CVE-2025-1022
8.2 HIGH

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by …

Feb 5, 2025
CVE-2025-1028
8.1 HIGH

The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the contact form upload feature in …

Feb 5, 2025
CVE-2025-23114
9.0 CRITICAL

A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to …

Feb 5, 2025
CVE-2025-0413
7.8 HIGH

Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. …

Feb 5, 2025
CVE-2024-53966
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Feb 5, 2025
CVE-2024-53965
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Feb 5, 2025
CVE-2024-53964
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Feb 5, 2025
CVE-2024-53963
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Feb 5, 2025
CVE-2024-53962
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Feb 5, 2025
CVE-2024-48445
9.8 CRITICAL

An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.

Feb 4, 2025
CVE-2024-11468
7.8 HIGH

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue …

Feb 4, 2025
CVE-2024-11467
7.8 HIGH

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers …

Feb 4, 2025
CVE-2023-40222
7.8 HIGH

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could …

Feb 4, 2025
CVE-2023-39943
7.8 HIGH

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing XE files. This could …

Feb 4, 2025
CVE-2024-8125

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. A bad actor with the required OpenText Content …

Feb 4, 2025
CVE-2024-53994
4.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. …

Feb 4, 2025
CVE-2024-53851
4.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enforcing limits on the …

Feb 4, 2025
CVE-2024-53266
4.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activity streams in the …

Feb 4, 2025
CVE-2024-13723
7.2 HIGH

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP …

Feb 4, 2025
CVE-2024-13722
5.4 MEDIUM

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the …

Feb 4, 2025
CVE-2025-23023
8.2 HIGH

Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a request with the right request headers to …

Feb 4, 2025
CVE-2025-22602
6.5 MEDIUM

Discourse is an open source platform for community discussion. In affected versions an attacker can execute arbitrary JavaScript on users' browsers by posting a malicious …

Feb 4, 2025
CVE-2025-22601
3.1 LOW

Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user to make changes to their own …

Feb 4, 2025
CVE-2024-56328
6.5 MEDIUM

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by posting a maliciously crafted onebox url. …

Feb 4, 2025
CVE-2024-56197
2.2 LOW

Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when the "PM tags allowed for …

Feb 4, 2025
CVE-2024-55948
8.2 HIGH

Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache …

Feb 4, 2025
CVE-2024-45658
2.7 LOW

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Feb 4, 2025
CVE-2024-45657
5.0 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.

Feb 4, 2025
CVE-2024-43187
5.9 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed …

Feb 4, 2025
CVE-2024-40700
6.1 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript …

Feb 4, 2025
CVE-2024-35138
6.5 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Feb 4, 2025
CVE-2025-24968
8.8 HIGH

reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tester` or `auditor` to …

Feb 4, 2025
CVE-2025-24967
5.4 MEDIUM

reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker …

Feb 4, 2025
CVE-2025-24966
5.4 MEDIUM

reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers to inject …

Feb 4, 2025
CVE-2025-24964
9.6 CRITICAL

Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API …

Feb 4, 2025
CVE-2025-24963
5.9 MEDIUM

Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. …

Feb 4, 2025
CVE-2025-0960
9.8 CRITICAL

AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause …

Feb 4, 2025
CVE-2025-0630
6.5 MEDIUM

Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged …

Feb 4, 2025
CVE-2025-0509
7.3 HIGH

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing …

Feb 4, 2025
CVE-2025-25039
4.7 MEDIUM

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the …

Feb 4, 2025
CVE-2025-24971

DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in …

Feb 4, 2025
CVE-2025-24373
6.5 MEDIUM

woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerability allows unauthorized …

Feb 4, 2025
CVE-2025-0451
6.3 MEDIUM

Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Feb 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.