CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13328
6.1 MEDIUM

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 4, 2025
CVE-2024-13327
6.1 MEDIUM

The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 4, 2025
CVE-2024-13326
6.1 MEDIUM

The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 4, 2025
CVE-2024-13325
6.1 MEDIUM

The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 4, 2025
CVE-2024-13115
6.1 MEDIUM

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well …

Feb 4, 2025
CVE-2024-13114
6.1 MEDIUM

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, …

Feb 4, 2025
CVE-2025-24982
4.3 MEDIUM

Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log …

Feb 4, 2025
CVE-2025-22475
3.7 LOW

Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote …

Feb 4, 2025
CVE-2025-1003

A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass which may result in escalation of privilege. …

Feb 4, 2025
CVE-2025-0148
2.6 LOW

Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via …

Feb 3, 2025
CVE-2025-24958
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_tag.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24957
9.8 CRITICAL

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_detalhes_socio.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24906
9.8 CRITICAL

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_detalhes_cobranca.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24905
9.8 CRITICAL

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_codigobarras_cobranca.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24902
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_cargo.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24901
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_permissao.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24371

CometBFT is a distributed, Byzantine fault-tolerant, deterministic state machine replication engine. In the `blocksync` protocol peers send their `base` and `latest` heights when they connect …

Feb 3, 2025
CVE-2025-24029
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the …

Feb 3, 2025
CVE-2025-23210

phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting …

Feb 3, 2025
CVE-2025-22129
4.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted …

Feb 3, 2025
CVE-2024-47770
4.6 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, …

Feb 3, 2025
CVE-2024-35177
7.8 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, …

Feb 3, 2025
CVE-2025-24962
8.8 HIGH

reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been …

Feb 3, 2025
CVE-2025-24961

org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to users. This …

Feb 3, 2025
CVE-2025-24960
8.7 HIGH

Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This …

Feb 3, 2025
CVE-2025-24959

zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended environment variables into `process.env`. This can …

Feb 3, 2025
CVE-2025-24899
7.5 HIGH

reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, …

Feb 3, 2025
CVE-2025-24370

Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are vulnerable to python class pollution vulnerability. The vulnerability arises from the …

Feb 3, 2025
CVE-2025-22918
7.5 HIGH

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage …

Feb 3, 2025
CVE-2024-57451
7.5 HIGH

ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory.

Feb 3, 2025
CVE-2024-56903
8.1 HIGH

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. …

Feb 3, 2025
CVE-2024-56902
7.5 HIGH

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

Feb 3, 2025
CVE-2024-56901
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via …

Feb 3, 2025
CVE-2024-56898
8.8 HIGH

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, …

Feb 3, 2025
CVE-2024-44449
6.1 MEDIUM

Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive information via the msg parameter in the Login page.

Feb 3, 2025
CVE-2024-34897
7.5 HIGH

Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

Feb 3, 2025
CVE-2024-34896
7.5 HIGH

An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device …

Feb 3, 2025
CVE-2023-52164
5.1 MEDIUM

access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Feb 3, 2025
CVE-2023-52163
8.8 HIGH KEV

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Feb 3, 2025
CVE-2025-25181
5.8 MEDIUM KEV

A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

Feb 3, 2025
CVE-2025-25065
5.3 MEDIUM

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to …

Feb 3, 2025
CVE-2025-25064
8.8 HIGH

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a …

Feb 3, 2025
CVE-2025-22978
9.8 CRITICAL

eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.

Feb 3, 2025
CVE-2024-57968
9.9 CRITICAL KEV

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). …

Feb 3, 2025
CVE-2024-57669
7.5 HIGH

Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupController.java file.

Feb 3, 2025
CVE-2024-57498
4.8 MEDIUM

Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.

Feb 3, 2025
CVE-2024-57452
7.5 HIGH

ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

Feb 3, 2025
CVE-2024-57450
9.8 CRITICAL

ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.

Feb 3, 2025
CVE-2024-57099
9.8 CRITICAL

ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, …

Feb 3, 2025
CVE-2024-57098
9.8 CRITICAL

Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.

Feb 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.