CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22957
9.8 CRITICAL

A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could …

Jan 31, 2025
CVE-2024-57432
7.5 HIGH

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the …

Jan 31, 2025
CVE-2024-53584
9.8 CRITICAL

OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

Jan 31, 2025
CVE-2024-49349
6.1 MEDIUM

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed …

Jan 31, 2025
CVE-2024-49339
6.4 MEDIUM

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed …

Jan 31, 2025
CVE-2024-47857
9.8 CRITICAL

SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows …

Jan 31, 2025
CVE-2024-42671
6.1 MEDIUM

A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to …

Jan 31, 2025
CVE-2025-23215

PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to …

Jan 31, 2025
CVE-2025-22994
6.1 MEDIUM

O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings.

Jan 31, 2025
CVE-2024-53582
7.5 HIGH

An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via …

Jan 31, 2025
CVE-2024-53537
9.1 CRITICAL

An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

Jan 31, 2025
CVE-2024-53320
9.8 CRITICAL

Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProject functions.

Jan 31, 2025
CVE-2024-53319
7.5 HIGH

A heap buffer overflow in the XML Text Escaping component of Qualisys C++ SDK commit a32a21a allows attackers to cause Denial of Service (DoS) via …

Jan 31, 2025
CVE-2024-49807
6.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to …

Jan 31, 2025
CVE-2024-47116
5.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to …

Jan 31, 2025
CVE-2024-47103
4.8 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to …

Jan 31, 2025
CVE-2024-45089
4.3 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information …

Jan 31, 2025
CVE-2024-40696
4.8 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to …

Jan 31, 2025
CVE-2024-11741
4.3 MEDIUM

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with …

Jan 31, 2025
CVE-2023-38739
4.3 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Jan 31, 2025
CVE-2024-45650
7.5 HIGH

IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.

Jan 31, 2025
CVE-2025-0930
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in TeamCal Neo, version 3.8.2. This allows an attacker to execute malicious JavaScript code, after injecting code via the ‘abs’ parameter …

Jan 31, 2025
CVE-2025-0929
9.8 CRITICAL

SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious …

Jan 31, 2025
CVE-2025-24831
6.6 MEDIUM

Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-24830
6.3 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-24829
6.3 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-24828
6.3 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-24827
6.3 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-21683
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_sk_select_reuseport() memory leak As pointed out in the original comment, lookup in sockmap …

Jan 31, 2025
CVE-2025-21682
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is …

Jan 31, 2025
CVE-2025-21681
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix lockup on tx to unregistering netdev with carrier Commit in a fixes tag …

Jan 31, 2025
CVE-2025-21680
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: pktgen: Avoid out-of-bounds access in get_imix_entries Passing a sufficient amount of imix entries leads to …

Jan 31, 2025
CVE-2025-21679
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: add the missing error handling inside get_canonical_dev_path Inside function get_canonical_dev_path(), we call d_path() to …

Jan 31, 2025
CVE-2025-21678
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gtp: Destroy device along with udp socket's netns dismantle. gtp_newlink() links the device to a …

Jan 31, 2025
CVE-2025-21677
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pfcp: Destroy device along with udp socket's netns dismantle. pfcp_newlink() links the device to a …

Jan 31, 2025
CVE-2025-21676
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: fec: handle page_pool_dev_alloc_pages error The fec_enet_update_cbd function calls page_pool_dev_alloc_pages but did not handle the …

Jan 31, 2025
CVE-2025-21675
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clear port select structure when fail to create Clear the port select structure on …

Jan 31, 2025
CVE-2025-21674
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel Attempt to enable IPsec packet offload …

Jan 31, 2025
CVE-2025-21673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd …

Jan 31, 2025
CVE-2025-21672
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: afs: Fix merge preference rule failure condition syzbot reported a lock held when returning to …

Jan 31, 2025
CVE-2025-21671
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: zram: fix potential UAF of zram table If zram_meta_alloc failed early, it frees allocated zram->table …

Jan 31, 2025
CVE-2025-21670
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock/bpf: return early if transport is not assigned Some of the core functions can only …

Jan 31, 2025
CVE-2025-21669
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been de-assigned or assigned …

Jan 31, 2025
CVE-2025-21668
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: add missing loop break condition Currently imx8mp_blk_ctrl_remove() will continue the for loop until …

Jan 31, 2025
CVE-2025-21667
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iomap: avoid avoid truncating 64-bit offset to 32 bits on 32-bit kernels, iomap_write_delalloc_scan() was inadvertently …

Jan 31, 2025
CVE-2025-21666
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports have shown how we sometimes call vsock_*_has_data() when …

Jan 31, 2025
CVE-2025-21665
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: filemap: avoid truncating 64-bit offset to 32 bits On 32-bit kernels, folio_seek_hole_data() was inadvertently truncating …

Jan 31, 2025
CVE-2024-57948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mac802154: check local interfaces before deleting sdata list syzkaller reported a corrupted list in ieee802154_if_remove. …

Jan 31, 2025
CVE-2024-13662
6.4 MEDIUM

The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_objects_image_grid' shortcode in all versions up to, and …

Jan 31, 2025
CVE-2024-12415
6.5 MEDIUM

The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due …

Jan 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.