CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24886
7.7 HIGH

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows …

Jan 30, 2025
CVE-2025-24885
7.6 HIGH

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rendering custom (unprivileged) dojo …

Jan 30, 2025
CVE-2025-0882
6.3 MEDIUM

A vulnerability was found in code-projects Chat System up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 30, 2025
CVE-2025-0881
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/saveroutine.php. …

Jan 30, 2025
CVE-2025-0880
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/updateplan.php. The …

Jan 30, 2025
CVE-2025-0574
7.5 HIGH

Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS …

Jan 30, 2025
CVE-2025-0573
5.3 MEDIUM

Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of …

Jan 30, 2025
CVE-2025-0572
4.3 MEDIUM

Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected …

Jan 30, 2025
CVE-2025-0571
6.5 MEDIUM

Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations …

Jan 30, 2025
CVE-2025-0570
6.5 MEDIUM

Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations …

Jan 30, 2025
CVE-2025-0569
7.5 HIGH

Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante …

Jan 30, 2025
CVE-2025-0568
7.5 HIGH

Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante …

Jan 30, 2025
CVE-2024-11611
7.8 HIGH

AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jan 30, 2025
CVE-2024-11610
7.8 HIGH

AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jan 30, 2025
CVE-2024-11609
7.8 HIGH

AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Jan 30, 2025
CVE-2025-24802
8.6 HIGH

Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not divisible by 26 = floor(num_routed_wires / 3) …

Jan 30, 2025
CVE-2025-0147
8.8 HIGH

Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.

Jan 30, 2025
CVE-2025-0146
3.9 LOW

Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via …

Jan 30, 2025
CVE-2025-0145
4.6 MEDIUM

Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via …

Jan 30, 2025
CVE-2025-0144
3.1 LOW

Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.

Jan 30, 2025
CVE-2025-0143
4.3 MEDIUM

Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network …

Jan 30, 2025
CVE-2025-0142
4.3 MEDIUM

Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information …

Jan 30, 2025
CVE-2024-10604
5.3 MEDIUM

Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and …

Jan 30, 2025
CVE-2024-10603
5.3 MEDIUM

Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker …

Jan 30, 2025
CVE-2024-10026
5.3 MEDIUM

A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a …

Jan 30, 2025
CVE-2025-24507

This vulnerability allows appliance compromise at boot time.

Jan 30, 2025
CVE-2025-24506

A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.

Jan 30, 2025
CVE-2025-24505

This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.

Jan 30, 2025
CVE-2025-24504

An improper input validation the CSRF filter results in unsanitized user input written to the application logs.

Jan 30, 2025
CVE-2025-24503

A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM …

Jan 30, 2025
CVE-2025-24502

An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing …

Jan 30, 2025
CVE-2025-24501

An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.

Jan 30, 2025
CVE-2025-24500

The vulnerability allows an unauthenticated attacker to access information in PAM database.

Jan 30, 2025
CVE-2025-0683
5.9 MEDIUM

In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up …

Jan 30, 2025
CVE-2025-0681
6.2 MEDIUM

The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service …

Jan 30, 2025
CVE-2025-0680
9.8 CRITICAL

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected …

Jan 30, 2025
CVE-2025-0626
7.5 HIGH

The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to …

Jan 30, 2025
CVE-2024-44142
7.8 HIGH

The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code …

Jan 30, 2025
CVE-2024-12248
9.8 CRITICAL

Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to …

Jan 30, 2025
CVE-2025-0874
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Simple Plugins Car Rental Management 1.0. Affected by this issue is some unknown …

Jan 30, 2025
CVE-2025-0498
9.8 CRITICAL

A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® …

Jan 30, 2025
CVE-2025-0497
9.8 CRITICAL

A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the …

Jan 30, 2025
CVE-2025-0477
9.8 CRITICAL

An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and …

Jan 30, 2025
CVE-2023-29080

Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript …

Jan 30, 2025
CVE-2025-24099
5.1 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker may …

Jan 30, 2025
CVE-2025-0873
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. …

Jan 30, 2025
CVE-2025-0367
6.5 MEDIUM

In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to …

Jan 30, 2025
CVE-2024-2658

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An …

Jan 30, 2025
CVE-2025-24883

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. …

Jan 30, 2025
CVE-2025-24784
4.3 MEDIUM

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. By …

Jan 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.