CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57510
7.8 HIGH

Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.

Jan 29, 2025
CVE-2024-57509
7.8 HIGH

Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions.

Jan 29, 2025
CVE-2024-57395
9.8 CRITICAL

Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the …

Jan 29, 2025
CVE-2024-54852
9.8 CRITICAL

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due …

Jan 29, 2025
CVE-2024-54851
8.8 HIGH

Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.

Jan 29, 2025
CVE-2024-51182
6.1 MEDIUM

HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML code via the "erro" parameter.

Jan 29, 2025
CVE-2024-48761
8.8 HIGH

Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.

Jan 29, 2025
CVE-2024-23733
7.5 HIGH

The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover …

Jan 29, 2025
CVE-2024-12705
7.5 HIGH

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects …

Jan 29, 2025
CVE-2024-11187
7.5 HIGH

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker …

Jan 29, 2025
CVE-2025-24884

kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the …

Jan 29, 2025
CVE-2025-24795
4.4 MEDIUM

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and …

Jan 29, 2025
CVE-2025-24794
6.7 MEDIUM

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and …

Jan 29, 2025
CVE-2025-24793
7.0 HIGH

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and …

Jan 29, 2025
CVE-2025-24788
5.0 MEDIUM

snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages …

Jan 29, 2025
CVE-2025-0841
7.3 HIGH

A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the …

Jan 29, 2025
CVE-2025-20061
9.8 CRITICAL

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to …

Jan 29, 2025
CVE-2025-20014
9.8 CRITICAL

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to …

Jan 29, 2025
CVE-2025-0840
5.0 MEDIUM

A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The …

Jan 29, 2025
CVE-2024-48852
9.4 CRITICAL

Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through …

Jan 29, 2025
CVE-2024-48849
9.4 CRITICAL

Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.

Jan 29, 2025
CVE-2024-10001
7.1 HIGH

A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property …

Jan 29, 2025
CVE-2025-24882
5.2 MEDIUM

regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This …

Jan 29, 2025
CVE-2025-24790
4.4 MEDIUM

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability …

Jan 29, 2025
CVE-2025-24789
7.8 HIGH

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability …

Jan 29, 2025
CVE-2025-24791
4.4 MEDIUM

snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential …

Jan 29, 2025
CVE-2025-24527
8.0 HIGH

An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug …

Jan 29, 2025
CVE-2023-37413
5.3 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.

Jan 29, 2025
CVE-2023-37412
4.4 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.

Jan 29, 2025
CVE-2023-37398
5.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise …

Jan 29, 2025
CVE-2023-35907
5.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise …

Jan 29, 2025
CVE-2025-24792
4.4 MEDIUM

Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated …

Jan 29, 2025
CVE-2025-24374
4.3 MEDIUM

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the …

Jan 29, 2025
CVE-2024-57439
4.9 MEDIUM

An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the …

Jan 29, 2025
CVE-2024-57438
5.4 MEDIUM

Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.

Jan 29, 2025
CVE-2024-57437
6.5 MEDIUM

RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.

Jan 29, 2025
CVE-2024-57436
7.2 HIGH

RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers …

Jan 29, 2025
CVE-2025-0353
6.4 MEDIUM

The Divi Torque Lite – Best Divi Addon, Extensions, Modules & Social Modules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets …

Jan 29, 2025
CVE-2024-54462
7.1 HIGH

The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user …

Jan 29, 2025
CVE-2024-54461
7.1 HIGH

The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user …

Jan 29, 2025
CVE-2024-41140
8.1 HIGH

Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

Jan 29, 2025
CVE-2024-13561
6.4 MEDIUM

The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_override_yt shortcode in all versions up to, and …

Jan 29, 2025
CVE-2025-0762
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. …

Jan 29, 2025
CVE-2025-0617
5.9 MEDIUM

An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger …

Jan 29, 2025
CVE-2021-3978
7.5 HIGH

When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since …

Jan 29, 2025
CVE-2024-57965
0.0 NONE

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties …

Jan 29, 2025
CVE-2024-7695
7.5 HIGH

Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient input validation, which allows data to be written to memory …

Jan 29, 2025
CVE-2024-13696
7.2 HIGH

The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wishlist_name’ parameter …

Jan 29, 2025
CVE-2024-12749
7.1 HIGH

The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 29, 2025
CVE-2025-0804
6.4 MEDIUM

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.