CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0806
4.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. …

Jan 29, 2025
CVE-2025-23362
6.1 MEDIUM

The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered …

Jan 29, 2025
CVE-2025-0803
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of …

Jan 29, 2025
CVE-2025-0802
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jan 29, 2025
CVE-2025-0800
2.4 LOW

A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component …

Jan 29, 2025
CVE-2025-0798
8.1 HIGH

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the …

Jan 29, 2025
CVE-2025-0797
3.3 LOW

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects unknown code of the file …

Jan 29, 2025
CVE-2025-0795
3.5 LOW

A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the file /todolistjump.jsp. The manipulation …

Jan 29, 2025
CVE-2023-33838
4.4 MEDIUM

IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but …

Jan 29, 2025
CVE-2025-0794
3.5 LOW

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown functionality of the file /todoDetail.jsp. The …

Jan 29, 2025
CVE-2025-0793
6.3 MEDIUM

A vulnerability has been found in ESAFENET CDG V5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /todoDetail.jsp. …

Jan 29, 2025
CVE-2025-0792
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in ESAFENET CDG V5. Affected is an unknown function of the file /sdTodoDetail.jsp. The manipulation of …

Jan 29, 2025
CVE-2025-0791
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The …

Jan 29, 2025
CVE-2025-0790
3.5 LOW

A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the file /doneDetail.jsp. The manipulation of the argument …

Jan 29, 2025
CVE-2023-35017
5.9 MEDIUM

IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the …

Jan 29, 2025
CVE-2025-0789
6.3 MEDIUM

A vulnerability classified as critical has been found in ESAFENET CDG V5. This affects an unknown part of the file /doneDetail.jsp. The manipulation of the …

Jan 28, 2025
CVE-2025-0788
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Jan 28, 2025
CVE-2024-57519
7.5 HIGH

An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.

Jan 28, 2025
CVE-2024-56529
7.1 HIGH

Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled …

Jan 28, 2025
CVE-2024-48310
7.5 HIGH

AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers may use these keys to access the …

Jan 28, 2025
CVE-2025-22917
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a …

Jan 28, 2025
CVE-2025-0787
3.5 LOW

A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Jan 28, 2025
CVE-2025-0786
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG V5. It has been classified as critical. Affected is an unknown function of the file /appDetail.jsp. The manipulation …

Jan 28, 2025
CVE-2025-0785
3.5 LOW

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing of the file /SysConfig.jsp. The manipulation of …

Jan 28, 2025
CVE-2024-57514
4.8 MEDIUM

The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When …

Jan 28, 2025
CVE-2024-57376
8.8 HIGH

Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.

Jan 28, 2025
CVE-2024-55968
8.8 HIGH

An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handling privileged operations within the macOS DTEX Event Forwarder agent, …

Jan 28, 2025
CVE-2024-29869
5.5 MEDIUM

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set …

Jan 28, 2025
CVE-2025-24826
6.7 MEDIUM

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.

Jan 28, 2025
CVE-2025-24482

A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs …

Jan 28, 2025
CVE-2025-24481

An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote …

Jan 28, 2025
CVE-2025-0784
3.7 LOW

A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of …

Jan 28, 2025
CVE-2024-40677
8.4 HIGH

In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local …

Jan 28, 2025
CVE-2024-40676
7.7 HIGH

In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This …

Jan 28, 2025
CVE-2024-40675
7.5 HIGH

In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no …

Jan 28, 2025
CVE-2024-40674
5.3 MEDIUM

In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could …

Jan 28, 2025
CVE-2024-40673
6.5 MEDIUM

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input …

Jan 28, 2025
CVE-2024-40672
8.4 HIGH

In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local …

Jan 28, 2025
CVE-2024-40670
8.4 HIGH

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with …

Jan 28, 2025
CVE-2024-40669
8.4 HIGH

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with …

Jan 28, 2025
CVE-2024-40651
8.4 HIGH

In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege …

Jan 28, 2025
CVE-2024-40649
8.4 HIGH

In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege …

Jan 28, 2025
CVE-2024-34748
8.4 HIGH

In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with …

Jan 28, 2025
CVE-2024-34733
8.4 HIGH

In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in …

Jan 28, 2025
CVE-2024-34732
8.4 HIGH

In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in …

Jan 28, 2025
CVE-2025-24480

A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could allow …

Jan 28, 2025
CVE-2025-24479

A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows …

Jan 28, 2025
CVE-2025-24478

A denial-of-service vulnerability exists in the affected products. The vulnerability could allow a remote, non-privileged user to send malicious requests resulting in a major nonrecoverable …

Jan 28, 2025
CVE-2025-22217
8.6 HIGH

Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected …

Jan 28, 2025
CVE-2025-0783
6.3 MEDIUM

A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component API Endpoint. …

Jan 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.