CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0631

A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear …

Jan 28, 2025
CVE-2025-23057
5.5 MEDIUM

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting …

Jan 28, 2025
CVE-2025-23056
5.5 MEDIUM

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting …

Jan 28, 2025
CVE-2025-23055
5.5 MEDIUM

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting …

Jan 28, 2025
CVE-2025-23054
6.5 MEDIUM

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not …

Jan 28, 2025
CVE-2025-23053
6.5 MEDIUM

A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator …

Jan 28, 2025
CVE-2024-13484
8.2 HIGH

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create …

Jan 28, 2025
CVE-2025-0781
8.6 HIGH

An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the …

Jan 28, 2025
CVE-2024-8401
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the …

Jan 28, 2025
CVE-2018-9378
6.2 MEDIUM

In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Jan 28, 2025
CVE-2018-9373
8.8 HIGH

In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to …

Jan 28, 2025
CVE-2017-13318
5.7 MEDIUM

In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with …

Jan 28, 2025
CVE-2017-13317
5.7 MEDIUM

In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with …

Jan 28, 2025
CVE-2025-24800

Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince …

Jan 28, 2025
CVE-2025-23385
7.8 HIGH

In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, …

Jan 28, 2025
CVE-2025-23213
8.7 HIGH

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html …

Jan 28, 2025
CVE-2025-23212
7.7 HIGH

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name …

Jan 28, 2025
CVE-2025-23211
9.9 CRITICAL

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on …

Jan 28, 2025
CVE-2025-23045
9.8 CRITICAL

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT …

Jan 28, 2025
CVE-2025-0659

A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable …

Jan 28, 2025
CVE-2025-0432
5.7 MEDIUM

EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.

Jan 28, 2025
CVE-2024-7881
5.1 MEDIUM

An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address …

Jan 28, 2025
CVE-2024-6351
4.3 MEDIUM

A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert

Jan 28, 2025
CVE-2024-11956
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of …

Jan 28, 2025
CVE-2024-11954
2.4 LOW

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation …

Jan 28, 2025
CVE-2025-0065
7.8 HIGH

Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior version 15.62 for Windows allows an attacker with local unprivileged access on …

Jan 28, 2025
CVE-2025-0754
4.3 MEDIUM

The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the …

Jan 28, 2025
CVE-2025-0752
7.1 HIGH

A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible …

Jan 28, 2025
CVE-2025-0750
6.6 MEDIUM

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to …

Jan 28, 2025
CVE-2025-0736
5.5 MEDIUM

A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details …

Jan 28, 2025
CVE-2025-0290
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 …

Jan 28, 2025
CVE-2024-23953
6.5 MEDIUM

Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by …

Jan 28, 2025
CVE-2024-13527
6.4 MEDIUM

The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions …

Jan 28, 2025
CVE-2025-0321
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.7.8 …

Jan 28, 2025
CVE-2024-13521
6.1 MEDIUM

The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to …

Jan 28, 2025
CVE-2024-13509
7.2 HIGH

The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in all versions up to, and …

Jan 28, 2025
CVE-2024-13448
9.8 CRITICAL

The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions …

Jan 28, 2025
CVE-2024-12807
4.8 MEDIUM

The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 28, 2025
CVE-2024-12723
6.1 MEDIUM

The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 28, 2025
CVE-2025-24810
4.8 MEDIUM

Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web …

Jan 28, 2025
CVE-2025-23084
5.5 MEDIUM

A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive …

Jan 28, 2025
CVE-2024-11135
7.5 HIGH

The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees' function in all versions up to, and including, …

Jan 28, 2025
CVE-2024-53881
5.5 MEDIUM

NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm on the host, which …

Jan 28, 2025
CVE-2024-53869
5.5 MEDIUM

NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A successful exploit of this vulnerability might lead to …

Jan 28, 2025
CVE-2024-0150
7.1 HIGH

NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before the beginning of a buffer. …

Jan 28, 2025
CVE-2024-0149
3.3 LOW

NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files. A successful exploit of this vulnerability might …

Jan 28, 2025
CVE-2024-0147
5.5 MEDIUM

NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been freed can lead to denial of service …

Jan 28, 2025
CVE-2024-0146
7.8 HIGH

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory corruption. A successful exploit of this vulnerability …

Jan 28, 2025
CVE-2024-0140
6.8 MEDIUM

NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data issue. A successful exploit of this …

Jan 28, 2025
CVE-2024-0137
5.5 MEDIUM

NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. …

Jan 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.