CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0136
7.6 HIGH

NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to …

Jan 28, 2025
CVE-2024-0135
7.6 HIGH

NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit …

Jan 28, 2025
CVE-2025-22865
7.5 HIGH

Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.

Jan 28, 2025
CVE-2024-45341
6.1 MEDIUM

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the …

Jan 28, 2025
CVE-2024-45340
8.8 HIGH

Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have …

Jan 28, 2025
CVE-2024-45339
7.1 HIGH

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic …

Jan 28, 2025
CVE-2024-45336
6.1 MEDIUM

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to …

Jan 28, 2025
CVE-2024-22315
4.0 MEDIUM

IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion …

Jan 28, 2025
CVE-2024-27263
5.3 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using …

Jan 28, 2025
CVE-2024-12649
9.8 CRITICAL

Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to …

Jan 28, 2025
CVE-2024-12648
9.8 CRITICAL

Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment …

Jan 28, 2025
CVE-2024-12647
9.8 CRITICAL

Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to …

Jan 28, 2025
CVE-2023-50316
6.3 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …

Jan 28, 2025
CVE-2022-3365
9.8 CRITICAL

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a …

Jan 28, 2025
CVE-2024-28786
6.5 MEDIUM

IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man …

Jan 28, 2025
CVE-2022-31749
6.5 MEDIUM

An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker …

Jan 28, 2025
CVE-2025-24369

Anubis is a tool that allows administrators to protect bots against AI scrapers through bot-checking heuristics and a proof-of-work challenge to discourage scraping from multiple …

Jan 27, 2025
CVE-2024-57549
7.5 HIGH

CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.

Jan 27, 2025
CVE-2024-57548
9.1 CRITICAL

CMSimple 5.16 allows the user to edit log.php file via print page.

Jan 27, 2025
CVE-2024-57547
7.5 HIGH

Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup …

Jan 27, 2025
CVE-2024-57546
7.5 HIGH

An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.

Jan 27, 2025
CVE-2024-57373
8.1 HIGH

Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading …

Jan 27, 2025
CVE-2024-57052
9.8 CRITICAL

An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.

Jan 27, 2025
CVE-2024-56316
7.5 HIGH

In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenticated attackers to cause a permanent Denial of …

Jan 27, 2025
CVE-2024-56178
6.5 MEDIUM

An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that …

Jan 27, 2025
CVE-2024-54728
6.5 MEDIUM

Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs.

Jan 27, 2025
CVE-2024-48662
6.1 MEDIUM

Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix …

Jan 27, 2025
CVE-2025-24177
7.5 HIGH

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, …

Jan 27, 2025
CVE-2025-24176
7.1 HIGH

A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker …

Jan 27, 2025
CVE-2025-24174
7.7 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be …

Jan 27, 2025
CVE-2025-24169
7.5 HIGH

A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able …

Jan 27, 2025
CVE-2025-24166

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 27, 2025
CVE-2025-24163
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS …

Jan 27, 2025
CVE-2025-24162
6.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, …

Jan 27, 2025
CVE-2025-24161
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, …

Jan 27, 2025
CVE-2025-24160
4.3 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, …

Jan 27, 2025
CVE-2025-24159
7.8 HIGH

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma …

Jan 27, 2025
CVE-2025-24158
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, …

Jan 27, 2025
CVE-2025-24156
7.8 HIGH

An integer overflow was addressed through improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app …

Jan 27, 2025
CVE-2025-24154
9.1 CRITICAL

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3, …

Jan 27, 2025
CVE-2025-24153
6.7 MEDIUM

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be …

Jan 27, 2025
CVE-2025-24152
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app may be able to cause unexpected system …

Jan 27, 2025
CVE-2025-24151
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may …

Jan 27, 2025
CVE-2025-24150
8.8 HIGH

A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. …

Jan 27, 2025
CVE-2025-24149
5.5 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS …

Jan 27, 2025
CVE-2025-24146
9.8 CRITICAL

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Deleting …

Jan 27, 2025
CVE-2025-24145
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia …

Jan 27, 2025
CVE-2025-24143
6.5 MEDIUM

The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS …

Jan 27, 2025
CVE-2025-24141
3.3 LOW

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to …

Jan 27, 2025
CVE-2025-24140
5.3 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not have the …

Jan 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.