CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21497
5.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 …

Jan 21, 2025
CVE-2025-21495
4.4 MEDIUM

Vulnerability in the MySQL Enterprise Firewall product of Oracle MySQL (component: Firewall). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and …

Jan 21, 2025
CVE-2025-21494
4.1 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior …

Jan 21, 2025
CVE-2025-21493
4.4 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.4.3 and prior and 9.1.0 and …

Jan 21, 2025
CVE-2025-21492
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable …

Jan 21, 2025
CVE-2025-21491
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 …

Jan 21, 2025
CVE-2025-21490
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 …

Jan 21, 2025
CVE-2025-21489
6.1 MEDIUM

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability …

Jan 21, 2025
CVE-2024-57545
5.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57544
5.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57543
5.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57542
8.8 HIGH

Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.

Jan 21, 2025
CVE-2024-57541
5.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57540
6.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57539
8.2 HIGH

Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.

Jan 21, 2025
CVE-2024-57538
6.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_protect_status) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57537
6.3 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57536
8.0 HIGH

Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.

Jan 21, 2025
CVE-2024-57360
5.5 MEDIUM

https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.

Jan 21, 2025
CVE-2024-55959
9.1 CRITICAL

Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.

Jan 21, 2025
CVE-2024-55958
4.8 MEDIUM

Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.

Jan 21, 2025
CVE-2024-48392
5.4 MEDIUM

OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, …

Jan 21, 2025
CVE-2024-21245
5.4 MEDIUM

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to …

Jan 21, 2025
CVE-2025-24024
9.1 CRITICAL

Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member of. This can allow users …

Jan 21, 2025
CVE-2024-42936
9.8 CRITICAL

The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.

Jan 21, 2025
CVE-2023-45908
6.1 MEDIUM

Homarr before v0.14.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notebook widget.

Jan 21, 2025
CVE-2025-23369
8.8 HIGH

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML …

Jan 21, 2025
CVE-2024-55504
5.5 MEDIUM

An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized …

Jan 21, 2025
CVE-2024-51417
6.4 MEDIUM

An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static properties/fields.

Jan 21, 2025
CVE-2025-24461
6.5 MEDIUM

In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint

Jan 21, 2025
CVE-2025-24460
4.3 MEDIUM

In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool

Jan 21, 2025
CVE-2025-24459
4.6 MEDIUM

In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page

Jan 21, 2025
CVE-2025-24458
7.1 HIGH

In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

Jan 21, 2025
CVE-2025-24457
5.5 MEDIUM

In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs

Jan 21, 2025
CVE-2025-24456
6.7 MEDIUM

In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

Jan 21, 2025
CVE-2025-24020
6.1 MEDIUM

WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` endpoint of versions up to and including 3.2.10 …

Jan 21, 2025
CVE-2025-24019
7.1 HIGH

YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use …

Jan 21, 2025
CVE-2025-23996
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in AnyRoad AnyRoad anyguide allows Cross Site Request Forgery.This issue affects AnyRoad: from n/a through <= 1.3.2.

Jan 21, 2025
CVE-2025-23994
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatebud Estatebud – Properties & Listings estatebud-properties-listings allows Stored XSS.This issue affects Estatebud …

Jan 21, 2025
CVE-2025-23580
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew BizLibrary bizlibrary allows Reflected XSS.This issue affects BizLibrary: from n/a through <= …

Jan 21, 2025
CVE-2025-23551
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in razvypp SexBundle sexbundle allows Reflected XSS.This issue affects SexBundle: from n/a through <= …

Jan 21, 2025
CVE-2025-23489
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Messenlehner WP-Announcements wp-announcements allows Reflected XSS.This issue affects WP-Announcements: from n/a through …

Jan 21, 2025
CVE-2025-23477
8.2 HIGH

Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Realty Workstation: from n/a through <= 1.0.45.

Jan 21, 2025
CVE-2025-23461
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xkollsoftware Social2Blog social2blog allows Reflected XSS.This issue affects Social2Blog: from n/a through <= …

Jan 21, 2025
CVE-2025-23454
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flashmaniac Nature FlipBook vertical-diamond-flipbook-flash allows Reflected XSS.This issue affects Nature FlipBook: from n/a …

Jan 21, 2025
CVE-2025-22722
4.3 MEDIUM

Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= …

Jan 21, 2025
CVE-2025-22721
4.3 MEDIUM

Missing Authorization vulnerability in Farhan Noor ApplyOnline apply-online allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline: from n/a through <= 2.6.7.1.

Jan 21, 2025
CVE-2025-22661
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payments – Get Paid with PayPal, Square & Stripe paypal-payment-button-by-vcita allows …

Jan 21, 2025
CVE-2025-22276
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enguerranws Related Post Shortcode related-post-shortcode allows Stored XSS.This issue affects Related Post Shortcode: …

Jan 21, 2025
CVE-2025-22267
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweaver Weaver Themes Shortcode Compatibility weaver-themes-shortcode-compatibility allows Stored XSS.This issue affects Weaver Themes …

Jan 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.