CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22349
4.0 MEDIUM

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another …

Jan 20, 2025
CVE-2024-22348
5.3 MEDIUM

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out …

Jan 20, 2025
CVE-2024-22347
5.9 MEDIUM

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt …

Jan 20, 2025
CVE-2025-23221
5.4 MEDIUM

Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. This vulnerability allows a user to maneuver the Webfinger …

Jan 20, 2025
CVE-2025-24013
5.3 MEDIUM

CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential attacker can construct …

Jan 20, 2025
CVE-2025-24010
6.5 MEDIUM

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due …

Jan 20, 2025
CVE-2025-23220
9.8 CRITICAL

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the …

Jan 20, 2025
CVE-2025-23219
9.8 CRITICAL

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the …

Jan 20, 2025
CVE-2025-23218
9.8 CRITICAL

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the …

Jan 20, 2025
CVE-2025-23044
6.8 MEDIUM

PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This …

Jan 20, 2025
CVE-2025-22620
5.0 MEDIUM

gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask …

Jan 20, 2025
CVE-2025-22131
6.1 MEDIUM

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a …

Jan 20, 2025
CVE-2024-51738
8.1 HIGH

Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby …

Jan 20, 2025
CVE-2024-45647
5.6 MEDIUM

IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the …

Jan 20, 2025
CVE-2025-24337
8.4 HIGH

WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.

Jan 20, 2025
CVE-2025-21655
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but …

Jan 20, 2025
CVE-2024-13176
4.1 MEDIUM

Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in …

Jan 20, 2025
CVE-2025-0479

This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit …

Jan 20, 2025
CVE-2023-52923
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: adapt set backend to use GC transaction API Use the GC transaction API …

Jan 20, 2025
CVE-2025-0590
7.5 HIGH

Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.

Jan 20, 2025
CVE-2025-0586
7.2 HIGH

The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code …

Jan 20, 2025
CVE-2025-0585
9.8 CRITICAL

The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database …

Jan 20, 2025
CVE-2025-0584
5.3 MEDIUM

The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.

Jan 20, 2025
CVE-2025-0582
4.7 MEDIUM

A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the file /add-pig.php. The …

Jan 20, 2025
CVE-2025-0581
3.5 LOW

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. This affects an unknown part of the file /chat/group/send of the …

Jan 20, 2025
CVE-2025-0580
5.6 MEDIUM

A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 20, 2025
CVE-2025-0579
7.3 HIGH

A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jan 20, 2025
CVE-2024-13524
4.5 MEDIUM

A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected by this vulnerability is an unknown …

Jan 20, 2025
CVE-2025-0583
6.1 MEDIUM

The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Jan 20, 2025
CVE-2025-0578
3.5 LOW

A vulnerability was found in Facile Sistemas Cloud Apps up to 20250107. It has been classified as problematic. Affected is an unknown function of the …

Jan 20, 2025
CVE-2025-0576
4.3 MEDIUM

A vulnerability was found in Mobotix M15 4.3.4.83 and classified as problematic. This issue affects some unknown processing of the file /control/player?center&eventlist&pda&dummy_for_reload=1736177631&p_evt. The manipulation of …

Jan 20, 2025
CVE-2025-0575
3.9 LOW

A vulnerability has been found in Union Bank of India Vyom 8.0.34 on Android and classified as problematic. This vulnerability affects unknown code of the …

Jan 19, 2025
CVE-2024-41783
9.1 CRITICAL

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due …

Jan 19, 2025
CVE-2024-41743
7.5 HIGH

IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.

Jan 19, 2025
CVE-2024-41742
7.5 HIGH

IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting …

Jan 19, 2025
CVE-2024-38337
9.1 CRITICAL

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to …

Jan 19, 2025
CVE-2024-57929
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm array: fix releasing a faulty array block twice in dm_array_cursor_end When dm_bm_read_lock() fails due …

Jan 19, 2025
CVE-2024-57928
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix enomem handling in buffered reads If netfs_read_to_pagecache() gets an error from either ->prepare_read() …

Jan 19, 2025
CVE-2024-57927
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfs: Fix oops in nfs_netfs_init_request() when copying to cache When netfslib wants to copy some …

Jan 19, 2025
CVE-2024-57926
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Set private->all_drm_private[i]->drm to NULL if mtk_drm_bind returns err The pointer need to be set …

Jan 19, 2025
CVE-2024-57925
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix a missing return value check bug In the smb2_send_interim_resp(), if ksmbd_alloc_work_struct() fails to …

Jan 19, 2025
CVE-2024-57924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles Encoding file handles is usually performed …

Jan 19, 2025
CVE-2024-57923
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: zlib: fix avail_in bytes for s390 zlib HW compression path Since the input data …

Jan 19, 2025
CVE-2024-57922
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add check for granularity in dml ceil/floor helpers [Why] Wrapper functions for dcn_bw_ceil2() and …

Jan 19, 2025
CVE-2024-57921
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add a lock when accessing the buddy trim function When running YouTube videos and …

Jan 19, 2025
CVE-2024-57920

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 19, 2025
CVE-2024-57919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix divide error in DM plane scale calcs dm_get_plane_scale doesn't take into account plane …

Jan 19, 2025
CVE-2024-57918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix page fault due to max surface definition mismatch DC driver is using two …

Jan 19, 2025
CVE-2024-57917
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: topology: Keep the cpumask unchanged when printing cpumap During fuzz testing, the following warning was …

Jan 19, 2025
CVE-2024-57916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: Resolve kernel panic during GPIO IRQ handling Resolve kernel panic caused by …

Jan 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.