CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2018-9434
7.8 HIGH

In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with …

Jan 17, 2025
CVE-2018-9384
4.4 MEDIUM

In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with …

Jan 17, 2025
CVE-2018-9383
4.4 MEDIUM

In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jan 17, 2025
CVE-2018-9382
7.8 HIGH

In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This …

Jan 17, 2025
CVE-2018-9379
5.5 MEDIUM

In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could lead …

Jan 17, 2025
CVE-2018-9375
7.8 HIGH

In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This …

Jan 17, 2025
CVE-2017-13322
5.5 MEDIUM

In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could …

Jan 17, 2025
CVE-2025-23207
6.3 MEDIUM

KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter …

Jan 17, 2025
CVE-2025-0541
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/edit_member.php. The …

Jan 17, 2025
CVE-2025-23206
8.1 HIGH

The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. …

Jan 17, 2025
CVE-2025-23205

nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user the ability to extract formgrader content by sending malicious …

Jan 17, 2025
CVE-2025-23202

Bible Module is a tool designed for ROBLOX developers to integrate Bible functionality into their games. The `FetchVerse` and `FetchPassage` functions in the Bible Module …

Jan 17, 2025
CVE-2025-23039
5.2 MEDIUM

Caido is a web security auditing toolkit. A Cross-Site Scripting (XSS) vulnerability was identified in Caido v0.45.0 due to improper sanitization in the URL decoding …

Jan 17, 2025
CVE-2025-21606

stats is a macOS system monitor in for the menu bar. The Stats application is vulnerable to a local privilege escalation due to the insecure …

Jan 17, 2025
CVE-2025-0540
6.3 MEDIUM

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /expadd.php. The …

Jan 17, 2025
CVE-2025-0538
3.5 LOW

A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected is an unknown function of the file /admin/manage-pages.php. The …

Jan 17, 2025
CVE-2024-57252
4.3 MEDIUM

OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.

Jan 17, 2025
CVE-2024-57035
9.8 CRITICAL

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

Jan 17, 2025
CVE-2024-57033
6.1 MEDIUM

WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.

Jan 17, 2025
CVE-2023-50738
4.3 MEDIUM

A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this downgrade protection has been identified.

Jan 17, 2025
CVE-2025-21399
7.4 HIGH

Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability

Jan 17, 2025
CVE-2025-21185
6.5 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 17, 2025
CVE-2025-0537
2.4 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the …

Jan 17, 2025
CVE-2025-0536
6.3 MEDIUM

A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The …

Jan 17, 2025
CVE-2024-57372
6.1 MEDIUM

Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters

Jan 17, 2025
CVE-2024-57370
6.1 MEDIUM

Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.

Jan 17, 2025
CVE-2024-57369
6.4 MEDIUM

Clickjacking vulnerability in typecho v1.2.1.

Jan 17, 2025
CVE-2024-57034
9.8 CRITICAL

WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.

Jan 17, 2025
CVE-2024-57032
9.8 CRITICAL

WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is …

Jan 17, 2025
CVE-2024-57031
9.8 CRITICAL

WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.

Jan 17, 2025
CVE-2024-57030
8.1 HIGH

Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.

Jan 17, 2025
CVE-2024-52870
7.1 HIGH

Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result …

Jan 17, 2025
CVE-2024-13026

A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism …

Jan 17, 2025
CVE-2025-0535
6.3 MEDIUM

A vulnerability classified as critical has been found in Codezips Gym Management System 1.0. This affects an unknown part of the file /dashboard/admin/edit_mem_submit.php. The manipulation …

Jan 17, 2025
CVE-2025-0534
7.3 HIGH

A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is …

Jan 17, 2025
CVE-2025-0533
7.3 HIGH

A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is …

Jan 17, 2025
CVE-2025-0532
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/new_submit.php. …

Jan 17, 2025
CVE-2025-0430
7.5 HIGH

Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition.

Jan 17, 2025
CVE-2024-12757
8.6 HIGH

Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker to potentially execute malicious code.

Jan 17, 2025
CVE-2024-54681
3.5 LOW

Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full …

Jan 17, 2025
CVE-2024-53683
4.4 MEDIUM

A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use …

Jan 17, 2025
CVE-2024-45832
4.3 MEDIUM

Hard-coded credentials were included as part of the application binary. These credentials served as part of the application authentication flow and communication with the mobile …

Jan 17, 2025
CVE-2024-26157
6.1 MEDIUM

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in get view method …

Jan 17, 2025
CVE-2024-26156
4.8 MEDIUM

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. …

Jan 17, 2025
CVE-2024-26155
6.8 MEDIUM

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the …

Jan 17, 2025
CVE-2024-26154
4.8 MEDIUM

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The …

Jan 17, 2025
CVE-2024-26153
7.4 HIGH

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access …

Jan 17, 2025
CVE-2025-0531
6.3 MEDIUM

A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/leaveroom.php. The manipulation …

Jan 17, 2025
CVE-2025-0530
3.5 LOW

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/_feedback_system.php. The manipulation …

Jan 17, 2025
CVE-2025-0529
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Train Ticket Reservation System 1.0. This affects an unknown part of the component Login …

Jan 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.