CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57764
9.1 CRITICAL

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.

Jan 15, 2025
CVE-2024-57763
9.1 CRITICAL

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.

Jan 15, 2025
CVE-2024-57762
7.5 HIGH

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

Jan 15, 2025
CVE-2024-57761
8.1 HIGH

An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 15, 2025
CVE-2024-57760
6.5 MEDIUM

JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.

Jan 15, 2025
CVE-2024-57757
7.5 HIGH

JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.

Jan 15, 2025
CVE-2024-57483
9.8 CRITICAL

Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.

Jan 14, 2025
CVE-2024-57473
9.8 CRITICAL

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit …

Jan 14, 2025
CVE-2024-54730
7.5 HIGH

Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.

Jan 14, 2025
CVE-2024-54142
9.0 CRITICAL

Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations into posts, if the conversation had …

Jan 14, 2025
CVE-2024-53277
5.4 MEDIUM

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, …

Jan 14, 2025
CVE-2024-47605
5.4 MEDIUM

silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON includes an HTML attribute which will …

Jan 14, 2025
CVE-2024-42911
7.4 HIGH

ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vulnerability.

Jan 14, 2025
CVE-2024-57482
9.8 CRITICAL

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully …

Jan 14, 2025
CVE-2024-57480
9.8 CRITICAL

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this …

Jan 14, 2025
CVE-2024-57479
9.8 CRITICAL

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit …

Jan 14, 2025
CVE-2024-57471
9.8 CRITICAL

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully …

Jan 14, 2025
CVE-2024-50861
6.1 MEDIUM

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved …

Jan 14, 2025
CVE-2024-50859
4.8 MEDIUM

The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in …

Jan 14, 2025
CVE-2024-50858
8.8 HIGH

Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious …

Jan 14, 2025
CVE-2024-50857
4.8 MEDIUM

The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user …

Jan 14, 2025
CVE-2024-48760
9.8 CRITICAL

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi …

Jan 14, 2025
CVE-2024-45102
6.8 MEDIUM

A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using …

Jan 14, 2025
CVE-2024-10254
4.7 MEDIUM

A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a …

Jan 14, 2025
CVE-2024-10253
4.7 MEDIUM

A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system …

Jan 14, 2025
CVE-2025-23019
5.4 MEDIUM

IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.

Jan 14, 2025
CVE-2025-23018
5.4 MEDIUM

IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof …

Jan 14, 2025
CVE-2025-21139
7.8 HIGH

Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jan 14, 2025
CVE-2025-21138
7.8 HIGH

Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21137
7.8 HIGH

Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jan 14, 2025
CVE-2025-21136
7.8 HIGH

Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21135
7.8 HIGH

Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Jan 14, 2025
CVE-2024-5175

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 14, 2025
CVE-2024-55945
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55924
8.0 HIGH

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55923
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55922
5.4 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55921
7.5 HIGH

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55920
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55894
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55893
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55892
4.8 MEDIUM

TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and …

Jan 14, 2025
CVE-2024-55891
3.1 LOW

TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in …

Jan 14, 2025
CVE-2024-53263

Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of …

Jan 14, 2025
CVE-2024-48858
7.5 HIGH

Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …

Jan 14, 2025
CVE-2025-23074
2.4 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfile Extension allows Functionality Misuse.This issue affects Mediawiki - SocialProfile Extension: …

Jan 14, 2025
CVE-2025-23073
3.5 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data. This issue briefly impacted …

Jan 14, 2025
CVE-2025-23072
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RefreshSpecial Extension allows Cross-Site Scripting (XSS).This issue …

Jan 14, 2025
CVE-2025-23042
7.5 HIGH

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. …

Jan 14, 2025
CVE-2025-23041
5.8 MEDIUM

Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only …

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.