CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-42240
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of …

Jan 13, 2025
CVE-2023-42239
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of …

Jan 13, 2025
CVE-2023-42238
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of …

Jan 13, 2025
CVE-2023-42237
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of …

Jan 13, 2025
CVE-2023-42236
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of …

Jan 13, 2025
CVE-2023-42235
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.

Jan 13, 2025
CVE-2023-42234
5.4 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.

Jan 13, 2025
CVE-2023-42233
6.1 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.

Jan 13, 2025
CVE-2023-42232
7.5 HIGH

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

Jan 13, 2025
CVE-2023-42231
8.1 HIGH

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the …

Jan 13, 2025
CVE-2023-42230
6.1 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.

Jan 13, 2025
CVE-2023-42229
6.5 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the …

Jan 13, 2025
CVE-2023-42228
8.8 HIGH

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request …

Jan 13, 2025
CVE-2023-42227
7.5 HIGH

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.

Jan 13, 2025
CVE-2023-42226
7.5 HIGH

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.

Jan 13, 2025
CVE-2023-42225
7.5 HIGH

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.

Jan 13, 2025
CVE-2025-22619
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22618
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22617
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22616
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22615
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22614
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22613
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22138

@codidact/qpixel is a Q&A-based community knowledge-sharing software. In affected versions when a category is set to private or limited-visibility within QPixel's admin tools, suggested edits …

Jan 13, 2025
CVE-2025-22134
4.2 MEDIUM

When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not …

Jan 13, 2025
CVE-2025-23027

next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of this token and should remove …

Jan 13, 2025
CVE-2025-23026
6.1 MEDIUM

jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTML templates with `script` tags or …

Jan 13, 2025
CVE-2025-22144
9.8 CRITICAL

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and …

Jan 13, 2025
CVE-2025-22142
5.4 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have …

Jan 13, 2025
CVE-2024-46481
7.2 HIGH

The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.

Jan 13, 2025
CVE-2024-46480
8.4 HIGH

An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host …

Jan 13, 2025
CVE-2024-46921
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, …

Jan 13, 2025
CVE-2024-46310
9.1 CRITICAL

Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint

Jan 13, 2025
CVE-2024-44771
6.1 MEDIUM

BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function.

Jan 13, 2025
CVE-2024-5743
9.8 CRITICAL

An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code. This issue affects …

Jan 13, 2025
CVE-2024-46920
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to …

Jan 13, 2025
CVE-2024-46479
9.9 CRITICAL

Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote …

Jan 13, 2025
CVE-2024-6352
4.3 MEDIUM

A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert

Jan 13, 2025
CVE-2024-57488
6.5 MEDIUM

Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

Jan 13, 2025
CVE-2024-57487
6.5 MEDIUM

In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a …

Jan 13, 2025
CVE-2024-54999
6.5 MEDIUM

MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.

Jan 13, 2025
CVE-2024-48883
4.3 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, …

Jan 13, 2025
CVE-2024-46919
5.3 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to …

Jan 13, 2025
CVE-2024-12211
5.4 MEDIUM

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

Jan 13, 2025
CVE-2025-22963
7.5 HIGH

Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.

Jan 13, 2025
CVE-2024-52333
8.4 HIGH

An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds …

Jan 13, 2025
CVE-2024-47796
8.4 HIGH

An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds …

Jan 13, 2025
CVE-2025-22800
4.3 MEDIUM

Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= …

Jan 13, 2025
CVE-2025-22777
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3.

Jan 13, 2025
CVE-2025-22588
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in intelligence_lab Scanventory woocommerce-inventory-management allows Reflected XSS.This issue affects Scanventory: from n/a through <= …

Jan 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.