CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54687
6.1 MEDIUM

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

Jan 10, 2025
CVE-2024-57214
6.3 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

Jan 10, 2025
CVE-2024-57213
6.3 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.

Jan 10, 2025
CVE-2024-57212
5.1 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.

Jan 10, 2025
CVE-2024-57211
8.0 HIGH

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.

Jan 10, 2025
CVE-2024-54849
5.9 MEDIUM

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack.

Jan 10, 2025
CVE-2024-54848
7.4 HIGH

Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.

Jan 10, 2025
CVE-2024-54847
5.9 MEDIUM

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack.

Jan 10, 2025
CVE-2024-54846
5.9 MEDIUM

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack.

Jan 10, 2025
CVE-2025-22949
9.8 CRITICAL

Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.

Jan 10, 2025
CVE-2025-22600
6.5 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_doacao.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22599
6.5 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22598
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22597
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22596
6.5 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the modulos_visiveis.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22152
9.1 CRITICAL

Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker …

Jan 10, 2025
CVE-2024-56511
9.8 CRITICAL

DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can …

Jan 10, 2025
CVE-2024-50807
6.1 MEDIUM

Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf extensions.

Jan 10, 2025
CVE-2024-46210
7.2 HIGH

An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 10, 2025
CVE-2024-29971
9.8 CRITICAL

Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.

Jan 10, 2025
CVE-2024-29970
9.8 CRITICAL

Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals.

Jan 10, 2025
CVE-2024-25371
7.5 HIGH

Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW signals vs HW exceptions.

Jan 10, 2025
CVE-2025-23022
4.0 MEDIUM

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

Jan 10, 2025
CVE-2025-22946
9.8 CRITICAL

Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.

Jan 10, 2025
CVE-2024-57687
9.8 CRITICAL

An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the …

Jan 10, 2025
CVE-2024-57686
9.8 CRITICAL

A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via …

Jan 10, 2025
CVE-2024-41787
9.8 CRITICAL

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending …

Jan 10, 2025
CVE-2024-57823
9.3 CRITICAL

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

Jan 10, 2025
CVE-2024-57822
4.0 MEDIUM

In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

Jan 10, 2025
CVE-2025-23016
9.3 CRITICAL

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to …

Jan 10, 2025
CVE-2024-13318
5.3 MEDIUM

The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all …

Jan 10, 2025
CVE-2024-13183
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, …

Jan 10, 2025
CVE-2025-0311
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, …

Jan 10, 2025
CVE-2024-12606
4.3 MEDIUM

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is …

Jan 10, 2025
CVE-2024-12473
6.5 MEDIUM

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is …

Jan 10, 2025
CVE-2025-21380
8.8 HIGH

Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.

Jan 9, 2025
CVE-2024-56377
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or …

Jan 9, 2025
CVE-2024-56376
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When …

Jan 9, 2025
CVE-2025-21385
8.8 HIGH

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

Jan 9, 2025
CVE-2024-51229
8.8 HIGH

Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

Jan 9, 2025
CVE-2024-46464
7.8 HIGH

In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer …

Jan 9, 2025
CVE-2023-28354
9.8 CRITICAL

An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in …

Jan 9, 2025
CVE-2024-55226
5.4 MEDIUM

Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.

Jan 9, 2025
CVE-2024-55225
9.8 CRITICAL

An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.

Jan 9, 2025
CVE-2024-55224
9.6 CRITICAL

An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of …

Jan 9, 2025
CVE-2024-48806
6.8 MEDIUM

Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a crafted payload to the password field

Jan 9, 2025
CVE-2024-13312
5.3 MEDIUM

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9.

Jan 9, 2025
CVE-2024-13311
7.3 HIGH

Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.

Jan 9, 2025
CVE-2024-13310
6.5 MEDIUM

Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*.

Jan 9, 2025
CVE-2024-13309
5.4 MEDIUM

Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.

Jan 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.