CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12803
7.2 HIGH

A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

Jan 9, 2025
CVE-2023-1907
8.0 HIGH

A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if …

Jan 9, 2025
CVE-2025-22449
3.8 LOW

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite …

Jan 9, 2025
CVE-2025-22445
3.5 LOW

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

Jan 9, 2025
CVE-2025-20033
4.3 MEDIUM

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to …

Jan 9, 2025
CVE-2025-0340
7.3 HIGH

A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jan 9, 2025
CVE-2025-0339
3.5 LOW

A vulnerability classified as problematic has been found in code-projects Online Bike Rental 1.0. Affected is an unknown function of the file /vehical-details.php of the …

Jan 9, 2025
CVE-2025-0336
6.3 MEDIUM

A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/teacher.php. …

Jan 9, 2025
CVE-2024-53706
7.8 HIGH

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to …

Jan 9, 2025
CVE-2024-53705
7.5 HIGH

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on …

Jan 9, 2025
CVE-2024-53704
9.8 CRITICAL KEV

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Jan 9, 2025
CVE-2024-40762
9.8 CRITICAL

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker …

Jan 9, 2025
CVE-2024-13041
4.2 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from …

Jan 9, 2025
CVE-2025-0335
6.3 MEDIUM

A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 9, 2025
CVE-2025-0334
6.3 MEDIUM

A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /sys/user/listData. …

Jan 9, 2025
CVE-2024-6324
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from …

Jan 9, 2025
CVE-2024-12736
6.1 MEDIUM

The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 9, 2025
CVE-2024-12731
6.1 MEDIUM

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 9, 2025
CVE-2024-12717
4.8 MEDIUM

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 9, 2025
CVE-2024-12715
6.1 MEDIUM

The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 9, 2025
CVE-2024-12714
6.1 MEDIUM

The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 9, 2025
CVE-2024-10815
4.2 MEDIUM

The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site …

Jan 9, 2025
CVE-2025-0333
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of …

Jan 9, 2025
CVE-2025-0331
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php …

Jan 9, 2025
CVE-2025-0328
7.3 HIGH

A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality …

Jan 9, 2025
CVE-2025-0306
7.4 HIGH

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages …

Jan 9, 2025
CVE-2024-56827
5.6 MEDIUM

A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress …

Jan 9, 2025
CVE-2024-56826
5.6 MEDIUM

A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress …

Jan 9, 2025
CVE-2024-13213
3.5 LOW

A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHousePage?hID=30. The manipulation leads to cross …

Jan 9, 2025
CVE-2024-13212
6.3 MEDIUM

A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the …

Jan 9, 2025
CVE-2024-13211
6.3 MEDIUM

A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Jan 9, 2025
CVE-2024-13210
4.7 MEDIUM

A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file …

Jan 9, 2025
CVE-2024-13209
2.4 LOW

A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the …

Jan 9, 2025
CVE-2024-13206
7.8 HIGH

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation …

Jan 9, 2025
CVE-2024-13205
2.4 LOW

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Jan 9, 2025
CVE-2024-13204
5.5 MEDIUM

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 9, 2025
CVE-2024-13203
4.3 MEDIUM

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request …

Jan 9, 2025
CVE-2024-13202
2.4 LOW

A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the function modifiyArticle of the file src/main/java/com/my/blog/website/controller/admin/PageController.java of the component …

Jan 9, 2025
CVE-2024-13201
4.7 MEDIUM

A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the …

Jan 9, 2025
CVE-2024-13200
7.3 HIGH

A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component …

Jan 9, 2025
CVE-2024-37372
3.6 LOW

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. …

Jan 9, 2025
CVE-2024-27980
8.1 HIGH

Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution …

Jan 9, 2025
CVE-2024-13199
3.5 LOW

A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search …

Jan 9, 2025
CVE-2024-13198
3.7 LOW

A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation …

Jan 9, 2025
CVE-2023-38037
5.5 MEDIUM

ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that …

Jan 9, 2025
CVE-2023-28362
4.0 MEDIUM

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential …

Jan 9, 2025
CVE-2023-28120
5.3 MEDIUM

There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.

Jan 9, 2025
CVE-2023-27539
5.3 MEDIUM

There is a denial of service vulnerability in the header parsing component of Rack.

Jan 9, 2025
CVE-2023-27531
5.3 MEDIUM

There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

Jan 9, 2025
CVE-2023-23913
6.3 MEDIUM

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable …

Jan 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.