CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21622
7.5 HIGH

ClipBucket V5 provides open source video hosting with PHP. During the user avatar upload workflow, a user can choose to upload and change their avatar …

Jan 7, 2025
CVE-2025-0298
6.3 MEDIUM

A vulnerability was found in code-projects Online Book Shop 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jan 7, 2025
CVE-2025-0297
6.3 MEDIUM

A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /detail.php. …

Jan 7, 2025
CVE-2025-0247
9.8 CRITICAL

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Jan 7, 2025
CVE-2025-0246
6.5 MEDIUM

When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are …

Jan 7, 2025
CVE-2025-0245
3.3 LOW

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability was fixed in Firefox …

Jan 7, 2025
CVE-2025-0244
5.3 MEDIUM

When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems …

Jan 7, 2025
CVE-2025-0243
5.1 MEDIUM

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and …

Jan 7, 2025
CVE-2025-0242
6.5 MEDIUM

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed …

Jan 7, 2025
CVE-2025-0241
7.7 HIGH

When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, …

Jan 7, 2025
CVE-2025-0240
4.0 MEDIUM

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox …

Jan 7, 2025
CVE-2025-0239
4.0 MEDIUM

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox …

Jan 7, 2025
CVE-2025-0238
5.3 MEDIUM

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox …

Jan 7, 2025
CVE-2025-0237
5.4 MEDIUM

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. …

Jan 7, 2025
CVE-2024-56056
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleCharm simplecharm allows Reflected XSS.This issue affects SimpleCharm: from n/a through <= …

Jan 7, 2025
CVE-2024-55556
9.8 CRITICAL

A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the …

Jan 7, 2025
CVE-2024-55008
7.5 HIGH

JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending …

Jan 7, 2025
CVE-2024-53800
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in rezgo Rezgo rezgo allows PHP Local File Inclusion.This issue …

Jan 7, 2025
CVE-2024-53345
8.8 HIGH

An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 7, 2025
CVE-2024-52813
4.3 MEDIUM

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify …

Jan 7, 2025
CVE-2024-48245
7.2 HIGH

Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a …

Jan 7, 2025
CVE-2024-46603
7.5 HIGH

An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via …

Jan 7, 2025
CVE-2024-46602
7.5 HIGH

An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to …

Jan 7, 2025
CVE-2024-46601
7.5 HIGH

Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.

Jan 7, 2025
CVE-2024-46242
7.5 HIGH

An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a Regular expression Denial of Service (ReDoS) via supplying a …

Jan 7, 2025
CVE-2024-40702
8.2 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources …

Jan 7, 2025
CVE-2024-28778
6.5 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code …

Jan 7, 2025
CVE-2024-25037
4.3 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned …

Jan 7, 2025
CVE-2022-22363
4.3 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Jan 7, 2025
CVE-2021-20455
3.7 LOW

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Jan 7, 2025
CVE-2025-0296
6.3 MEDIUM

A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unknown part of the file /booklist.php. …

Jan 7, 2025
CVE-2025-0295
3.5 LOW

A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Jan 7, 2025
CVE-2024-11681
6.8 MEDIUM

A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirror.

Jan 7, 2025
CVE-2025-0294
4.7 MEDIUM

A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Jan 7, 2025
CVE-2024-45640
5.3 MEDIUM

IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.

Jan 7, 2025
CVE-2024-45100
4.9 MEDIUM

IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of …

Jan 7, 2025
CVE-2024-12738
6.1 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 7, 2025
CVE-2024-12426
6.5 MEDIUM

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded …

Jan 7, 2025
CVE-2024-12131
4.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Jan 7, 2025
CVE-2024-52893
5.3 MEDIUM

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is …

Jan 7, 2025
CVE-2024-52891
5.4 MEDIUM

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due …

Jan 7, 2025
CVE-2024-52367
5.3 MEDIUM

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthorized actor that could be used in further attacks …

Jan 7, 2025
CVE-2024-52366
5.9 MEDIUM

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable …

Jan 7, 2025
CVE-2024-12711
5.3 MEDIUM

The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() …

Jan 7, 2025
CVE-2024-12532
4.3 MEDIUM

The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.18 in widgets/bwdeb-content-switcher.php. This makes …

Jan 7, 2025
CVE-2024-12425
3.3 LOW

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write …

Jan 7, 2025
CVE-2024-12316
5.3 MEDIUM

The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in …

Jan 7, 2025
CVE-2024-12033
4.3 MEDIUM

The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions …

Jan 7, 2025
CVE-2024-11826
6.4 MEDIUM

The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress plugin for …

Jan 7, 2025
CVE-2025-22364
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice App ach-invoice-app allows PHP Local …

Jan 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.