CVE Database

37796+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23058
8.8 HIGH

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the …

Feb 4, 2025
CVE-2025-24648
7.5 HIGH

Incorrect Privilege Assignment vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Privilege Escalation.This issue affects Admin and Site Enhancements (ASE): from n/a through …

Feb 4, 2025
CVE-2025-24602
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain Check wp24-domain-check allows Reflected XSS.This issue affects WP24 Domain Check: …

Feb 4, 2025
CVE-2025-24599
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through …

Feb 4, 2025
CVE-2025-24598
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP Mailster: from n/a …

Feb 4, 2025
CVE-2025-23645
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide Find Content IDs find-content-ids allows Reflected XSS.This issue affects Find Content …

Feb 4, 2025
CVE-2025-22794
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ianhaycox World Cup Predictor world-cup-predictor allows Reflected XSS.This issue affects World Cup Predictor: …

Feb 4, 2025
CVE-2025-22700
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through …

Feb 4, 2025
CVE-2024-23690
7.2 HIGH

The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary …

Feb 4, 2025
CVE-2025-1014
8.8 HIGH

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox …

Feb 4, 2025
CVE-2025-1012
7.5 HIGH

A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird …

Feb 4, 2025
CVE-2025-1011
8.8 HIGH

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve …

Feb 4, 2025
CVE-2025-1010
8.8 HIGH

An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, …

Feb 4, 2025
CVE-2025-23015
8.8 HIGH

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted …

Feb 4, 2025
CVE-2024-40891
8.8 HIGH KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an …

Feb 4, 2025
CVE-2024-40890
8.8 HIGH KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an …

Feb 4, 2025
CVE-2025-22205
7.5 HIGH

Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.

Feb 4, 2025
CVE-2025-20890
7.0 HIGH

Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction …

Feb 4, 2025
CVE-2025-20888
7.0 HIGH

Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with …

Feb 4, 2025
CVE-2025-20882
7.0 HIGH

Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. …

Feb 4, 2025
CVE-2025-20881
7.0 HIGH

Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code …

Feb 4, 2025
CVE-2024-10239
7.2 HIGH

A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with administrator privileges can upload a specially crafted image, which …

Feb 4, 2025
CVE-2024-10238
7.2 HIGH

A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can upload a specially crafted image that will cause a stack …

Feb 4, 2025
CVE-2024-10237
7.2 HIGH

There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection …

Feb 4, 2025
CVE-2024-13330
7.1 HIGH

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 4, 2025
CVE-2024-13329
7.1 HIGH

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 4, 2025
CVE-2025-24958
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_tag.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24902
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_cargo.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24901
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_permissao.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2024-35177
7.8 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, …

Feb 3, 2025
CVE-2025-24962
8.8 HIGH

reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been …

Feb 3, 2025
CVE-2025-24960
8.7 HIGH

Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This …

Feb 3, 2025
CVE-2025-24899
7.5 HIGH

reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, …

Feb 3, 2025
CVE-2025-22918
7.5 HIGH

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage …

Feb 3, 2025
CVE-2024-57451
7.5 HIGH

ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory.

Feb 3, 2025
CVE-2024-56903
8.1 HIGH

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. …

Feb 3, 2025
CVE-2024-56902
7.5 HIGH

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

Feb 3, 2025
CVE-2024-56901
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via …

Feb 3, 2025
CVE-2024-56898
8.8 HIGH

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, …

Feb 3, 2025
CVE-2024-34897
7.5 HIGH

Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

Feb 3, 2025
CVE-2024-34896
7.5 HIGH

An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device …

Feb 3, 2025
CVE-2023-52163
8.8 HIGH KEV

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Feb 3, 2025
CVE-2025-25064
8.8 HIGH

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a …

Feb 3, 2025
CVE-2024-57669
7.5 HIGH

Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupController.java file.

Feb 3, 2025
CVE-2024-57452
7.5 HIGH

ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

Feb 3, 2025
CVE-2024-56921
7.5 HIGH

An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() …

Feb 3, 2025
CVE-2024-12859
8.8 HIGH

The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_listing' shortcode …

Feb 3, 2025
CVE-2024-12511
7.6 HIGH

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

Feb 3, 2025
CVE-2024-57238
7.3 HIGH

Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL …

Feb 3, 2025
CVE-2024-56161
7.2 HIGH

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in …

Feb 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.