CVE Database

38081+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20029
8.8 HIGH

Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands. …

Feb 5, 2025
CVE-2024-56135
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to …

Feb 5, 2025
CVE-2024-56134
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to …

Feb 5, 2025
CVE-2024-56133
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to …

Feb 5, 2025
CVE-2024-56132
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to …

Feb 5, 2025
CVE-2024-56131
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to …

Feb 5, 2025
CVE-2025-20176
7.7 HIGH

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS …

Feb 5, 2025
CVE-2025-20175
7.7 HIGH

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS …

Feb 5, 2025
CVE-2025-20174
7.7 HIGH

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS …

Feb 5, 2025
CVE-2025-20173
7.7 HIGH

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS …

Feb 5, 2025
CVE-2025-20172
7.7 HIGH

A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker …

Feb 5, 2025
CVE-2025-20171
7.7 HIGH

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS …

Feb 5, 2025
CVE-2025-20170
7.7 HIGH

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS …

Feb 5, 2025
CVE-2025-20169
7.7 HIGH

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS …

Feb 5, 2025
CVE-2024-39564
7.5 HIGH

This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability in the routing process daemon (rpd) of Juniper Networks …

Feb 5, 2025
CVE-2024-2878
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

Feb 5, 2025
CVE-2024-9631
7.5 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from …

Feb 5, 2025
CVE-2024-49352
7.1 HIGH

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when …

Feb 5, 2025
CVE-2025-0725
7.3 HIGH

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer …

Feb 5, 2025
CVE-2025-0665
7.0 HIGH

libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.

Feb 5, 2025
CVE-2025-25246
8.1 HIGH

NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.

Feb 5, 2025
CVE-2025-1026
8.6 HIGH

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in …

Feb 5, 2025
CVE-2025-1025
7.5 HIGH

Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.

Feb 5, 2025
CVE-2025-1022
8.2 HIGH

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by …

Feb 5, 2025
CVE-2025-1028
8.1 HIGH

The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the contact form upload feature in …

Feb 5, 2025
CVE-2025-0413
7.8 HIGH

Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. …

Feb 5, 2025
CVE-2024-11468
7.8 HIGH

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue …

Feb 4, 2025
CVE-2024-11467
7.8 HIGH

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers …

Feb 4, 2025
CVE-2023-40222
7.8 HIGH

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could …

Feb 4, 2025
CVE-2023-39943
7.8 HIGH

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing XE files. This could …

Feb 4, 2025
CVE-2024-13723
7.2 HIGH

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP …

Feb 4, 2025
CVE-2025-23023
8.2 HIGH

Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a request with the right request headers to …

Feb 4, 2025
CVE-2024-55948
8.2 HIGH

Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache …

Feb 4, 2025
CVE-2025-24968
8.8 HIGH

reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tester` or `auditor` to …

Feb 4, 2025
CVE-2025-0509
7.3 HIGH

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing …

Feb 4, 2025
CVE-2025-23058
8.8 HIGH

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the …

Feb 4, 2025
CVE-2025-24648
7.5 HIGH

Incorrect Privilege Assignment vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Privilege Escalation.This issue affects Admin and Site Enhancements (ASE): from n/a through …

Feb 4, 2025
CVE-2025-24602
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain Check wp24-domain-check allows Reflected XSS.This issue affects WP24 Domain Check: …

Feb 4, 2025
CVE-2025-24599
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through …

Feb 4, 2025
CVE-2025-24598
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP Mailster: from n/a …

Feb 4, 2025
CVE-2025-23645
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide Find Content IDs find-content-ids allows Reflected XSS.This issue affects Find Content …

Feb 4, 2025
CVE-2025-22794
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ianhaycox World Cup Predictor world-cup-predictor allows Reflected XSS.This issue affects World Cup Predictor: …

Feb 4, 2025
CVE-2025-22700
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through …

Feb 4, 2025
CVE-2024-23690
7.2 HIGH

The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary …

Feb 4, 2025
CVE-2025-1014
8.8 HIGH

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox …

Feb 4, 2025
CVE-2025-1012
7.5 HIGH

A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird …

Feb 4, 2025
CVE-2025-1011
8.8 HIGH

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve …

Feb 4, 2025
CVE-2025-1010
8.8 HIGH

An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, …

Feb 4, 2025
CVE-2025-23015
8.8 HIGH

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted …

Feb 4, 2025
CVE-2024-40891
8.8 HIGH KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an …

Feb 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.