CVE Database

38081+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40890
8.8 HIGH KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an …

Feb 4, 2025
CVE-2025-22205
7.5 HIGH

Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.

Feb 4, 2025
CVE-2025-20890
7.0 HIGH

Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction …

Feb 4, 2025
CVE-2025-20888
7.0 HIGH

Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with …

Feb 4, 2025
CVE-2025-20882
7.0 HIGH

Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. …

Feb 4, 2025
CVE-2025-20881
7.0 HIGH

Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code …

Feb 4, 2025
CVE-2024-10239
7.2 HIGH

A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with administrator privileges can upload a specially crafted image, which …

Feb 4, 2025
CVE-2024-10238
7.2 HIGH

A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can upload a specially crafted image that will cause a stack …

Feb 4, 2025
CVE-2024-10237
7.2 HIGH

There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection …

Feb 4, 2025
CVE-2024-13330
7.1 HIGH

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 4, 2025
CVE-2024-13329
7.1 HIGH

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 4, 2025
CVE-2025-24958
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_tag.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24902
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_cargo.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2025-24901
8.8 HIGH

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_permissao.php` endpoint. This vulnerability could allow an …

Feb 3, 2025
CVE-2024-35177
7.8 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, …

Feb 3, 2025
CVE-2025-24962
8.8 HIGH

reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been …

Feb 3, 2025
CVE-2025-24960
8.7 HIGH

Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This …

Feb 3, 2025
CVE-2025-24899
7.5 HIGH

reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, …

Feb 3, 2025
CVE-2025-22918
7.5 HIGH

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage …

Feb 3, 2025
CVE-2024-57451
7.5 HIGH

ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory.

Feb 3, 2025
CVE-2024-56903
8.1 HIGH

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. …

Feb 3, 2025
CVE-2024-56902
7.5 HIGH

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

Feb 3, 2025
CVE-2024-56901
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via …

Feb 3, 2025
CVE-2024-56898
8.8 HIGH

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, …

Feb 3, 2025
CVE-2024-34897
7.5 HIGH

Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

Feb 3, 2025
CVE-2024-34896
7.5 HIGH

An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device …

Feb 3, 2025
CVE-2023-52163
8.8 HIGH KEV

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Feb 3, 2025
CVE-2025-25064
8.8 HIGH

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a …

Feb 3, 2025
CVE-2024-57669
7.5 HIGH

Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupController.java file.

Feb 3, 2025
CVE-2024-57452
7.5 HIGH

ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

Feb 3, 2025
CVE-2024-56921
7.5 HIGH

An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() …

Feb 3, 2025
CVE-2024-12859
8.8 HIGH

The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_listing' shortcode …

Feb 3, 2025
CVE-2024-12511
7.6 HIGH

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

Feb 3, 2025
CVE-2024-57238
7.3 HIGH

Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL …

Feb 3, 2025
CVE-2024-56161
7.2 HIGH

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in …

Feb 3, 2025
CVE-2024-49843
7.8 HIGH

Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.

Feb 3, 2025
CVE-2024-49840
7.8 HIGH

Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.

Feb 3, 2025
CVE-2024-49839
8.2 HIGH

Memory corruption during management frame processing due to mismatch in T2LM info element.

Feb 3, 2025
CVE-2024-49838
8.2 HIGH

Information disclosure while parsing the OCI IE with invalid length.

Feb 3, 2025
CVE-2024-49837
7.8 HIGH

Memory corruption while reading CPU state data during guest VM suspend.

Feb 3, 2025
CVE-2024-49834
7.8 HIGH

Memory corruption while power-up or power-down sequence of the camera sensor.

Feb 3, 2025
CVE-2024-49833
7.8 HIGH

Memory corruption can occur in the camera when an invalid CID is used.

Feb 3, 2025
CVE-2024-49832
7.8 HIGH

Memory corruption in Camera due to unusually high number of nodes passed to AXI port.

Feb 3, 2025
CVE-2024-45584
7.8 HIGH

Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.

Feb 3, 2025
CVE-2024-45582
7.8 HIGH

Memory corruption while validating number of devices in Camera kernel .

Feb 3, 2025
CVE-2024-45573
7.8 HIGH

Memory corruption may occour while generating test pattern due to negative indexing of display ID.

Feb 3, 2025
CVE-2024-45571
7.8 HIGH

Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.

Feb 3, 2025
CVE-2024-45561
7.8 HIGH

Memory corruption while handling IOCTL call from user-space to set latency level.

Feb 3, 2025
CVE-2024-45560
7.8 HIGH

Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.

Feb 3, 2025
CVE-2024-38420
8.8 HIGH

Memory corruption while configuring a Hypervisor based input virtual device.

Feb 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.