CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13694
7.5 HIGH

The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up …

Jan 30, 2025
CVE-2024-12708
7.1 HIGH

The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jan 30, 2025
CVE-2024-12638
7.1 HIGH

The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 30, 2025
CVE-2024-12400
7.1 HIGH

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

Jan 30, 2025
CVE-2025-23374
8.0 HIGH

Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high …

Jan 30, 2025
CVE-2025-0847
7.3 HIGH

A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jan 30, 2025
CVE-2025-0846
7.3 HIGH

A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the …

Jan 30, 2025
CVE-2025-21396
8.2 HIGH

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

Jan 29, 2025
CVE-2025-0843
7.3 HIGH

A vulnerability was found in needyamin Library Card System 1.0. It has been classified as critical. Affected is an unknown function of the file admindashboard.php …

Jan 29, 2025
CVE-2025-0842
7.3 HIGH

A vulnerability was found in needyamin Library Card System 1.0 and classified as critical. This issue affects some unknown processing of the file admin.php of …

Jan 29, 2025
CVE-2024-57510
7.8 HIGH

Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.

Jan 29, 2025
CVE-2024-57509
7.8 HIGH

Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions.

Jan 29, 2025
CVE-2024-54851
8.8 HIGH

Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.

Jan 29, 2025
CVE-2024-48761
8.8 HIGH

Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.

Jan 29, 2025
CVE-2024-23733
7.5 HIGH

The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover …

Jan 29, 2025
CVE-2024-12705
7.5 HIGH

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects …

Jan 29, 2025
CVE-2024-11187
7.5 HIGH

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker …

Jan 29, 2025
CVE-2025-24793
7.0 HIGH

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and …

Jan 29, 2025
CVE-2025-0841
7.3 HIGH

A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the …

Jan 29, 2025
CVE-2024-10001
7.1 HIGH

A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property …

Jan 29, 2025
CVE-2025-24789
7.8 HIGH

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability …

Jan 29, 2025
CVE-2025-24527
8.0 HIGH

An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug …

Jan 29, 2025
CVE-2024-57436
7.2 HIGH

RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers …

Jan 29, 2025
CVE-2024-54462
7.1 HIGH

The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user …

Jan 29, 2025
CVE-2024-54461
7.1 HIGH

The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user …

Jan 29, 2025
CVE-2024-41140
8.1 HIGH

Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

Jan 29, 2025
CVE-2025-0762
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. …

Jan 29, 2025
CVE-2021-3978
7.5 HIGH

When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since …

Jan 29, 2025
CVE-2024-7695
7.5 HIGH

Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient input validation, which allows data to be written to memory …

Jan 29, 2025
CVE-2024-13696
7.2 HIGH

The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wishlist_name’ parameter …

Jan 29, 2025
CVE-2024-12749
7.1 HIGH

The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 29, 2025
CVE-2025-0803
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of …

Jan 29, 2025
CVE-2025-0802
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jan 29, 2025
CVE-2025-0798
8.1 HIGH

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the …

Jan 29, 2025
CVE-2024-57519
7.5 HIGH

An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.

Jan 28, 2025
CVE-2024-56529
7.1 HIGH

Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled …

Jan 28, 2025
CVE-2024-48310
7.5 HIGH

AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers may use these keys to access the …

Jan 28, 2025
CVE-2024-57376
8.8 HIGH

Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.

Jan 28, 2025
CVE-2024-55968
8.8 HIGH

An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handling privileged operations within the macOS DTEX Event Forwarder agent, …

Jan 28, 2025
CVE-2024-40677
8.4 HIGH

In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local …

Jan 28, 2025
CVE-2024-40676
7.7 HIGH

In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This …

Jan 28, 2025
CVE-2024-40675
7.5 HIGH

In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no …

Jan 28, 2025
CVE-2024-40672
8.4 HIGH

In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local …

Jan 28, 2025
CVE-2024-40670
8.4 HIGH

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with …

Jan 28, 2025
CVE-2024-40669
8.4 HIGH

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with …

Jan 28, 2025
CVE-2024-40651
8.4 HIGH

In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege …

Jan 28, 2025
CVE-2024-40649
8.4 HIGH

In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege …

Jan 28, 2025
CVE-2024-34748
8.4 HIGH

In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with …

Jan 28, 2025
CVE-2024-34733
8.4 HIGH

In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in …

Jan 28, 2025
CVE-2024-34732
8.4 HIGH

In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in …

Jan 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.