CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22317
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gallery Ape Photo Gallery – Image Gallery by Ape gallery-images-ape allows Reflected XSS.This …

Jan 15, 2025
CVE-2024-8603
7.5 HIGH

A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp …

Jan 15, 2025
CVE-2024-47140
8.7 HIGH

A cross-site scripting (xss) vulnerability exists in the add_alert_check page of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript …

Jan 15, 2025
CVE-2024-47002
8.7 HIGH

A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary …

Jan 15, 2025
CVE-2024-45061
8.7 HIGH

A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a …

Jan 15, 2025
CVE-2024-11322
7.5 HIGH

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog …

Jan 15, 2025
CVE-2024-57900
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ila: serialize calls to nf_register_net_hooks() syzbot found a race in ila_add_mapping() [1] commit 031ae72825ce ("ila: …

Jan 15, 2025
CVE-2024-57899
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix mbss changed flags corruption on 32 bit systems On 32-bit systems, the …

Jan 15, 2025
CVE-2024-57896
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: flush delalloc workers queue before stopping cleaner kthread during unmount During the unmount path, …

Jan 15, 2025
CVE-2024-57892
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv When mounting ocfs2 and then remounting it …

Jan 15, 2025
CVE-2024-57887
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm: adv7511: Fix use-after-free in adv7533_attach_dsi() The host_node pointer was assigned and freed in adv7533_parse_dt(), …

Jan 15, 2025
CVE-2024-57857
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Remove direct link to net_device Do not manage a per device direct link to …

Jan 15, 2025
CVE-2024-57801
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Skip restore TC rules for vport rep without loaded flag During driver unload, unregister_netdev …

Jan 15, 2025
CVE-2024-57795
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Remove the direct link to net_device The similar patch in siw is in the …

Jan 15, 2025
CVE-2024-11848
8.1 HIGH

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all …

Jan 15, 2025
CVE-2025-0447
8.8 HIGH

Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security …

Jan 15, 2025
CVE-2025-0443
8.8 HIGH

Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Jan 15, 2025
CVE-2025-0438
8.8 HIGH

Stack buffer overflow in Tracing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. …

Jan 15, 2025
CVE-2025-0437
8.8 HIGH

Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Jan 15, 2025
CVE-2025-0436
8.8 HIGH

Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Jan 15, 2025
CVE-2025-0434
8.8 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Jan 15, 2025
CVE-2024-13351
7.2 HIGH

The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rw_image_badge1' shortcode in all versions …

Jan 15, 2025
CVE-2025-0356
7.2 HIGH

NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network.

Jan 15, 2025
CVE-2025-0355
7.5 HIGH

Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and …

Jan 15, 2025
CVE-2024-4227
7.5 HIGH

In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate …

Jan 15, 2025
CVE-2024-55577
7.0 HIGH

Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file which is specially crafted by an attacker, arbitrary …

Jan 15, 2025
CVE-2025-0343
7.5 HIGH

Swift ASN.1 can be caused to crash when parsing certain BER/DER constructions. This crash is caused by a confusion in the ASN.1 library itself which …

Jan 15, 2025
CVE-2024-57767
8.6 HIGH

MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.

Jan 15, 2025
CVE-2024-57765
7.5 HIGH

MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.

Jan 15, 2025
CVE-2024-57762
7.5 HIGH

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

Jan 15, 2025
CVE-2024-57761
8.1 HIGH

An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 15, 2025
CVE-2024-57757
7.5 HIGH

JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.

Jan 15, 2025
CVE-2024-54730
7.5 HIGH

Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.

Jan 14, 2025
CVE-2024-42911
7.4 HIGH

ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vulnerability.

Jan 14, 2025
CVE-2024-50858
8.8 HIGH

Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious …

Jan 14, 2025
CVE-2025-21139
7.8 HIGH

Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jan 14, 2025
CVE-2025-21138
7.8 HIGH

Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21137
7.8 HIGH

Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jan 14, 2025
CVE-2025-21136
7.8 HIGH

Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21135
7.8 HIGH

Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Jan 14, 2025
CVE-2024-55924
8.0 HIGH

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55921
7.5 HIGH

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-48858
7.5 HIGH

Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …

Jan 14, 2025
CVE-2025-23042
7.5 HIGH

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. …

Jan 14, 2025
CVE-2025-21134
7.8 HIGH

Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Jan 14, 2025
CVE-2025-21133
7.8 HIGH

Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Jan 14, 2025
CVE-2025-21132
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21131
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21130
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21129
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.