CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-42450
4.6 MEDIUM

Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

Apr 30, 2025
CVE-2025-30422
6.5 MEDIUM

A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker …

Apr 30, 2025
CVE-2025-24132
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on …

Apr 30, 2025
CVE-2022-42449
4.6 MEDIUM

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

Apr 30, 2025
CVE-2022-27562
4.6 MEDIUM

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

Apr 30, 2025
CVE-2025-4136
5.4 MEDIUM

A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the component Sale Endpoint. The …

Apr 30, 2025
CVE-2024-6029
5.0 MEDIUM

Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected …

Apr 30, 2025
CVE-2025-46554
5.3 MEDIUM

XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and …

Apr 30, 2025
CVE-2025-24887
6.3 MEDIUM

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user …

Apr 30, 2025
CVE-2024-9877
4.3 MEDIUM

: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through …

Apr 30, 2025
CVE-2025-4135
6.3 MEDIUM

A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The manipulation of …

Apr 30, 2025
CVE-2025-39413
4.3 MEDIUM

Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This issue affects Simple Sitemap – Create a Responsive HTML Sitemap: …

Apr 30, 2025
CVE-2025-24091
5.5 MEDIUM

An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An …

Apr 30, 2025
CVE-2025-3859
6.1 MEDIUM

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into …

Apr 30, 2025
CVE-2025-3599
6.5 MEDIUM

Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an …

Apr 30, 2025
CVE-2025-4122
6.3 MEDIUM

A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the function sub_435E04. The manipulation of …

Apr 30, 2025
CVE-2025-32970
6.1 MEDIUM

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, …

Apr 30, 2025
CVE-2025-32376
4.3 MEDIUM

Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a …

Apr 30, 2025
CVE-2025-4121
6.3 MEDIUM

A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmd_wireless. The manipulation of …

Apr 30, 2025
CVE-2025-4119
5.3 MEDIUM

A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the component Product Statistics …

Apr 30, 2025
CVE-2025-4118
5.3 MEDIUM

A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /historyList of the component Product …

Apr 30, 2025
CVE-2025-45021
5.3 MEDIUM

A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email …

Apr 30, 2025
CVE-2025-45019
5.4 MEDIUM

A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code …

Apr 30, 2025
CVE-2025-45015
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. The vulnerability allows remote attackers to inject …

Apr 30, 2025
CVE-2025-45011
5.3 MEDIUM

A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary …

Apr 30, 2025
CVE-2025-45010
5.3 MEDIUM

A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary …

Apr 30, 2025
CVE-2025-45009
5.3 MEDIUM

A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary …

Apr 30, 2025
CVE-2025-4117
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in Netgear JWNR2000v2 1.0.0.11. This affects the function sub_41A914. The manipulation of the argument host leads …

Apr 30, 2025
CVE-2025-45007
4.8 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Generator System v1.0. This vulnerability allows remote attackers to execute …

Apr 30, 2025
CVE-2025-27532
6.5 MEDIUM

A vulnerability in the “Backup & Restore” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to access secret information …

Apr 30, 2025
CVE-2025-24348
5.4 MEDIUM

A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the wireless network …

Apr 30, 2025
CVE-2025-24347
6.5 MEDIUM

A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the network configuration …

Apr 30, 2025
CVE-2025-24345
6.3 MEDIUM

A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the “hosts” file in …

Apr 30, 2025
CVE-2025-24344
6.3 MEDIUM

A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated attacker to inject arbitrary HTML tags and, …

Apr 30, 2025
CVE-2025-24343
5.4 MEDIUM

A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary files …

Apr 30, 2025
CVE-2025-24342
5.3 MEDIUM

A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted …

Apr 30, 2025
CVE-2025-24341
6.5 MEDIUM

A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to induce a Denial-of-Service (DoS) condition on the device via …

Apr 30, 2025
CVE-2025-4113
6.3 MEDIUM

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 30, 2025
CVE-2025-4111
6.3 MEDIUM

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/visitor-details.php. …

Apr 30, 2025
CVE-2025-4110
6.3 MEDIUM

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Apr 30, 2025
CVE-2025-24340
6.5 MEDIUM

A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low-privileged) attacker to recover the plaintext passwords of other users.

Apr 30, 2025
CVE-2025-24339
5.0 MEDIUM

A vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks against users of the vulnerable system, including …

Apr 30, 2025
CVE-2025-4109
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Apr 30, 2025
CVE-2025-2890
6.5 MEDIUM

The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘subscriptionCouponId’ parameter in all versions up to, and including, 1.7 …

Apr 30, 2025
CVE-2025-3953
5.4 MEDIUM

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Apr 30, 2025
CVE-2025-3471
4.9 MEDIUM

The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and …

Apr 30, 2025
CVE-2025-46560
6.5 MEDIUM

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical …

Apr 30, 2025
CVE-2025-46550
4.3 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker …

Apr 29, 2025
CVE-2025-46549
4.3 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from …

Apr 29, 2025
CVE-2025-3910
5.4 MEDIUM

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up …

Apr 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.