CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31283
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-31282
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-20203
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Apr 2, 2025
CVE-2025-20120
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to …

Apr 2, 2025
CVE-2025-0154
5.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers.

Apr 2, 2025
CVE-2024-56476
5.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.

Apr 2, 2025
CVE-2024-56475
5.4 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Apr 2, 2025
CVE-2024-56474
4.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Apr 2, 2025
CVE-2025-31728
5.5 MEDIUM

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe …

Apr 2, 2025
CVE-2025-31727
5.5 MEDIUM

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by …

Apr 2, 2025
CVE-2025-31726
5.5 MEDIUM

Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be …

Apr 2, 2025
CVE-2025-31725
5.5 MEDIUM

Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read …

Apr 2, 2025
CVE-2025-31724
4.3 MEDIUM

Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be …

Apr 2, 2025
CVE-2025-31723
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to change and reset the build queue order.

Apr 2, 2025
CVE-2025-31721
4.3 MEDIUM

A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an …

Apr 2, 2025
CVE-2025-31720
4.3 MEDIUM

A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy …

Apr 2, 2025
CVE-2024-56341
5.4 MEDIUM

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Apr 2, 2025
CVE-2024-25051
6.6 MEDIUM

IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on …

Apr 2, 2025
CVE-2025-21994
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field of smb_acl parse_dcal() validate num_aces to allocate posix_ace_state_array. …

Apr 2, 2025
CVE-2024-50597
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial …

Apr 2, 2025
CVE-2024-50596
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial …

Apr 2, 2025
CVE-2024-50595
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead …

Apr 2, 2025
CVE-2024-50594
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead …

Apr 2, 2025
CVE-2024-50385
6.5 MEDIUM

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to …

Apr 2, 2025
CVE-2024-50384
6.5 MEDIUM

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to …

Apr 2, 2025
CVE-2025-27556
5.8 MEDIUM

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, …

Apr 2, 2025
CVE-2025-21992
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera The HP 5MP Camera (USB ID 0408:5473) …

Apr 2, 2025
CVE-2025-21990
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flags PRT BOs may not have …

Apr 2, 2025
CVE-2025-21989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix missing .is_two_pixels_per_container Starting from 6.11, AMDGPU driver, while being loaded with amdgpu.dc=1, due …

Apr 2, 2025
CVE-2025-21988
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending …

Apr 2, 2025
CVE-2025-21987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_buffer Otherwise an uninitialized value can be returned if amdgpu_res_cleared …

Apr 2, 2025
CVE-2025-1805
5.3 MEDIUM

Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.

Apr 2, 2025
CVE-2025-2842
4.3 MEDIUM

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo …

Apr 2, 2025
CVE-2025-2786
4.3 MEDIUM

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This …

Apr 2, 2025
CVE-2025-3099
6.1 MEDIUM

The Advanced Search by My Solr Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This …

Apr 2, 2025
CVE-2025-3098
6.1 MEDIUM

The Video Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.0.0.3 due …

Apr 2, 2025
CVE-2025-3097
6.1 MEDIUM

The wp Time Machine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.0. This is due to …

Apr 2, 2025
CVE-2025-2513
6.4 MEDIUM

The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Apr 2, 2025
CVE-2025-2483
6.1 MEDIUM

The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘receip_address’ parameter in all versions up to, and including, 1.1.0 …

Apr 2, 2025
CVE-2024-13637
6.5 MEDIUM

The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin function in all …

Apr 2, 2025
CVE-2024-12410
4.9 MEDIUM

The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versions up to, and including, 3.2.32 due …

Apr 2, 2025
CVE-2024-45700
6.5 MEDIUM

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will …

Apr 2, 2025
CVE-2024-45699
5.4 MEDIUM

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML …

Apr 2, 2025
CVE-2025-27244
5.9 MEDIUM

AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitive information may be obtained by …

Apr 2, 2025
CVE-2025-2779
6.5 MEDIUM

The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Apr 2, 2025
CVE-2025-3074
5.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Apr 2, 2025
CVE-2025-3073
5.4 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Apr 2, 2025
CVE-2025-3072
5.4 MEDIUM

Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Apr 2, 2025
CVE-2025-3071
5.4 MEDIUM

Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Apr 2, 2025
CVE-2025-3070
6.5 MEDIUM

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML …

Apr 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.