CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29925
5.3 MEDIUM

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if …

Mar 19, 2025
CVE-2025-29405
6.3 MEDIUM

An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a …

Mar 19, 2025
CVE-2024-25132
4.3 MEDIUM

A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to …

Mar 19, 2025
CVE-2025-29118
6.5 MEDIUM

Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.

Mar 19, 2025
CVE-2025-0431
5.8 MEDIUM

Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity …

Mar 19, 2025
CVE-2024-53970
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Mar 19, 2025
CVE-2024-53969
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in …

Mar 19, 2025
CVE-2024-53968
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in …

Mar 19, 2025
CVE-2024-53967
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in …

Mar 19, 2025
CVE-2025-30196
6.5 MEDIUM

Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulting in a stored …

Mar 19, 2025
CVE-2025-30152
6.5 MEDIUM

The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows …

Mar 19, 2025
CVE-2025-30144
6.5 MEDIUM

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly validate the iss claim based on the RFC …

Mar 19, 2025
CVE-2025-2324
5.9 MEDIUM

Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 …

Mar 19, 2025
CVE-2025-29770
6.5 MEDIUM

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the backends used by vLLM to support …

Mar 19, 2025
CVE-2025-26486
6.0 MEDIUM

Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable …

Mar 19, 2025
CVE-2025-26485
5.8 MEDIUM

A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usage of a wrong …

Mar 19, 2025
CVE-2025-26475
5.5 MEDIUM

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping containers running during daemon restarts, reducing …

Mar 19, 2025
CVE-2025-23382
5.5 MEDIUM

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A …

Mar 19, 2025
CVE-2025-1758
4.3 MEDIUM

Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 …

Mar 19, 2025
CVE-2025-1472
4.3 MEDIUM

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No …

Mar 19, 2025
CVE-2025-2511
4.9 MEDIUM

The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.6 due …

Mar 19, 2025
CVE-2024-45644
4.7 MEDIUM

IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

Mar 19, 2025
CVE-2025-27018
6.3 MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql …

Mar 19, 2025
CVE-2024-12136
6.9 MEDIUM

Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass.This issue affects ANKA JPD-00028: before V.01.01.

Mar 19, 2025
CVE-2024-50629
5.3 MEDIUM

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, …

Mar 19, 2025
CVE-2025-2290
5.3 MEDIUM

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability …

Mar 19, 2025
CVE-2024-10445
4.3 MEDIUM

Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 …

Mar 19, 2025
CVE-2024-57151
6.8 MEDIUM

SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function

Mar 18, 2025
CVE-2025-30138
4.6 MEDIUM

An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized …

Mar 18, 2025
CVE-2025-29790
5.4 MEDIUM

Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. …

Mar 18, 2025
CVE-2025-27080
6.0 MEDIUM

Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to …

Mar 18, 2025
CVE-2025-25042
4.3 MEDIUM

A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an …

Mar 18, 2025
CVE-2025-2487
4.9 MEDIUM

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the …

Mar 18, 2025
CVE-2025-26138
6.5 MEDIUM

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users …

Mar 18, 2025
CVE-2025-25586
4.2 MEDIUM

yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.

Mar 18, 2025
CVE-2025-25582
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

Mar 18, 2025
CVE-2024-57170
6.5 MEDIUM

SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences …

Mar 18, 2025
CVE-2025-30110
6.5 MEDIUM

On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism relies solely on MAC address verification, …

Mar 18, 2025
CVE-2025-30109
6.5 MEDIUM

In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded …

Mar 18, 2025
CVE-2025-25590
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.

Mar 18, 2025
CVE-2025-25580
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.

Mar 18, 2025
CVE-2024-49822
4.1 MEDIUM

IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Mar 18, 2025
CVE-2024-44314
6.5 MEDIUM

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the …

Mar 18, 2025
CVE-2025-2495
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to upload XML files to the server with JavaScript …

Mar 18, 2025
CVE-2025-0694
6.6 MEDIUM

Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

Mar 18, 2025
CVE-2024-41975
5.3 MEDIUM

An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the …

Mar 18, 2025
CVE-2025-2471
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unknown function of the file /boat-details.php. The …

Mar 18, 2025
CVE-2025-2420
4.3 MEDIUM

A vulnerability classified as problematic was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. Affected by this vulnerability is an unknown functionality. The manipulation leads to …

Mar 17, 2025
CVE-2025-2419
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /InsertFeedback.php. …

Mar 17, 2025
CVE-2025-29781
6.5 MEDIUM

The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator enables users to load Secret from arbitrary …

Mar 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.