CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40635
4.6 MEDIUM

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User …

Mar 17, 2025
CVE-2025-2393
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the …

Mar 17, 2025
CVE-2025-29426
4.6 MEDIUM

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters.

Mar 17, 2025
CVE-2025-2392
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing …

Mar 17, 2025
CVE-2025-26393
5.4 MEDIUM

SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.

Mar 17, 2025
CVE-2025-24185
5.5 MEDIUM

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Parsing …

Mar 17, 2025
CVE-2024-54565
6.2 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.

Mar 17, 2025
CVE-2024-54559
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.

Mar 17, 2025
CVE-2025-2390
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /user_dashboard/add_donor.php. The …

Mar 17, 2025
CVE-2025-2389
4.7 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 17, 2025
CVE-2025-29427
5.9 MEDIUM

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.

Mar 17, 2025
CVE-2025-29425
5.5 MEDIUM

Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.

Mar 17, 2025
CVE-2025-26042
6.0 MEDIUM

Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it …

Mar 17, 2025
CVE-2024-8510
5.3 MEDIUM

N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is …

Mar 17, 2025
CVE-2024-44866
6.8 MEDIUM

A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) …

Mar 17, 2025
CVE-2025-29430
4.1 MEDIUM

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.

Mar 17, 2025
CVE-2025-29429
6.1 MEDIUM

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.

Mar 17, 2025
CVE-2024-48828
5.5 MEDIUM

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit …

Mar 17, 2025
CVE-2024-48017
6.5 MEDIUM

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high …

Mar 17, 2025
CVE-2024-48015
6.7 MEDIUM

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high …

Mar 17, 2025
CVE-2025-22474
6.8 MEDIUM

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially …

Mar 17, 2025
CVE-2025-30143
5.4 MEDIUM

Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in …

Mar 17, 2025
CVE-2025-2384
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file …

Mar 17, 2025
CVE-2025-26127
5.0 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via …

Mar 17, 2025
CVE-2025-25621
4.3 MEDIUM

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.

Mar 17, 2025
CVE-2025-29788
6.5 MEDIUM

The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 …

Mar 17, 2025
CVE-2024-9055
4.2 MEDIUM

The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract …

Mar 17, 2025
CVE-2021-32584
5.3 MEDIUM

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to …

Mar 17, 2025
CVE-2021-26087
4.3 MEDIUM

An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface …

Mar 17, 2025
CVE-2021-22126
6.7 MEDIUM

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may …

Mar 17, 2025
CVE-2020-9295
4.7 MEDIUM

FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version …

Mar 17, 2025
CVE-2020-29010
5.0 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to …

Mar 17, 2025
CVE-2019-6697
5.3 MEDIUM

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP …

Mar 17, 2025
CVE-2019-15706
4.1 MEDIUM

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version …

Mar 17, 2025
CVE-2025-2374
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This issue affects some unknown processing of …

Mar 17, 2025
CVE-2025-2373
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This vulnerability affects unknown code of the file /check_availability.php. The …

Mar 17, 2025
CVE-2025-2368
6.3 MEDIUM

A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the …

Mar 17, 2025
CVE-2025-2367
6.3 MEDIUM

A vulnerability has been found in Oiwtech OIW-2431APGN-HP 2.5.3-B20131128 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formScript of the component …

Mar 17, 2025
CVE-2025-2365
6.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the …

Mar 17, 2025
CVE-2025-2363
6.3 MEDIUM

A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation …

Mar 17, 2025
CVE-2025-2361
4.3 MEDIUM

A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The …

Mar 17, 2025
CVE-2025-2358
6.3 MEDIUM

A vulnerability was found in Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System 1.0. It has been rated as critical. This issue affects some …

Mar 17, 2025
CVE-2025-2357
6.3 MEDIUM

A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS Decoder. The …

Mar 17, 2025
CVE-2025-30089
5.4 MEDIUM

gurk (aka gurk-rs) through 0.6.3 mishandles ANSI escape sequences.

Mar 17, 2025
CVE-2025-2354
4.3 MEDIUM

A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 17, 2025
CVE-2025-2350
6.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown …

Mar 16, 2025
CVE-2025-2348
4.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the …

Mar 16, 2025
CVE-2025-2347
6.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component …

Mar 16, 2025
CVE-2025-2346
5.6 MEDIUM

A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown …

Mar 16, 2025
CVE-2025-2344
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this …

Mar 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.