CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34398
4.2 MEDIUM

An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers.

Mar 12, 2025
CVE-2025-2002
6.0 MEDIUM

CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, …

Mar 12, 2025
CVE-2025-27867
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: …

Mar 12, 2025
CVE-2025-25566
5.6 MEDIUM

Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function. NOTE: the Supplier disputes this because …

Mar 12, 2025
CVE-2025-20177
6.7 MEDIUM

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR image signature verification …

Mar 12, 2025
CVE-2025-20145
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to …

Mar 12, 2025
CVE-2025-20144
4.0 MEDIUM

A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to …

Mar 12, 2025
CVE-2025-20143
6.7 MEDIUM

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot …

Mar 12, 2025
CVE-2025-1984
5.2 MEDIUM

Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low-privileged user to gain SYSTEM-level access.

Mar 12, 2025
CVE-2025-0813
6.8 MEDIUM

CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights has physical access to the EPAS-UI computer …

Mar 12, 2025
CVE-2025-29891
4.8 MEDIUM

Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended …

Mar 12, 2025
CVE-2025-27915
5.4 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client …

Mar 12, 2025
CVE-2025-27914
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing …

Mar 12, 2025
CVE-2024-27763
5.3 MEDIUM

XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST …

Mar 12, 2025
CVE-2025-27794
6.8 MEDIUM

Flarum is open-source forum software. A session hijacking vulnerability exists in versions prior to 1.8.10 when an attacker-controlled authoritative subdomain under a parent domain (e.g., …

Mar 12, 2025
CVE-2025-21590
4.4 MEDIUM KEV

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity …

Mar 12, 2025
CVE-2024-52362
4.3 MEDIUM

IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, …

Mar 12, 2025
CVE-2025-29904
5.3 MEDIUM

In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible

Mar 12, 2025
CVE-2025-29903
5.2 MEDIUM

In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible

Mar 12, 2025
CVE-2025-1527
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a …

Mar 12, 2025
CVE-2024-13870
5.7 MEDIUM

An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware …

Mar 12, 2025
CVE-2025-2239
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.

Mar 12, 2025
CVE-2025-21866
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC Erhard reported the …

Mar 12, 2025
CVE-2025-21865
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl(). Brad Spengler reported the list_del() corruption splat in …

Mar 12, 2025
CVE-2025-21864
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: drop secpath at the same time as we currently drop dst Xiumei reported hitting …

Mar 12, 2025
CVE-2025-21862
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix incorrect initialization order Syzkaller reports the following bug: BUG: spinlock bad magic on …

Mar 12, 2025
CVE-2025-21861
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() If migration succeeded, we …

Mar 12, 2025
CVE-2025-21859
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: f_midi: f_midi_complete to call queue_work When using USB MIDI, a lock is attempted …

Mar 12, 2025
CVE-2025-21857
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix error handling causing NULL dereference tcf_exts_miss_cookie_base_alloc() calls xa_alloc_cyclic() which can return 1 …

Mar 12, 2025
CVE-2025-21854
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sockmap, vsock: For connectible sockets allow only connected sockmap expects all vsocks to have a …

Mar 12, 2025
CVE-2025-21853
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: avoid holding freeze_mutex during mmap operation We use map->freeze_mutex to prevent races between map_freeze() …

Mar 12, 2025
CVE-2025-21852
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Add rx_skb of kfree_skb to raw_tp_null_args[]. Yan Zhai reported a BPF prog could trigger …

Mar 12, 2025
CVE-2025-21850
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: Fix crash when a namespace is disabled The namespace percpu counter protects pending I/O, …

Mar 12, 2025
CVE-2025-21849
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Use spin_lock_irqsave() in interruptible context spin_lock/unlock() functions used in interrupt contexts could result in …

Mar 12, 2025
CVE-2025-21848
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() Add check for the return value of nfp_app_ctrl_msg_alloc() in …

Mar 12, 2025
CVE-2025-21847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data() The nullity of sps->cstream should be …

Mar 12, 2025
CVE-2025-21846
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: acct: perform last write from workqueue In [1] it was reported that the acct(2) system …

Mar 12, 2025
CVE-2025-21845
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: sst: Fix SST write failure 'commit 18bcb4aa54ea ("mtd: spi-nor: sst: Factor out common …

Mar 12, 2025
CVE-2025-21844
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of …

Mar 12, 2025
CVE-2024-58089
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_delalloc_range() failed [BUG] When running btrfs with block size …

Mar 12, 2025
CVE-2024-58088
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock when freeing cgroup storage The following commit bc235cdb423a ("bpf: Prevent deadlock from …

Mar 12, 2025
CVE-2024-13430
4.3 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Mar 12, 2025
CVE-2024-13838
5.5 MEDIUM

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Mar 12, 2025
CVE-2024-12589
6.4 MEDIUM

The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the countdown timer …

Mar 12, 2025
CVE-2024-13498
5.3 MEDIUM

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Mar 12, 2025
CVE-2025-2205
4.4 MEDIUM

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Mar 12, 2025
CVE-2025-2078
4.4 MEDIUM

The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due …

Mar 12, 2025
CVE-2025-2077
6.1 MEDIUM

The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in all versions up to, and including, 1.0.9 …

Mar 12, 2025
CVE-2025-2076
4.4 MEDIUM

The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient …

Mar 12, 2025
CVE-2025-1508
5.3 MEDIUM

The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all …

Mar 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.