CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2174
5.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been declared as problematic. Affected by this vulnerability is the function vbi_strndup_iconv_ucs2 of the …

Mar 11, 2025
CVE-2025-2173
5.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The …

Mar 11, 2025
CVE-2025-26706
5.4 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

Mar 11, 2025
CVE-2025-26705
5.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2025-26704
6.4 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2025-26703
4.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

Mar 11, 2025
CVE-2025-26702
4.9 MEDIUM

Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

Mar 11, 2025
CVE-2024-13228
4.3 MEDIUM

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the …

Mar 11, 2025
CVE-2025-0629
4.8 MEDIUM

The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such …

Mar 11, 2025
CVE-2024-13853
6.1 MEDIUM

The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 11, 2025
CVE-2024-13580
4.3 MEDIUM

The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Mar 11, 2025
CVE-2024-13413
6.1 MEDIUM

The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all versions up to, and including, 1.0.24 due to …

Mar 11, 2025
CVE-2025-26707
5.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2024-13436
6.1 MEDIUM

The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing …

Mar 11, 2025
CVE-2025-27436
4.3 MEDIUM

The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact …

Mar 11, 2025
CVE-2025-27433
4.3 MEDIUM

The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank …

Mar 11, 2025
CVE-2025-27431
5.4 MEDIUM

User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload …

Mar 11, 2025
CVE-2025-26660
4.3 MEDIUM

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This …

Mar 11, 2025
CVE-2025-26659
6.1 MEDIUM

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to …

Mar 11, 2025
CVE-2025-26658
6.8 MEDIUM

The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. …

Mar 11, 2025
CVE-2025-26656
4.3 MEDIUM

OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has …

Mar 11, 2025
CVE-2025-25245
5.4 MEDIUM

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this …

Mar 11, 2025
CVE-2025-25244
5.7 MEDIUM

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the …

Mar 11, 2025
CVE-2025-25242
6.1 MEDIUM

SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no …

Mar 11, 2025
CVE-2025-23194
5.3 MEDIUM

SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to …

Mar 11, 2025
CVE-2025-23188
4.3 MEDIUM

An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond …

Mar 11, 2025
CVE-2025-23185
4.1 MEDIUM

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user …

Mar 11, 2025
CVE-2025-0071
4.9 MEDIUM

SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes …

Mar 11, 2025
CVE-2025-0062
4.7 MEDIUM

SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence reports. This code is then executed in the victim's browser …

Mar 11, 2025
CVE-2024-49823
6.5 MEDIUM

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using …

Mar 11, 2025
CVE-2024-22340
6.5 MEDIUM

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a …

Mar 11, 2025
CVE-2025-27926
4.3 MEDIUM

In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.

Mar 10, 2025
CVE-2025-27924
5.4 MEDIUM

Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.

Mar 10, 2025
CVE-2025-25908
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Mar 10, 2025
CVE-2025-0660
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin …

Mar 10, 2025
CVE-2022-48610
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2. An app …

Mar 10, 2025
CVE-2025-26695
5.3 MEDIUM

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of …

Mar 10, 2025
CVE-2024-56188
5.1 MEDIUM

there is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no …

Mar 10, 2025
CVE-2024-56187
6.6 MEDIUM

In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the code. This could lead to …

Mar 10, 2025
CVE-2024-56186
5.1 MEDIUM

In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Mar 10, 2025
CVE-2024-56185
5.1 MEDIUM

In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband …

Mar 10, 2025
CVE-2024-56184
5.1 MEDIUM

In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local …

Mar 10, 2025
CVE-2024-54560
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. …

Mar 10, 2025
CVE-2024-54473
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to access …

Mar 10, 2025
CVE-2024-54469
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura …

Mar 10, 2025
CVE-2024-54467
6.5 MEDIUM

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, …

Mar 10, 2025
CVE-2024-54463
5.5 MEDIUM

This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without …

Mar 10, 2025
CVE-2024-44192
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS …

Mar 10, 2025
CVE-2025-1296
6.5 MEDIUM

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, …

Mar 10, 2025
CVE-2024-55199
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file …

Mar 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.