CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1877
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the component HTTP POST Request Handler. …

Mar 3, 2025
CVE-2024-30154
5.3 MEDIUM

HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that …

Mar 3, 2025
CVE-2025-27371
6.9 MEDIUM

In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the …

Mar 3, 2025
CVE-2025-27370
6.9 MEDIUM

OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt authentication mechanism is used, a malicious Authorization Server …

Mar 3, 2025
CVE-2025-0686
6.4 MEDIUM

A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses user-controlled parameters from the filesystem …

Mar 3, 2025
CVE-2025-0685
6.4 MEDIUM

A flaw was found in grub2. When reading data from a jfs filesystem, grub's jfs filesystem module uses user-controlled parameters from the filesystem geometry to …

Mar 3, 2025
CVE-2025-0684
6.4 MEDIUM

A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses user-controlled parameters from the filesystem …

Mar 3, 2025
CVE-2024-53384
5.1 MEDIUM

A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components

Mar 3, 2025
CVE-2024-51091
5.4 MEDIUM

Cross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary code via the seajs package

Mar 3, 2025
CVE-2023-49031
5.1 MEDIUM

Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information …

Mar 3, 2025
CVE-2025-25302
6.5 MEDIUM

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows …

Mar 3, 2025
CVE-2025-0287
5.1 MEDIUM

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the …

Mar 3, 2025
CVE-2024-57240
5.4 MEDIUM

A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted …

Mar 3, 2025
CVE-2024-45778
4.1 MEDIUM

A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to …

Mar 3, 2025
CVE-2025-27420
5.4 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in …

Mar 3, 2025
CVE-2025-27418
5.4 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in …

Mar 3, 2025
CVE-2025-27417
6.1 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in …

Mar 3, 2025
CVE-2025-27099
4.8 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in …

Mar 3, 2025
CVE-2025-27094
5.4 MEDIUM

Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user with access to a tracker could force-reset certain field …

Mar 3, 2025
CVE-2024-55570
5.4 MEDIUM

/api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenticated users of the application to …

Mar 3, 2025
CVE-2024-45780
6.7 MEDIUM

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify …

Mar 3, 2025
CVE-2024-45779
6.0 MEDIUM

An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails …

Mar 3, 2025
CVE-2025-27274
4.9 MEDIUM

Path Traversal: '.../...//' vulnerability in axelkeller GPX Viewer gpx-viewer allows Path Traversal.This issue affects GPX Viewer: from n/a through <= 2.2.11.

Mar 3, 2025
CVE-2025-27273
5.8 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager affiliate-links-manager allows Reflected XSS.This issue affects Affiliate Links Manager: …

Mar 3, 2025
CVE-2025-25137
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Stored XSS.This issue affects Social Links: from n/a through <= 1.0.11.

Mar 3, 2025
CVE-2025-25131
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows Stored XSS.This issue affects RJ Quickcharts: from n/a …

Mar 3, 2025
CVE-2025-25115
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zeshan Abdullah Like dislike plus counter like-dislike-plus-counter allows Stored XSS.This issue affects Like …

Mar 3, 2025
CVE-2025-25084
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antrouss UniTimetable unitimetable allows Stored XSS.This issue affects UniTimetable: from n/a through <= …

Mar 3, 2025
CVE-2025-23829
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codingkart Woo Update Variations In Cart woo-update-variations-in-cart allows Stored XSS.This issue affects Woo …

Mar 3, 2025
CVE-2025-23763
6.5 MEDIUM

Missing Authorization vulnerability in Alex Volkov WAH Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WAH Forms: from n/a through 1.0.

Mar 3, 2025
CVE-2025-23615
6.5 MEDIUM

Missing Authorization vulnerability in gtekelis Interactive Page Hierarchy interactive-page-hierarchy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Interactive Page Hierarchy: from n/a through …

Mar 3, 2025
CVE-2025-23613
6.5 MEDIUM

Missing Authorization vulnerability in mediabeta WP Journal wpjournal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Journal: from n/a through <= 1.1.

Mar 3, 2025
CVE-2025-23579
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio DZS Ajaxer Lite dzs-ajaxer-lite-dynamic-page-load allows Stored XSS.This issue affects DZS Ajaxer Lite: …

Mar 3, 2025
CVE-2025-23515
6.5 MEDIUM

Missing Authorization vulnerability in tsecher ts-tree ts-tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ts-tree: from n/a through <= 0.1.1.

Mar 3, 2025
CVE-2025-23480
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MicahBlu RSVP ME rsvp-me allows Stored XSS.This issue affects RSVP ME: from n/a …

Mar 3, 2025
CVE-2025-23440
6.3 MEDIUM

Missing Authorization vulnerability in radicaldesigns radSLIDE radslide allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects radSLIDE: from n/a through <= 2.1.

Mar 3, 2025
CVE-2024-54179
5.4 MEDIUM

IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. This vulnerability …

Mar 3, 2025
CVE-2025-1868
6.8 MEDIUM

Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scanner. It occurs when these applications initiate a network scan, inadvertently …

Mar 3, 2025
CVE-2024-53025
5.5 MEDIUM

Transient DOS can occur while processing UCI command.

Mar 3, 2025
CVE-2024-43056
5.5 MEDIUM

Transient DOS during hypervisor virtual I/O operation in a virtual machine.

Mar 3, 2025
CVE-2024-43051
5.5 MEDIUM

Information disclosure while deriving keys for a session for any Widevine use case.

Mar 3, 2025
CVE-2024-38426
5.4 MEDIUM

While processing the authentication message in UE, improper authentication may lead to information disclosure.

Mar 3, 2025
CVE-2024-24778
6.5 MEDIUM

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: …

Mar 3, 2025
CVE-2024-10925
5.3 MEDIUM

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user …

Mar 3, 2025
CVE-2024-8186
5.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could …

Mar 3, 2025
CVE-2025-25280
5.3 MEDIUM

Buffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by Century Systems Co., Ltd. If this vulnerability …

Mar 3, 2025
CVE-2025-1855
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Mar 3, 2025
CVE-2025-1854
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/del_member.php. …

Mar 3, 2025
CVE-2024-53386
4.9 MEDIUM

Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can …

Mar 3, 2025
CVE-2024-53382
4.9 MEDIUM

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript …

Mar 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.