CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13416
4.3 MEDIUM

Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has released an updated …

Feb 6, 2025
CVE-2024-36557
6.6 MEDIUM

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious …

Feb 6, 2025
CVE-2025-22866
4.0 MEDIUM

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars …

Feb 6, 2025
CVE-2025-1078
5.3 MEDIUM

A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection …

Feb 6, 2025
CVE-2024-57599
4.8 MEDIUM

Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in …

Feb 6, 2025
CVE-2024-57429
5.4 MEDIUM

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an …

Feb 6, 2025
CVE-2024-57427
6.1 MEDIUM

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a …

Feb 6, 2025
CVE-2024-13614
5.3 MEDIUM

Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small …

Feb 6, 2025
CVE-2022-40490
4.8 MEDIUM

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via …

Feb 6, 2025
CVE-2025-1076
4.8 MEDIUM

A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload …

Feb 6, 2025
CVE-2025-1074
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component …

Feb 6, 2025
CVE-2024-24911
5.3 MEDIUM

In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the …

Feb 6, 2025
CVE-2024-57962
6.1 MEDIUM

Vulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this vulnerability may affect availability.

Feb 6, 2025
CVE-2024-57961
6.8 MEDIUM

Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57959
6.1 MEDIUM

Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57958
5.7 MEDIUM

Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57957
6.6 MEDIUM

Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-57955
6.1 MEDIUM

Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-57954
6.2 MEDIUM

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-12602
6.2 MEDIUM

Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-45626
6.5 MEDIUM

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in …

Feb 6, 2025
CVE-2025-0859
6.5 MEDIUM

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up …

Feb 6, 2025
CVE-2025-24845
5.5 MEDIUM

Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially …

Feb 6, 2025
CVE-2025-24483
5.5 MEDIUM

NULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of …

Feb 6, 2025
CVE-2025-0522
4.7 MEDIUM

The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Feb 6, 2025
CVE-2025-0799
6.5 MEDIUM

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system …

Feb 6, 2025
CVE-2024-49800
4.3 MEDIUM

IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

Feb 6, 2025
CVE-2024-49798
4.3 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information …

Feb 6, 2025
CVE-2024-49797
5.9 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker …

Feb 6, 2025
CVE-2024-49796
5.4 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web …

Feb 6, 2025
CVE-2024-49795
4.3 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that …

Feb 6, 2025
CVE-2024-49794
4.3 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that …

Feb 6, 2025
CVE-2024-49793
5.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025
CVE-2024-49792
5.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025
CVE-2024-49791
6.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025
CVE-2024-56473
5.3 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper …

Feb 5, 2025
CVE-2024-56472
6.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the …

Feb 5, 2025
CVE-2024-56471
5.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from …

Feb 5, 2025
CVE-2024-56470
5.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from …

Feb 5, 2025
CVE-2024-38318
4.8 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Feb 5, 2025
CVE-2024-38317
4.8 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the …

Feb 5, 2025
CVE-2024-38316
4.3 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in …

Feb 5, 2025
CVE-2024-57598
6.5 MEDIUM

A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial …

Feb 5, 2025
CVE-2024-57082
6.5 MEDIUM

A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-54853
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads …

Feb 5, 2025
CVE-2025-24805
5.5 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is …

Feb 5, 2025
CVE-2025-24804
4.3 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, …

Feb 5, 2025
CVE-2025-24803
5.4 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, …

Feb 5, 2025
CVE-2025-24319
6.5 MEDIUM

When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes …

Feb 5, 2025
CVE-2025-23419
4.3 MEDIUM

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication …

Feb 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.