CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-35907
5.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise …

Jan 29, 2025
CVE-2025-24792
4.4 MEDIUM

Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated …

Jan 29, 2025
CVE-2025-24374
4.3 MEDIUM

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the …

Jan 29, 2025
CVE-2024-57439
4.9 MEDIUM

An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the …

Jan 29, 2025
CVE-2024-57438
5.4 MEDIUM

Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.

Jan 29, 2025
CVE-2024-57437
6.5 MEDIUM

RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.

Jan 29, 2025
CVE-2025-0353
6.4 MEDIUM

The Divi Torque Lite – Best Divi Addon, Extensions, Modules & Social Modules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets …

Jan 29, 2025
CVE-2024-13561
6.4 MEDIUM

The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_override_yt shortcode in all versions up to, and …

Jan 29, 2025
CVE-2025-0617
5.9 MEDIUM

An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger …

Jan 29, 2025
CVE-2025-0804
6.4 MEDIUM

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 29, 2025
CVE-2025-0806
4.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. …

Jan 29, 2025
CVE-2025-23362
6.1 MEDIUM

The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered …

Jan 29, 2025
CVE-2023-33838
4.4 MEDIUM

IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but …

Jan 29, 2025
CVE-2025-0793
6.3 MEDIUM

A vulnerability has been found in ESAFENET CDG V5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /todoDetail.jsp. …

Jan 29, 2025
CVE-2025-0792
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in ESAFENET CDG V5. Affected is an unknown function of the file /sdTodoDetail.jsp. The manipulation of …

Jan 29, 2025
CVE-2025-0791
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The …

Jan 29, 2025
CVE-2023-35017
5.9 MEDIUM

IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the …

Jan 29, 2025
CVE-2025-0789
6.3 MEDIUM

A vulnerability classified as critical has been found in ESAFENET CDG V5. This affects an unknown part of the file /doneDetail.jsp. The manipulation of the …

Jan 28, 2025
CVE-2025-0788
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Jan 28, 2025
CVE-2025-22917
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a …

Jan 28, 2025
CVE-2025-0786
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG V5. It has been classified as critical. Affected is an unknown function of the file /appDetail.jsp. The manipulation …

Jan 28, 2025
CVE-2024-57514
4.8 MEDIUM

The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When …

Jan 28, 2025
CVE-2024-29869
5.5 MEDIUM

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set …

Jan 28, 2025
CVE-2025-24826
6.7 MEDIUM

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.

Jan 28, 2025
CVE-2024-40674
5.3 MEDIUM

In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could …

Jan 28, 2025
CVE-2024-40673
6.5 MEDIUM

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input …

Jan 28, 2025
CVE-2025-0783
6.3 MEDIUM

A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component API Endpoint. …

Jan 28, 2025
CVE-2025-23057
5.5 MEDIUM

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting …

Jan 28, 2025
CVE-2025-23056
5.5 MEDIUM

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting …

Jan 28, 2025
CVE-2025-23055
5.5 MEDIUM

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting …

Jan 28, 2025
CVE-2025-23054
6.5 MEDIUM

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not …

Jan 28, 2025
CVE-2025-23053
6.5 MEDIUM

A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator …

Jan 28, 2025
CVE-2024-8401
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the …

Jan 28, 2025
CVE-2018-9378
6.2 MEDIUM

In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Jan 28, 2025
CVE-2017-13318
5.7 MEDIUM

In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with …

Jan 28, 2025
CVE-2017-13317
5.7 MEDIUM

In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with …

Jan 28, 2025
CVE-2025-0432
5.7 MEDIUM

EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.

Jan 28, 2025
CVE-2024-7881
5.1 MEDIUM

An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address …

Jan 28, 2025
CVE-2024-6351
4.3 MEDIUM

A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert

Jan 28, 2025
CVE-2024-11956
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of …

Jan 28, 2025
CVE-2025-0754
4.3 MEDIUM

The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the …

Jan 28, 2025
CVE-2025-0750
6.6 MEDIUM

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to …

Jan 28, 2025
CVE-2025-0736
5.5 MEDIUM

A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details …

Jan 28, 2025
CVE-2025-0290
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 …

Jan 28, 2025
CVE-2024-23953
6.5 MEDIUM

Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by …

Jan 28, 2025
CVE-2024-13527
6.4 MEDIUM

The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions …

Jan 28, 2025
CVE-2025-0321
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.7.8 …

Jan 28, 2025
CVE-2024-13521
6.1 MEDIUM

The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to …

Jan 28, 2025
CVE-2024-12807
4.8 MEDIUM

The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 28, 2025
CVE-2024-12723
6.1 MEDIUM

The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.