CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22980
6.7 MEDIUM

A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.

Jan 22, 2025
CVE-2025-0604
5.4 MEDIUM

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate …

Jan 22, 2025
CVE-2024-24432
5.3 MEDIUM

A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

Jan 22, 2025
CVE-2023-37012
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37011
6.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37010
6.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37009
6.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37008
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in …

Jan 22, 2025
CVE-2023-37007
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37006
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37005
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37004
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37003
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2023-37002
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025
CVE-2025-0395
6.2 MEDIUM

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message …

Jan 22, 2025
CVE-2024-13447
4.3 MEDIUM

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action …

Jan 22, 2025
CVE-2022-23439
4.7 MEDIUM

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the …

Jan 22, 2025
CVE-2024-13361
6.3 MEDIUM

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in …

Jan 22, 2025
CVE-2024-13360
5.4 MEDIUM

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the …

Jan 22, 2025
CVE-2024-13319
6.1 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Jan 22, 2025
CVE-2024-13406
6.1 MEDIUM

The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and …

Jan 22, 2025
CVE-2024-12117
6.4 MEDIUM

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the Button block in …

Jan 22, 2025
CVE-2025-23237
6.6 MEDIUM

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs …

Jan 22, 2025
CVE-2024-12879
4.3 MEDIUM

The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qc_wp_latest_update_check_pro' function …

Jan 22, 2025
CVE-2024-13590
6.4 MEDIUM

The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, and including, 0.1.2 …

Jan 22, 2025
CVE-2024-13584
6.4 MEDIUM

The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode in …

Jan 22, 2025
CVE-2024-13426
5.4 MEDIUM

The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping on …

Jan 22, 2025
CVE-2023-37039
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allow network-adjacent attackers to crash …

Jan 22, 2025
CVE-2024-49736
5.5 MEDIUM

In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. …

Jan 21, 2025
CVE-2024-49733
5.5 MEDIUM

In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic …

Jan 21, 2025
CVE-2024-43763
6.5 MEDIUM

In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (proximal/adjacent) …

Jan 21, 2025
CVE-2024-24443
6.5 MEDIUM

An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) …

Jan 21, 2025
CVE-2023-40108
5.5 MEDIUM

In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead …

Jan 21, 2025
CVE-2023-37038
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37037
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37036
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37035
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37034
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37033
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37031
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37030
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37028
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37027
6.5 MEDIUM

Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the …

Jan 21, 2025
CVE-2023-37026
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2023-37025
6.5 MEDIUM

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash …

Jan 21, 2025
CVE-2024-45478
4.8 MEDIUM

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger …

Jan 21, 2025
CVE-2024-24445
6.5 MEDIUM

OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protocol messages which allows an attacker with network-adjacent access …

Jan 21, 2025
CVE-2025-21570
6.1 MEDIUM

Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login). The supported version that is affected is 8.2.3. Easily …

Jan 21, 2025
CVE-2025-21569
6.6 MEDIUM

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). The supported version that is affected is 11.2.19.0.000. Difficult to …

Jan 21, 2025
CVE-2025-21568
4.5 MEDIUM

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security). The supported version that is affected is 11.2.19.0.000. Easily …

Jan 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.