CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21500
6.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and …

Jan 21, 2025
CVE-2025-21499
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.3 and prior and 9.1.0 and prior. …

Jan 21, 2025
CVE-2025-21498
5.3 MEDIUM

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows …

Jan 21, 2025
CVE-2025-21497
5.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 …

Jan 21, 2025
CVE-2025-21495
4.4 MEDIUM

Vulnerability in the MySQL Enterprise Firewall product of Oracle MySQL (component: Firewall). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and …

Jan 21, 2025
CVE-2025-21494
4.1 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior …

Jan 21, 2025
CVE-2025-21493
4.4 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.4.3 and prior and 9.1.0 and …

Jan 21, 2025
CVE-2025-21492
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable …

Jan 21, 2025
CVE-2025-21491
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 …

Jan 21, 2025
CVE-2025-21490
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 …

Jan 21, 2025
CVE-2025-21489
6.1 MEDIUM

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability …

Jan 21, 2025
CVE-2024-57545
5.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57544
5.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57543
5.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57541
5.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57540
6.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57538
6.5 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_protect_status) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57537
6.3 MEDIUM

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification.

Jan 21, 2025
CVE-2024-57360
5.5 MEDIUM

https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.

Jan 21, 2025
CVE-2024-55958
4.8 MEDIUM

Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.

Jan 21, 2025
CVE-2024-48392
5.4 MEDIUM

OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, …

Jan 21, 2025
CVE-2024-21245
5.4 MEDIUM

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to …

Jan 21, 2025
CVE-2023-45908
6.1 MEDIUM

Homarr before v0.14.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notebook widget.

Jan 21, 2025
CVE-2024-55504
5.5 MEDIUM

An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized …

Jan 21, 2025
CVE-2024-51417
6.4 MEDIUM

An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static properties/fields.

Jan 21, 2025
CVE-2025-24461
6.5 MEDIUM

In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint

Jan 21, 2025
CVE-2025-24460
4.3 MEDIUM

In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool

Jan 21, 2025
CVE-2025-24459
4.6 MEDIUM

In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page

Jan 21, 2025
CVE-2025-24457
5.5 MEDIUM

In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs

Jan 21, 2025
CVE-2025-24456
6.7 MEDIUM

In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

Jan 21, 2025
CVE-2025-24020
6.1 MEDIUM

WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` endpoint of versions up to and including 3.2.10 …

Jan 21, 2025
CVE-2025-23996
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in AnyRoad AnyRoad anyguide allows Cross Site Request Forgery.This issue affects AnyRoad: from n/a through <= 1.3.2.

Jan 21, 2025
CVE-2025-22722
4.3 MEDIUM

Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= …

Jan 21, 2025
CVE-2025-22721
4.3 MEDIUM

Missing Authorization vulnerability in Farhan Noor ApplyOnline apply-online allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline: from n/a through <= 2.6.7.1.

Jan 21, 2025
CVE-2025-22661
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payments – Get Paid with PayPal, Square & Stripe paypal-payment-button-by-vcita allows …

Jan 21, 2025
CVE-2025-22276
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enguerranws Related Post Shortcode related-post-shortcode allows Stored XSS.This issue affects Related Post Shortcode: …

Jan 21, 2025
CVE-2025-22267
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweaver Weaver Themes Shortcode Compatibility weaver-themes-shortcode-compatibility allows Stored XSS.This issue affects Weaver Themes …

Jan 21, 2025
CVE-2025-22150
6.8 MEDIUM

Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for …

Jan 21, 2025
CVE-2024-54795
5.4 MEDIUM

SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.

Jan 21, 2025
CVE-2024-54792
6.1 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into …

Jan 21, 2025
CVE-2025-24012
4.6 MEDIUM

Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are …

Jan 21, 2025
CVE-2025-24011
5.3 MEDIUM

Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible to …

Jan 21, 2025
CVE-2024-56990
4.5 MEDIUM

PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php.

Jan 21, 2025
CVE-2024-56998
4.2 MEDIUM

PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address.

Jan 21, 2025
CVE-2024-56997
4.2 MEDIUM

PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter.

Jan 21, 2025
CVE-2025-23997
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tamara Solution Tamara Checkout tamara-checkout allows Stored XSS.This issue affects Tamara Checkout: from …

Jan 21, 2025
CVE-2025-22825
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible PDF Coupons flexible-coupons allows Stored XSS.This issue affects Flexible PDF Coupons: …

Jan 21, 2025
CVE-2025-22732
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Admiral Ad Blocking Detector ad-blocking-detector allows Stored XSS.This issue affects Ad Blocking Detector: …

Jan 21, 2025
CVE-2025-22727
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps MailChimp Subscribe Forms mailchimp-subscribe-sm allows Stored XSS.This issue affects MailChimp Subscribe Forms …

Jan 21, 2025
CVE-2025-22718
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Event Lite fat-event-lite allows Stored XSS.This issue affects FAT Event Lite: …

Jan 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.