CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2409
9.1 CRITICAL

File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS …

May 22, 2025
CVE-2024-9639
8.0 HIGH

Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX …

May 22, 2025
CVE-2024-52874
8.8 HIGH

In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.

May 22, 2025
CVE-2024-13931
7.2 HIGH

Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: …

May 22, 2025
CVE-2024-13930
4.9 MEDIUM

An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects …

May 22, 2025
CVE-2024-13929
7.2 HIGH

Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; …

May 22, 2025
CVE-2024-13928
7.2 HIGH

SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; …

May 22, 2025
CVE-2025-48061
5.6 MEDIUM

wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user …

May 22, 2025
CVE-2025-47780
7.8 HIGH

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, …

May 22, 2025
CVE-2025-47779
7.7 HIGH

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, …

May 22, 2025
CVE-2025-46716
5.5 MEDIUM

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_SetSecureParam fails …

May 22, 2025
CVE-2025-46715
7.8 HIGH

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_GetSecureParam fails …

May 22, 2025
CVE-2025-45472
8.8 HIGH

Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.

May 22, 2025
CVE-2025-43596
7.8 HIGH

An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially …

May 22, 2025
CVE-2025-33138
5.4 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

May 22, 2025
CVE-2025-33137
7.1 HIGH

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due …

May 22, 2025
CVE-2025-33136
7.1 HIGH

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due …

May 22, 2025
CVE-2024-48853
9.0 CRITICAL

An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. …

May 22, 2025
CVE-2024-48850
7.2 HIGH

Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: …

May 22, 2025
CVE-2025-5081
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminprofile.php. …

May 22, 2025
CVE-2025-4366
6.1 MEDIUM

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading …

May 22, 2025
CVE-2025-45468
8.8 HIGH

Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.

May 22, 2025
CVE-2025-2506
5.3 MEDIUM

When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a …

May 22, 2025
CVE-2025-23183
6.1 MEDIUM

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

May 22, 2025
CVE-2025-23182
4.3 MEDIUM

CWE-203: Observable Discrepancy

May 22, 2025
CVE-2025-5080
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the …

May 22, 2025
CVE-2025-5079
7.3 HIGH

A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/updateorder.php. Executing manipulation …

May 22, 2025
CVE-2025-5024
7.4 HIGH

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There …

May 22, 2025
CVE-2025-45471
8.8 HIGH

Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.

May 22, 2025
CVE-2025-32915
5.5 MEDIUM

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 …

May 22, 2025
CVE-2025-32815
6.5 MEDIUM

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

May 22, 2025
CVE-2025-32814
9.8 CRITICAL

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

May 22, 2025
CVE-2025-32813
7.2 HIGH

An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

May 22, 2025
CVE-2025-0993
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated …

May 22, 2025
CVE-2025-0679
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions …

May 22, 2025
CVE-2025-0605
4.6 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls …

May 22, 2025
CVE-2024-54188
5.3 MEDIUM

Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root access.

May 22, 2025
CVE-2024-12093
6.8 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation …

May 22, 2025
CVE-2025-5078
7.3 HIGH

A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. Performing manipulation of the argument Category …

May 22, 2025
CVE-2025-5077
7.3 HIGH

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. …

May 22, 2025
CVE-2025-5076
7.3 HIGH

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component SEND …

May 22, 2025
CVE-2025-4979
4.9 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able …

May 22, 2025
CVE-2025-4575
6.5 MEDIUM

Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: …

May 22, 2025
CVE-2025-3111
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of …

May 22, 2025
CVE-2025-2853
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation …

May 22, 2025
CVE-2025-1110
2.7 LOW

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access …

May 22, 2025
CVE-2023-47466
2.9 LOW

TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the …

May 22, 2025
CVE-2025-5075
7.3 HIGH

A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component …

May 22, 2025
CVE-2025-46714
7.8 HIGH

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an …

May 22, 2025
CVE-2025-46713
7.8 HIGH

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 0.0.1 and prior to 1.15.12, API_SET_SECURE_PARAM may have …

May 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.