CVE Database

11833+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37361
9.9 CRITICAL

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 …

Feb 20, 2025
CVE-2025-25196
9.8 CRITICAL

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < …

Feb 19, 2025
CVE-2023-46271
9.8 CRITICAL

Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on …

Feb 19, 2025
CVE-2020-35546
9.1 CRITICAL

Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

Feb 19, 2025
CVE-2025-25467
9.8 CRITICAL

Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.

Feb 18, 2025
CVE-2025-26617
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26615
10.0 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26613
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the …

Feb 18, 2025
CVE-2025-26612
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26611
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26610
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26609
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26608
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26607
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26606
9.8 CRITICAL

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA …

Feb 18, 2025
CVE-2025-26623
9.8 CRITICAL

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer …

Feb 18, 2025
CVE-2025-22654
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious Files.This issue affects Simplified: from n/a through <= 1.0.6.

Feb 18, 2025
CVE-2024-56000
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.

Feb 18, 2025
CVE-2025-24895
9.1 CRITICAL

CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: 1. …

Feb 18, 2025
CVE-2025-24894
9.1 CRITICAL

SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider …

Feb 18, 2025
CVE-2024-55460
9.8 CRITICAL

A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code …

Feb 18, 2025
CVE-2024-39327
9.9 CRITICAL

Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.

Feb 18, 2025
CVE-2024-57049
9.8 CRITICAL

A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under …

Feb 18, 2025
CVE-2024-57045
9.8 CRITICAL

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain …

Feb 18, 2025
CVE-2025-1023
9.8 CRITICAL

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability …

Feb 18, 2025
CVE-2024-12860
9.8 CRITICAL

The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, …

Feb 18, 2025
CVE-2024-13725
9.8 CRITICAL

The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service …

Feb 18, 2025
CVE-2025-25222
9.8 CRITICAL

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability …

Feb 18, 2025
CVE-2025-25221
9.8 CRITICAL

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability …

Feb 18, 2025
CVE-2021-46686
9.8 CRITICAL

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ver.4.0.3 and earlier and acmailer DB ver.1.1.5 …

Feb 18, 2025
CVE-2025-1387
9.8 CRITICAL

Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.

Feb 17, 2025
CVE-2025-22290
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition ltl-freight-quotes-freightquote-edition allows SQL Injection.This …

Feb 16, 2025
CVE-2024-57971
9.1 CRITICAL

DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI …

Feb 16, 2025
CVE-2024-12562
9.8 CRITICAL

The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input …

Feb 15, 2025
CVE-2024-13513
9.8 CRITICAL

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Feb 15, 2025
CVE-2025-1302
9.8 CRITICAL

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code …

Feb 15, 2025
CVE-2024-4282
9.8 CRITICAL

Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.

Feb 15, 2025
CVE-2025-26508
9.8 CRITICAL

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when …

Feb 14, 2025
CVE-2025-26507
9.8 CRITICAL

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when …

Feb 14, 2025
CVE-2025-26506
9.8 CRITICAL

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when …

Feb 14, 2025
CVE-2024-56973
9.8 CRITICAL

Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename …

Feb 14, 2025
CVE-2024-56180
9.8 CRITICAL

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers …

Feb 14, 2025
CVE-2025-0867
9.9 CRITICAL

The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its …

Feb 14, 2025
CVE-2024-13152
10.0 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection.This issue …

Feb 14, 2025
CVE-2024-52577
9.0 CRITICAL

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if …

Feb 14, 2025
CVE-2025-1298
9.8 CRITICAL

Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.

Feb 14, 2025
CVE-2025-22630
9.9 CRITICAL

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widget Options widget-options allows OS Command Injection.This issue affects Widget …

Feb 14, 2025
CVE-2025-25067
9.8 CRITICAL

mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

Feb 13, 2025
CVE-2025-24865
10.0 CRITICAL

The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload …

Feb 13, 2025
CVE-2025-1283
9.8 CRITICAL

The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.

Feb 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.