CVE Database

11833+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57099
9.8 CRITICAL

ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, …

Feb 3, 2025
CVE-2024-57098
9.8 CRITICAL

Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.

Feb 3, 2025
CVE-2024-45569
9.8 CRITICAL

Memory corruption while parsing the ML IE due to invalid frame content.

Feb 3, 2025
CVE-2025-20634
9.8 CRITICAL

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a …

Feb 3, 2025
CVE-2025-24891
9.6 CRITICAL

Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite …

Jan 31, 2025
CVE-2024-57587
9.1 CRITICAL

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) …

Jan 31, 2025
CVE-2024-55062
9.8 CRITICAL

Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.

Jan 31, 2025
CVE-2024-53356
9.8 CRITICAL

Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret …

Jan 31, 2025
CVE-2025-22957
9.8 CRITICAL

A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could …

Jan 31, 2025
CVE-2024-53584
9.8 CRITICAL

OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

Jan 31, 2025
CVE-2024-47857
9.8 CRITICAL

SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows …

Jan 31, 2025
CVE-2024-53537
9.1 CRITICAL

An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

Jan 31, 2025
CVE-2024-53320
9.8 CRITICAL

Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProject functions.

Jan 31, 2025
CVE-2025-0929
9.8 CRITICAL

SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious …

Jan 31, 2025
CVE-2025-0493
9.8 CRITICAL

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and …

Jan 31, 2025
CVE-2022-1736
9.8 CRITICAL

Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.

Jan 31, 2025
CVE-2025-0680
9.8 CRITICAL

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected …

Jan 30, 2025
CVE-2024-12248
9.8 CRITICAL

Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to …

Jan 30, 2025
CVE-2025-0498
9.8 CRITICAL

A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® …

Jan 30, 2025
CVE-2025-0497
9.8 CRITICAL

A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the …

Jan 30, 2025
CVE-2025-0477
9.8 CRITICAL

An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and …

Jan 30, 2025
CVE-2024-13742
9.8 CRITICAL

The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via …

Jan 30, 2025
CVE-2024-12822
9.8 CRITICAL

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing …

Jan 30, 2025
CVE-2025-21415
9.9 CRITICAL

Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

Jan 29, 2025
CVE-2024-57665
9.8 CRITICAL

JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly …

Jan 29, 2025
CVE-2025-0851
9.8 CRITICAL

A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary …

Jan 29, 2025
CVE-2024-57395
9.8 CRITICAL

Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the …

Jan 29, 2025
CVE-2024-54852
9.8 CRITICAL

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due …

Jan 29, 2025
CVE-2025-20061
9.8 CRITICAL

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to …

Jan 29, 2025
CVE-2025-20014
9.8 CRITICAL

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to …

Jan 29, 2025
CVE-2024-48852
9.4 CRITICAL

Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through …

Jan 29, 2025
CVE-2024-48849
9.4 CRITICAL

Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.

Jan 29, 2025
CVE-2025-23211
9.9 CRITICAL

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on …

Jan 28, 2025
CVE-2025-23045
9.8 CRITICAL

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT …

Jan 28, 2025
CVE-2024-13448
9.8 CRITICAL

The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions …

Jan 28, 2025
CVE-2024-12649
9.8 CRITICAL

Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to …

Jan 28, 2025
CVE-2024-12648
9.8 CRITICAL

Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment …

Jan 28, 2025
CVE-2024-12647
9.8 CRITICAL

Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to …

Jan 28, 2025
CVE-2022-3365
9.8 CRITICAL

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a …

Jan 28, 2025
CVE-2024-57548
9.1 CRITICAL

CMSimple 5.16 allows the user to edit log.php file via print page.

Jan 27, 2025
CVE-2024-57052
9.8 CRITICAL

An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.

Jan 27, 2025
CVE-2025-24154
9.1 CRITICAL

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3, …

Jan 27, 2025
CVE-2025-24146
9.8 CRITICAL

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Deleting …

Jan 27, 2025
CVE-2025-24102
9.8 CRITICAL

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app …

Jan 27, 2025
CVE-2025-24093
9.8 CRITICAL

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may …

Jan 27, 2025
CVE-2025-24085
10.0 CRITICAL KEV

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia …

Jan 27, 2025
CVE-2024-54542
9.1 CRITICAL

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, watchOS …

Jan 27, 2025
CVE-2024-54530
9.1 CRITICAL

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visionOS 2.2, watchOS 11.2. Password …

Jan 27, 2025
CVE-2024-54512
9.1 CRITICAL

The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A system binary could …

Jan 27, 2025
CVE-2024-48841
10.0 CRITICAL

Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.

Jan 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.