CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48930
2.8 LOW

The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.

May 28, 2025
CVE-2025-47295
3.7 LOW

A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker …

May 28, 2025
CVE-2025-46777
2.3 LOW

A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an …

May 28, 2025
CVE-2025-24473
3.7 LOW

A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an …

May 28, 2025
CVE-2024-54020
2.3 LOW

A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds …

May 28, 2025
CVE-2025-2826
2.6 LOW

n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on …

May 27, 2025
CVE-2025-26211
3.7 LOW

Gibbon before 29.0.00 allows CSRF.

May 27, 2025
CVE-2025-5204
3.3 LOW

A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::ParseSkinLump_3DGS_MDL7 of the file assimp/code/AssetLib/MDL/MDLMaterialLoader.cpp. The …

May 26, 2025
CVE-2025-5203
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function SkipSpaces …

May 26, 2025
CVE-2025-5202
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function HL1MDLLoader::validate_header …

May 26, 2025
CVE-2025-5201
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function LWOImporter::CountVertsAndFacesLWO2 of the file …

May 26, 2025
CVE-2025-5200
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDLImporter::InternReadFile_Quake1 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. …

May 26, 2025
CVE-2025-46804
3.3 LOW

A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. …

May 26, 2025
CVE-2025-5183
3.5 LOW

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as problematic. This issue affects some unknown processing …

May 26, 2025
CVE-2025-5181
3.5 LOW

A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. This affects an unknown part …

May 26, 2025
CVE-2025-5179
2.4 LOW

A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by this vulnerability is an unknown functionality of …

May 26, 2025
CVE-2025-5169
3.3 LOW

A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The …

May 26, 2025
CVE-2025-5168
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 …

May 26, 2025
CVE-2025-5167
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 …

May 26, 2025
CVE-2025-5166
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file …

May 26, 2025
CVE-2025-5165
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. …

May 26, 2025
CVE-2025-5164
3.7 LOW

A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation …

May 26, 2025
CVE-2025-5154
2.3 LOW

A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of …

May 25, 2025
CVE-2025-5153
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown processing of the component Design …

May 25, 2025
CVE-2025-5138
3.5 LOW

A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

May 25, 2025
CVE-2025-5136
3.7 LOW

A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of …

May 25, 2025
CVE-2025-5135
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionality of …

May 24, 2025
CVE-2025-5134
3.5 LOW

A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the component Buy …

May 24, 2025
CVE-2025-5127
3.5 LOW

A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. Executing manipulation of the …

May 24, 2025
CVE-2025-48756
2.9 LOW

In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits …

May 24, 2025
CVE-2025-48755
2.9 LOW

In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).

May 24, 2025
CVE-2025-48754
2.9 LOW

In the memory_pages crate 0.1.0 for Rust, division by zero can occur.

May 24, 2025
CVE-2025-48753
2.9 LOW

In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.

May 24, 2025
CVE-2025-48752
2.9 LOW

In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.

May 24, 2025
CVE-2025-48751
2.9 LOW

The process_lock crate 0.1.0 for Rust allows data races in unlock.

May 24, 2025
CVE-2025-48376
3.5 LOW

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft …

May 23, 2025
CVE-2023-53154
2.9 LOW

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

May 23, 2025
CVE-2024-9163
3.5 LOW

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 …

May 23, 2025
CVE-2025-1110
2.7 LOW

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access …

May 22, 2025
CVE-2023-47466
2.9 LOW

TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the …

May 22, 2025
CVE-2025-48070
3.5 LOW

Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to …

May 21, 2025
CVE-2025-48064
3.3 LOW

GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file …

May 21, 2025
CVE-2025-5031
3.1 LOW

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the component …

May 21, 2025
CVE-2025-48009
3.1 LOW

Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.

May 21, 2025
CVE-2025-5011
2.4 LOW

A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List …

May 21, 2025
CVE-2025-5010
2.4 LOW

A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog …

May 21, 2025
CVE-2025-5007
3.5 LOW

A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the …

May 20, 2025
CVE-2025-5001
3.3 LOW

A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The …

May 20, 2025
CVE-2025-4996
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add …

May 20, 2025
CVE-2025-48015
3.7 LOW

Failed login response could be different depending on whether the username was local or central.

May 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.