CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48928
4.0 MEDIUM KEV

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which …

May 28, 2025
CVE-2025-48927
5.3 MEDIUM KEV

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in …

May 28, 2025
CVE-2025-48926
4.3 MEDIUM

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

May 28, 2025
CVE-2025-48925
4.3 MEDIUM

The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as …

May 28, 2025
CVE-2025-48746
6.5 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.

May 28, 2025
CVE-2025-36572
6.5 MEDIUM

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the …

May 28, 2025
CVE-2025-32802
6.1 MEDIUM

Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, …

May 28, 2025
CVE-2024-47056
5.1 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be directly accessible via a web browser. This exposure could lead …

May 28, 2025
CVE-2024-51453
4.3 MEDIUM

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted …

May 28, 2025
CVE-2024-38341
5.9 MEDIUM

IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker …

May 28, 2025
CVE-2025-4493
6.5 MEDIUM

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting …

May 28, 2025
CVE-2025-5297
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file …

May 28, 2025
CVE-2025-4963
6.4 MEDIUM

The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.15 due …

May 28, 2025
CVE-2025-5082
6.1 MEDIUM

The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ parameter in all versions up to, and including, 5.0.12 due …

May 28, 2025
CVE-2025-47294
5.3 MEDIUM

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the …

May 28, 2025
CVE-2025-27526
6.5 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability …

May 28, 2025
CVE-2025-27522
6.5 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for …

May 28, 2025
CVE-2025-5025
4.8 MEDIUM

libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC …

May 28, 2025
CVE-2025-4947
6.5 MEDIUM

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does …

May 28, 2025
CVE-2025-25029
4.9 MEDIUM

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

May 28, 2025
CVE-2025-25026
4.3 MEDIUM

IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.

May 28, 2025
CVE-2025-25025
4.3 MEDIUM

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This …

May 28, 2025
CVE-2025-2796
5.3 MEDIUM

On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. …

May 27, 2025
CVE-2024-45094
5.5 MEDIUM

IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code …

May 27, 2025
CVE-2024-11185
6.5 MEDIUM

On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, …

May 27, 2025
CVE-2025-40911
6.5 MEDIUM

Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass …

May 27, 2025
CVE-2025-5283
5.4 MEDIUM

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 27, 2025
CVE-2025-5281
5.4 MEDIUM

Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium …

May 27, 2025
CVE-2025-5278
4.4 MEDIUM

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside …

May 27, 2025
CVE-2025-5198
5.0 MEDIUM

A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of …

May 27, 2025
CVE-2025-5067
5.4 MEDIUM

Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

May 27, 2025
CVE-2025-5066
6.5 MEDIUM

Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI …

May 27, 2025
CVE-2025-5065
6.5 MEDIUM

Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

May 27, 2025
CVE-2025-5064
5.4 MEDIUM

Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

May 27, 2025
CVE-2025-46173
6.1 MEDIUM

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.

May 27, 2025
CVE-2025-45475
5.4 MEDIUM

maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

May 27, 2025
CVE-2024-49197
6.5 MEDIUM

An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. …

May 27, 2025
CVE-2025-23247
4.4 MEDIUM

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow …

May 27, 2025
CVE-2025-22377
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, …

May 27, 2025
CVE-2025-27701
5.5 MEDIUM

In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will …

May 27, 2025
CVE-2024-56193
5.1 MEDIUM

There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no additional execution …

May 27, 2025
CVE-2025-5245
5.3 MEDIUM

A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the …

May 27, 2025
CVE-2025-3704
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions Volunteer Sign Up Sheets pta-volunteer-sign-up-sheets allows Stored XSS.This issue affects Volunteer …

May 27, 2025
CVE-2025-5271
6.5 MEDIUM

Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 139 and Thunderbird 139.

May 27, 2025
CVE-2025-5267
5.4 MEDIUM

A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed …

May 27, 2025
CVE-2025-5266
4.3 MEDIUM

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR …

May 27, 2025
CVE-2025-5265
4.8 MEDIUM

Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially …

May 27, 2025
CVE-2025-5264
4.8 MEDIUM

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially …

May 27, 2025
CVE-2025-5263
4.3 MEDIUM

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed in Firefox 139, …

May 27, 2025
CVE-2025-5244
5.3 MEDIUM

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of …

May 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.