CVE Database

39635+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30349
7.2 HIGH

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message …

Mar 21, 2025
CVE-2025-29230
8.6 HIGH

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.

Mar 21, 2025
CVE-2024-53350
7.4 HIGH

Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escalation of privileges.

Mar 21, 2025
CVE-2024-53349
7.4 HIGH

Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in …

Mar 21, 2025
CVE-2024-53348
7.4 HIGH

LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.

Mar 21, 2025
CVE-2025-29641
7.3 HIGH

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' parameter.

Mar 21, 2025
CVE-2025-24915
7.8 HIGH

When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. …

Mar 21, 2025
CVE-2024-57490
7.7 HIGH

Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system administrator through …

Mar 21, 2025
CVE-2025-25068
7.5 HIGH

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers …

Mar 21, 2025
CVE-2025-26336
8.3 HIGH

Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior …

Mar 21, 2025
CVE-2025-2585
8.8 HIGH

EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify, …

Mar 21, 2025
CVE-2025-29807
8.7 HIGH

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mar 21, 2025
CVE-2024-54551
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, …

Mar 21, 2025
CVE-2024-44305
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root …

Mar 21, 2025
CVE-2024-44199
7.1 HIGH

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unexpected …

Mar 21, 2025
CVE-2025-25758
7.5 HIGH

An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

Mar 20, 2025
CVE-2025-30160
7.5 HIGH

Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by …

Mar 20, 2025
CVE-2025-2480
7.8 HIGH

Santesoft Sante DICOM Viewer Pro is vulnerable to an out-of-bounds write, which requires a user to open a malicious DCM file, resulting in execution of …

Mar 20, 2025
CVE-2025-29149
7.5 HIGH

Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.

Mar 20, 2025
CVE-2025-29121
7.5 HIGH

A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based …

Mar 20, 2025
CVE-2024-57440
7.5 HIGH

D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webproc cgi

Mar 20, 2025
CVE-2025-29214
7.5 HIGH

Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.

Mar 20, 2025
CVE-2025-23120
8.8 HIGH

A vulnerability allowing remote code execution (RCE) for domain users.

Mar 20, 2025
CVE-2025-29101
7.5 HIGH

Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function.

Mar 20, 2025
CVE-2025-2539
7.5 HIGH

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all …

Mar 20, 2025
CVE-2024-13923
7.6 HIGH

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 …

Mar 20, 2025
CVE-2024-13921
7.2 HIGH

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 …

Mar 20, 2025
CVE-2024-13558
7.5 HIGH

The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due …

Mar 20, 2025
CVE-2025-1796
8.8 HIGH

A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo-random number generator (PRNG) used …

Mar 20, 2025
CVE-2025-1473
7.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a …

Mar 20, 2025
CVE-2025-1451
7.5 HIGH

A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or validate the length …

Mar 20, 2025
CVE-2025-1040
8.8 HIGH

AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from …

Mar 20, 2025
CVE-2025-0628
8.1 HIGH

An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided …

Mar 20, 2025
CVE-2025-0454
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname …

Mar 20, 2025
CVE-2025-0453
7.5 HIGH

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly …

Mar 20, 2025
CVE-2025-0452
8.2 HIGH

eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, …

Mar 20, 2025
CVE-2025-0330
7.5 HIGH

In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability …

Mar 20, 2025
CVE-2025-0317
7.5 HIGH

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can …

Mar 20, 2025
CVE-2025-0315
7.5 HIGH

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. …

Mar 20, 2025
CVE-2025-0312
7.5 HIGH

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama …

Mar 20, 2025
CVE-2025-0190
7.5 HIGH

In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through …

Mar 20, 2025
CVE-2025-0189
7.5 HIGH

In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, …

Mar 20, 2025
CVE-2025-0187
7.5 HIGH

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of …

Mar 20, 2025
CVE-2025-0185
8.8 HIGH

A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs …

Mar 20, 2025
CVE-2025-0182
7.5 HIGH

A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of …

Mar 20, 2025
CVE-2024-9920
8.8 HIGH

In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangerous ones like .py, .sh, .bat, …

Mar 20, 2025
CVE-2024-9919
8.4 HIGH

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call …

Mar 20, 2025
CVE-2024-9847
8.0 HIGH

FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a …

Mar 20, 2025
CVE-2024-9606
7.5 HIGH

In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the …

Mar 20, 2025
CVE-2024-9597
7.1 HIGH

A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.