CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4338
6.8 MEDIUM

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access …

May 22, 2025
CVE-2024-5962
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious …

May 22, 2025
CVE-2024-7487
5.8 MEDIUM

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid …

May 22, 2025
CVE-2024-7103
4.6 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor …

May 22, 2025
CVE-2024-51553
6.5 MEDIUM

Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: …

May 22, 2025
CVE-2024-51552
6.0 MEDIUM

Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

May 22, 2025
CVE-2024-48848
6.5 MEDIUM

Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through …

May 22, 2025
CVE-2024-13958
4.8 MEDIUM

Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through …

May 22, 2025
CVE-2024-13956
6.7 MEDIUM

SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

May 22, 2025
CVE-2024-13954
6.5 MEDIUM

Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: …

May 22, 2025
CVE-2024-13953
4.9 MEDIUM

Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: …

May 22, 2025
CVE-2024-13950
6.8 MEDIUM

Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: …

May 22, 2025
CVE-2024-13949
6.8 MEDIUM

Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through …

May 22, 2025
CVE-2024-13947
6.0 MEDIUM

Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through …

May 22, 2025
CVE-2024-13946
6.8 MEDIUM

DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; …

May 22, 2025
CVE-2025-48369
5.4 MEDIUM

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a persistent Cross-Site Scripting (XSS) vulnerability exists in Groupoffice's …

May 22, 2025
CVE-2025-48368
5.4 MEDIUM

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a DOM-based Cross-Site Scripting (XSS) vulnerability exists in the …

May 22, 2025
CVE-2025-48366
5.4 MEDIUM

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a stored and blind XSS vulnerability exists in the …

May 22, 2025
CVE-2025-48066
6.0 MEDIUM

wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local …

May 22, 2025
CVE-2025-30173
6.7 MEDIUM

File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: …

May 22, 2025
CVE-2025-30170
5.5 MEDIUM

Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised. …

May 22, 2025
CVE-2025-30169
6.7 MEDIUM

File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: …

May 22, 2025
CVE-2024-13930
4.9 MEDIUM

An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects …

May 22, 2025
CVE-2025-48061
5.6 MEDIUM

wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user …

May 22, 2025
CVE-2025-46716
5.5 MEDIUM

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_SetSecureParam fails …

May 22, 2025
CVE-2025-33138
5.4 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

May 22, 2025
CVE-2025-4366
6.1 MEDIUM

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading …

May 22, 2025
CVE-2025-2506
5.3 MEDIUM

When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a …

May 22, 2025
CVE-2025-23183
6.1 MEDIUM

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

May 22, 2025
CVE-2025-23182
4.3 MEDIUM

CWE-203: Observable Discrepancy

May 22, 2025
CVE-2025-32915
5.5 MEDIUM

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 …

May 22, 2025
CVE-2025-32815
6.5 MEDIUM

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

May 22, 2025
CVE-2025-0679
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions …

May 22, 2025
CVE-2025-0605
4.6 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls …

May 22, 2025
CVE-2024-54188
5.3 MEDIUM

Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root access.

May 22, 2025
CVE-2024-12093
6.8 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation …

May 22, 2025
CVE-2025-4979
4.9 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able …

May 22, 2025
CVE-2025-4575
6.5 MEDIUM

Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: …

May 22, 2025
CVE-2025-3111
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of …

May 22, 2025
CVE-2025-2853
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation …

May 22, 2025
CVE-2025-3943
4.1 MEDIUM

Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, …

May 22, 2025
CVE-2025-3942
4.3 MEDIUM

Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data …

May 22, 2025
CVE-2025-3941
5.4 MEDIUM

Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. …

May 22, 2025
CVE-2025-3940
5.3 MEDIUM

Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data …

May 22, 2025
CVE-2025-3939
5.3 MEDIUM

Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects …

May 22, 2025
CVE-2025-3938
6.8 MEDIUM

Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects …

May 22, 2025
CVE-2025-3936
6.5 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Exploiting Incorrectly Configured Access Control …

May 22, 2025
CVE-2025-3444
6.5 MEDIUM

Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help …

May 22, 2025
CVE-2025-4419
4.3 MEDIUM

The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 via the 'path' parameter. This …

May 22, 2025
CVE-2025-4405
4.9 MEDIUM

The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.9.2 …

May 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.