CVE Database

39635+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13876
7.1 HIGH

The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 20, 2025
CVE-2024-13875
7.1 HIGH

The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 20, 2025
CVE-2025-27787
7.5 HIGH

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.py. `model_name` in train.py takes user input, …

Mar 19, 2025
CVE-2025-27785
7.5 HIGH

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This issue may lead to …

Mar 19, 2025
CVE-2025-27784
7.5 HIGH

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to …

Mar 19, 2025
CVE-2025-27777
7.5 HIGH

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) in `model_download.py` (line 195 in 3.2.7). The blind …

Mar 19, 2025
CVE-2025-2476
8.8 HIGH

Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 19, 2025
CVE-2025-27415
7.5 HIGH

Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a server behind an CDN, it …

Mar 19, 2025
CVE-2024-51459
8.4 HIGH

IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.

Mar 19, 2025
CVE-2025-29924
7.5 HIGH

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through …

Mar 19, 2025
CVE-2025-30154
8.6 HIGH KEV

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps …

Mar 19, 2025
CVE-2025-30153
7.5 HIGH

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows …

Mar 19, 2025
CVE-2024-55551
8.3 HIGH

An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the …

Mar 19, 2025
CVE-2024-13933
8.8 HIGH

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. …

Mar 19, 2025
CVE-2024-12920
8.8 HIGH

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a …

Mar 19, 2025
CVE-2024-12137
7.6 HIGH

Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking.This issue affects ANKA JPD-00028: before V.01.01.

Mar 19, 2025
CVE-2024-13412
7.5 HIGH

The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions …

Mar 19, 2025
CVE-2025-30236
8.6 HIGH

Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a …

Mar 19, 2025
CVE-2025-1232
8.8 HIGH

The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform …

Mar 19, 2025
CVE-2024-50631
7.5 HIGH

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, …

Mar 19, 2025
CVE-2024-50630
7.5 HIGH

Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain …

Mar 19, 2025
CVE-2025-30234
8.3 HIGH

SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image …

Mar 19, 2025
CVE-2024-12295
8.8 HIGH

The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is …

Mar 19, 2025
CVE-2024-10444
7.5 HIGH

Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication …

Mar 19, 2025
CVE-2025-30140
7.5 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered …

Mar 18, 2025
CVE-2024-12563
8.8 HIGH

The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This …

Mar 18, 2025
CVE-2025-30142
8.1 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism …

Mar 18, 2025
CVE-2025-30141
7.5 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream. It exposes API endpoints …

Mar 18, 2025
CVE-2025-29907
7.5 HIGH

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU …

Mar 18, 2025
CVE-2025-24801
8.5 HIGH

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the …

Mar 18, 2025
CVE-2025-24799
7.5 HIGH

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is …

Mar 18, 2025
CVE-2025-26137
7.5 HIGH

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by …

Mar 18, 2025
CVE-2025-27688
7.8 HIGH

Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation …

Mar 18, 2025
CVE-2025-25589
8.1 HIGH

An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted …

Mar 18, 2025
CVE-2025-30117
7.3 HIGH

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can …

Mar 18, 2025
CVE-2025-30116
7.5 HIGH

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. …

Mar 18, 2025
CVE-2025-30111
7.5 HIGH

On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained …

Mar 18, 2025
CVE-2025-30107
7.5 HIGH

On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. A vulnerability in the …

Mar 18, 2025
CVE-2025-25585
7.3 HIGH

Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.

Mar 18, 2025
CVE-2024-44313
8.1 HIGH

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to …

Mar 18, 2025
CVE-2025-30106
8.8 HIGH

On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi range …

Mar 18, 2025
CVE-2025-2450
8.8 HIGH

NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Mar 18, 2025
CVE-2025-2449
8.8 HIGH

NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of …

Mar 18, 2025
CVE-2025-25500
7.5 HIGH

An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows …

Mar 18, 2025
CVE-2024-21760
8.4 HIGH

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 …

Mar 18, 2025
CVE-2025-2493
7.5 HIGH

Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘/softdial/scheduler/load.php’ endpoint to …

Mar 18, 2025
CVE-2025-1468
7.5 HIGH

An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.

Mar 18, 2025
CVE-2024-23942
7.1 HIGH

A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or …

Mar 18, 2025
CVE-2025-25220
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vulnerability …

Mar 18, 2025
CVE-2025-24306
7.2 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.0_1101. If this vulnerability …

Mar 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.