CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4551
3.5 LOW

A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/common/file. The …

May 11, 2025
CVE-2025-4547
2.4 LOW

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown …

May 11, 2025
CVE-2025-4542
3.1 LOW

A vulnerability, which was classified as problematic, has been found in Freeebird Hotel 酒店管理系统 API up to 1.2. Affected by this issue is some unknown …

May 11, 2025
CVE-2025-4537
3.1 LOW

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some unknown functionality of the file …

May 11, 2025
CVE-2025-4534
3.7 LOW

A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak …

May 11, 2025
CVE-2025-4533
2.7 LOW

A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component …

May 11, 2025
CVE-2025-4527
3.7 LOW

A vulnerability has been found in Dígitro NGC Explorer 3.44.15 and classified as problematic. This vulnerability affects unknown code of the component Password Transmission Handler. …

May 11, 2025
CVE-2025-47816
2.9 LOW

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.

May 10, 2025
CVE-2025-4495
3.5 LOW

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. …

May 10, 2025
CVE-2025-4470
2.4 LOW

A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file …

May 9, 2025
CVE-2025-4469
2.4 LOW

A vulnerability classified as problematic has been found in SourceCodester Online Student Clearance System 1.0. Affected is an unknown function of the file /admin/add-admin.php. The …

May 9, 2025
CVE-2025-4461
2.4 LOW

A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unknown code of the component Virtual Server Page. The manipulation leads …

May 9, 2025
CVE-2025-47737
2.9 LOW

lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero.

May 9, 2025
CVE-2025-47736
2.9 LOW

dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.

May 9, 2025
CVE-2025-47735
2.9 LOW

inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization.

May 9, 2025
CVE-2025-4460
2.4 LOW

A vulnerability classified as problematic has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the component URL Filtering Page. The manipulation …

May 9, 2025
CVE-2025-46712
3.7 LOW

Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), …

May 8, 2025
CVE-2025-44021
2.8 LOW

OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A …

May 8, 2025
CVE-2025-47729
1.9 LOW KEV

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described …

May 8, 2025
CVE-2023-7303
3.5 LOW

A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This affects the function process_request of the file q2apro-onsitenotifications-page.php. The …

May 7, 2025
CVE-2025-46824
3.1 LOW

The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' …

May 7, 2025
CVE-2025-46551
3.7 LOW

JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding …

May 7, 2025
CVE-2025-20977
3.3 LOW

Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction …

May 7, 2025
CVE-2025-1400
3.1 LOW

Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.

May 7, 2025
CVE-2025-1399
3.1 LOW

Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.

May 7, 2025
CVE-2025-23379
3.5 LOW

Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker …

May 6, 2025
CVE-2025-22479
3.5 LOW

Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated …

May 6, 2025
CVE-2025-46814
3.4 LOW

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. An HTTP header injection vulnerability …

May 6, 2025
CVE-2025-27248
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

May 6, 2025
CVE-2025-27241
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

May 6, 2025
CVE-2025-27132
3.8 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only …

May 6, 2025
CVE-2025-25218
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

May 6, 2025
CVE-2025-25052
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through buffer overflow.

May 6, 2025
CVE-2025-22886
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

May 6, 2025
CVE-2025-4328
3.5 LOW

A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. Affected by this vulnerability is the function sendBack of …

May 6, 2025
CVE-2025-4326
2.4 LOW

A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of the component Add …

May 6, 2025
CVE-2025-4325
2.4 LOW

A vulnerability has been found in MRCMS 3.1.2 and classified as problematic. This vulnerability affects unknown code of the file /admin/category/add.do of the component Category …

May 6, 2025
CVE-2025-4324
2.4 LOW

A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file /admin/link/edit.do of the component External …

May 6, 2025
CVE-2025-4323
2.4 LOW

A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the component Edit …

May 6, 2025
CVE-2025-4293
2.4 LOW

A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group/edit.do of the …

May 5, 2025
CVE-2025-4292
2.4 LOW

A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/user/edit.do of …

May 5, 2025
CVE-2025-4287
3.3 LOW

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. …

May 5, 2025
CVE-2025-4286
2.7 LOW

A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos …

May 5, 2025
CVE-2025-46720
3.1 LOW

Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding …

May 5, 2025
CVE-2025-4257
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pay.php. The manipulation …

May 5, 2025
CVE-2025-4256
3.5 LOW

A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus …

May 5, 2025
CVE-2025-47229
2.9 LOW

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such …

May 3, 2025
CVE-2025-4215
3.1 LOW

A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file …

May 2, 2025
CVE-2024-58253
2.9 LOW

In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces …

May 2, 2025
CVE-2025-3514
3.5 LOW

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin …

May 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.