CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3107
6.5 MEDIUM

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to …

May 13, 2025
CVE-2025-43009
6.3 MEDIUM

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact …

May 13, 2025
CVE-2025-43008
5.8 MEDIUM

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. …

May 13, 2025
CVE-2025-43007
6.3 MEDIUM

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact …

May 13, 2025
CVE-2025-43006
6.1 MEDIUM

SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute malicious scripts in the application, potentially leading to a Cross-Site Scripting …

May 13, 2025
CVE-2025-43005
4.3 MEDIUM

SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT application to store user credentials. While this issue …

May 13, 2025
CVE-2025-43004
5.3 MEDIUM

Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access customer data when they access these …

May 13, 2025
CVE-2025-43003
6.4 MEDIUM

SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout …

May 13, 2025
CVE-2025-43002
4.3 MEDIUM

SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on …

May 13, 2025
CVE-2025-42997
6.6 MEDIUM

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of …

May 13, 2025
CVE-2025-31329
6.2 MEDIUM

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges …

May 13, 2025
CVE-2025-30011
5.3 MEDIUM

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated …

May 13, 2025
CVE-2025-30010
6.1 MEDIUM

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated …

May 13, 2025
CVE-2025-30009
6.1 MEDIUM

he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated …

May 13, 2025
CVE-2025-26662
4.4 MEDIUM

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already …

May 13, 2025
CVE-2025-46825
5.4 MEDIUM

Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a Stored Cross-Site Scripting (XSS) Vulnerability in the `name` …

May 12, 2025
CVE-2025-31260
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user …

May 12, 2025
CVE-2025-31258
6.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out …

May 12, 2025
CVE-2025-31257
4.7 MEDIUM

This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, …

May 12, 2025
CVE-2025-31256
5.5 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a user’s deleted …

May 12, 2025
CVE-2025-31251
5.5 MEDIUM

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma …

May 12, 2025
CVE-2025-31250
5.5 MEDIUM

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access …

May 12, 2025
CVE-2025-31245
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, …

May 12, 2025
CVE-2025-31242
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, …

May 12, 2025
CVE-2025-31241
5.3 MEDIUM

A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, …

May 12, 2025
CVE-2025-31239
4.3 MEDIUM

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS …

May 12, 2025
CVE-2025-31236
5.5 MEDIUM

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access …

May 12, 2025
CVE-2025-31235
6.5 MEDIUM

A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura …

May 12, 2025
CVE-2025-31233
6.3 MEDIUM

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma …

May 12, 2025
CVE-2025-31228
6.8 MEDIUM

The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to …

May 12, 2025
CVE-2025-31227
4.6 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a …

May 12, 2025
CVE-2025-31226
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, …

May 12, 2025
CVE-2025-31220
5.5 MEDIUM

A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. …

May 12, 2025
CVE-2025-31218
6.2 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to observe the …

May 12, 2025
CVE-2025-31217
6.5 MEDIUM

The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, …

May 12, 2025
CVE-2025-31215
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS …

May 12, 2025
CVE-2025-31212
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, …

May 12, 2025
CVE-2025-31210
6.5 MEDIUM

The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web content may lead to …

May 12, 2025
CVE-2025-31209
6.3 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS …

May 12, 2025
CVE-2025-31206
4.3 MEDIUM

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS …

May 12, 2025
CVE-2025-31205
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS …

May 12, 2025
CVE-2025-31196
5.5 MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS …

May 12, 2025
CVE-2025-31195
6.3 MEDIUM

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of …

May 12, 2025
CVE-2025-30440
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be …

May 12, 2025
CVE-2025-24225
6.5 MEDIUM

An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing an email may …

May 12, 2025
CVE-2025-24222
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web content may lead to an …

May 12, 2025
CVE-2025-24220
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may be able …

May 12, 2025
CVE-2025-24155
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may …

May 12, 2025
CVE-2025-24144
5.5 MEDIUM

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia …

May 12, 2025
CVE-2025-24142
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS …

May 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.