CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3513
3.5 LOW

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin …

May 2, 2025
CVE-2023-37517
3.2 LOW

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

Apr 30, 2025
CVE-2024-47784
2.6 LOW

Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web …

Apr 30, 2025
CVE-2025-32972
2.7 LOW

XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, …

Apr 30, 2025
CVE-2025-32971
3.8 LOW

XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, …

Apr 30, 2025
CVE-2025-46350
3.5 LOW

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from …

Apr 29, 2025
CVE-2024-12273
3.5 LOW

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 29, 2025
CVE-2025-46330
3.3 LOW

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code …

Apr 29, 2025
CVE-2025-46329
3.3 LOW

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging …

Apr 29, 2025
CVE-2025-46328
3.3 LOW

snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When …

Apr 28, 2025
CVE-2025-46327
3.3 LOW

gosnowflake is the Snowflake Golang driver. Versions starting from 1.7.0 to before 1.13.3, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using …

Apr 28, 2025
CVE-2025-46326
3.3 LOW

snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When …

Apr 28, 2025
CVE-2025-0049
3.5 LOW

When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server …

Apr 28, 2025
CVE-2025-46614
3.3 LOW

In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive …

Apr 28, 2025
CVE-2023-35816
3.5 LOW

DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.

Apr 28, 2025
CVE-2023-35815
3.5 LOW

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

Apr 28, 2025
CVE-2023-35814
3.5 LOW

DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

Apr 28, 2025
CVE-2025-23376
2.3 LOW

Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged …

Apr 28, 2025
CVE-2025-4012
2.7 LOW

A vulnerability was found in playeduxyz PlayEdu 开源培训系统 up to 1.8 and classified as problematic. This issue affects some unknown processing of the file /api/backend/v1/user/create …

Apr 28, 2025
CVE-2025-4011
3.5 LOW

A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation …

Apr 28, 2025
CVE-2025-32471
3.7 LOW

The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.

Apr 28, 2025
CVE-2025-0627
3.5 LOW

The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high …

Apr 28, 2025
CVE-2024-9771
3.5 LOW

The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Apr 28, 2025
CVE-2025-4001
3.3 LOW

A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability is the function main of the …

Apr 28, 2025
CVE-2025-4000
3.5 LOW

A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function of the …

Apr 28, 2025
CVE-2025-3999
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unknown processing …

Apr 28, 2025
CVE-2025-3996
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Apr 28, 2025
CVE-2025-3995
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Apr 28, 2025
CVE-2025-3994
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unknown function of the file /home.htm of the …

Apr 28, 2025
CVE-2025-3985
2.7 LOW

A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation …

Apr 27, 2025
CVE-2025-3970
3.5 LOW

A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. The manipulation …

Apr 27, 2025
CVE-2025-3965
3.5 LOW

A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. …

Apr 27, 2025
CVE-2024-52887
3.5 LOW

Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.

Apr 27, 2025
CVE-2025-3962
3.5 LOW

A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects unknown code of the file /api/comment/add of the component Comment Handler. …

Apr 27, 2025
CVE-2025-3961
3.5 LOW

A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unknown part of the file /admin/article/add/do. The manipulation of the …

Apr 27, 2025
CVE-2025-3958
3.5 LOW

A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is an unknown function of the file /book_edit_do.html of the …

Apr 27, 2025
CVE-2025-46675
3.5 LOW

In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.

Apr 27, 2025
CVE-2025-46674
3.5 LOW

NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.

Apr 27, 2025
CVE-2025-46672
3.5 LOW

NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.

Apr 27, 2025
CVE-2025-46656
2.9 LOW

python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.

Apr 26, 2025
CVE-2025-3954
3.7 LOW

A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some unknown functionality of the component Referer …

Apr 26, 2025
CVE-2025-46653
3.1 LOW

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as …

Apr 26, 2025
CVE-2025-2850
3.5 LOW

A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 …

Apr 26, 2025
CVE-2025-46618
3.5 LOW

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

Apr 25, 2025
CVE-2025-3637
3.1 LOW

A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This …

Apr 25, 2025
CVE-2025-3635
3.5 LOW

A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection …

Apr 25, 2025
CVE-2024-57375
2.4 LOW

Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) …

Apr 25, 2025
CVE-2025-46546
3.5 LOW

In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, …

Apr 25, 2025
CVE-2024-30127
3.2 LOW

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

Apr 24, 2025
CVE-2023-37516
3.2 LOW

Missing "no cache" headers in HCL Leap permits user directory information to be cached.

Apr 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.