CVE Database

39684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25943
7.8 HIGH

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.

Feb 19, 2025
CVE-2025-24989
8.2 HIGH KEV

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This …

Feb 19, 2025
CVE-2025-21355
8.6 HIGH

Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network

Feb 19, 2025
CVE-2024-5706
8.8 HIGH

The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier …

Feb 19, 2025
CVE-2024-5705
8.8 HIGH

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the …

Feb 19, 2025
CVE-2024-37359
8.6 HIGH

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently …

Feb 19, 2025
CVE-2023-51302
8.8 HIGH

PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient …

Feb 19, 2025
CVE-2023-51301
7.5 HIGH

A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount …

Feb 19, 2025
CVE-2025-0624
7.6 HIGH

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user …

Feb 19, 2025
CVE-2023-51293
7.5 HIGH

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount …

Feb 19, 2025
CVE-2023-46272
8.8 HIGH

Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation …

Feb 19, 2025
CVE-2025-0893
7.8 HIGH

Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.

Feb 19, 2025
CVE-2020-10095
8.1 HIGH

Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.

Feb 19, 2025
CVE-2025-1426
8.8 HIGH

Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Feb 19, 2025
CVE-2025-1006
8.8 HIGH

Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. …

Feb 19, 2025
CVE-2025-0999
8.8 HIGH

Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 19, 2025
CVE-2024-52541
8.2 HIGH

Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of …

Feb 19, 2025
CVE-2023-47160
8.2 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. …

Feb 19, 2025
CVE-2024-45084
8.0 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary …

Feb 19, 2025
CVE-2024-28777
8.8 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate …

Feb 19, 2025
CVE-2024-52902
8.8 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used …

Feb 19, 2025
CVE-2025-1464
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. This issue affects some unknown processing …

Feb 19, 2025
CVE-2025-0916
7.2 HIGH

The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Feb 19, 2025
CVE-2024-13534
7.5 HIGH

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions …

Feb 19, 2025
CVE-2024-13533
7.5 HIGH

The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and …

Feb 19, 2025
CVE-2024-13491
7.5 HIGH

The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all …

Feb 19, 2025
CVE-2024-13485
7.5 HIGH

The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions …

Feb 19, 2025
CVE-2024-13483
7.5 HIGH

The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up …

Feb 19, 2025
CVE-2024-13481
7.5 HIGH

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions …

Feb 19, 2025
CVE-2024-13479
7.5 HIGH

The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up …

Feb 19, 2025
CVE-2024-13478
7.5 HIGH

The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up …

Feb 19, 2025
CVE-2025-1075
7.5 HIGH

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache …

Feb 19, 2025
CVE-2024-13489
7.5 HIGH

The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions …

Feb 19, 2025
CVE-2025-1135
7.2 HIGH

A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL …

Feb 19, 2025
CVE-2025-1134
7.2 HIGH

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL …

Feb 19, 2025
CVE-2025-1133
7.2 HIGH

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability …

Feb 19, 2025
CVE-2025-1132
8.8 HIGH

A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an …

Feb 19, 2025
CVE-2024-13592
7.5 HIGH

The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Feb 19, 2025
CVE-2024-13468
7.5 HIGH

The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' …

Feb 19, 2025
CVE-2024-11582
7.2 HIGH

The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up …

Feb 19, 2025
CVE-2025-1448
7.3 HIGH

A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This issue affects some unknown processing …

Feb 19, 2025
CVE-2024-57262
7.1 HIGH

In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode …

Feb 19, 2025
CVE-2024-57261
7.1 HIGH

In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-57258.

Feb 19, 2025
CVE-2025-25475
7.5 HIGH

A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM …

Feb 18, 2025
CVE-2025-24928
7.8 HIGH

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an …

Feb 18, 2025
CVE-2024-57259
7.1 HIGH

sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not …

Feb 18, 2025
CVE-2024-57258
7.1 HIGH

Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled …

Feb 18, 2025
CVE-2024-57256
7.1 HIGH

An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with …

Feb 18, 2025
CVE-2024-57255
7.1 HIGH

An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a …

Feb 18, 2025
CVE-2024-57254
7.1 HIGH

An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem.

Feb 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.