CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30114
3.7 LOW

Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

Apr 24, 2025
CVE-2025-41423
3.1 LOW

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or …

Apr 24, 2025
CVE-2025-25046
3.7 LOW

IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using …

Apr 23, 2025
CVE-2024-58251
2.5 LOW

In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a …

Apr 23, 2025
CVE-2025-46394
3.2 LOW

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

Apr 23, 2025
CVE-2025-46393
2.9 LOW

In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).

Apr 23, 2025
CVE-2025-43965
2.9 LOW

In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.

Apr 23, 2025
CVE-2025-23253
2.5 LOW

NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a …

Apr 22, 2025
CVE-2025-3850
3.7 LOW

A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The …

Apr 22, 2025
CVE-2025-2987
3.8 LOW

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, …

Apr 22, 2025
CVE-2025-3841
3.3 LOW

A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of …

Apr 21, 2025
CVE-2025-29446
3.3 LOW

open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.

Apr 21, 2025
CVE-2025-43916
3.4 LOW

Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent with RFC …

Apr 21, 2025
CVE-2025-32408
2.5 LOW

In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.

Apr 21, 2025
CVE-2025-25228
3.8 LOW

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area …

Apr 21, 2025
CVE-2025-43967
2.9 LOW

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.

Apr 21, 2025
CVE-2025-43966
2.9 LOW

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.

Apr 21, 2025
CVE-2025-43964
2.9 LOW

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

Apr 21, 2025
CVE-2025-43963
2.9 LOW

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.

Apr 21, 2025
CVE-2025-43962
2.9 LOW

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and …

Apr 21, 2025
CVE-2025-43961
2.9 LOW

In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.

Apr 21, 2025
CVE-2025-43955
2.2 LOW

TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

Apr 20, 2025
CVE-2025-3826
2.4 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file …

Apr 20, 2025
CVE-2025-3825
2.4 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown …

Apr 20, 2025
CVE-2025-3824
2.4 LOW

A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Apr 20, 2025
CVE-2025-3823
2.4 LOW

A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. …

Apr 20, 2025
CVE-2025-3822
2.4 LOW

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Apr 20, 2025
CVE-2025-3821
2.4 LOW

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the …

Apr 20, 2025
CVE-2023-30421
2.9 LOW

mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 8891110122900e913013935755114.

Apr 19, 2025
CVE-2023-26819
2.9 LOW

cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

Apr 19, 2025
CVE-2022-47112
2.5 LOW

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

Apr 19, 2025
CVE-2022-47111
2.5 LOW

7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.

Apr 19, 2025
CVE-2025-3806
2.4 LOW

A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this issue is some unknown functionality of …

Apr 19, 2025
CVE-2025-3801
2.4 LOW

A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System …

Apr 19, 2025
CVE-2025-3795
2.4 LOW

A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO …

Apr 18, 2025
CVE-2025-25985
2.6 LOW

An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini …

Apr 18, 2025
CVE-2025-25983
3.4 LOW

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via …

Apr 18, 2025
CVE-2025-3789
3.5 LOW

A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Apr 18, 2025
CVE-2025-3788
3.5 LOW

A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Apr 18, 2025
CVE-2025-3787
2.7 LOW

A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation …

Apr 18, 2025
CVE-2024-42178
2.5 LOW

HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk …

Apr 17, 2025
CVE-2024-42177
2.6 LOW

HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt …

Apr 17, 2025
CVE-2025-26269
3.3 LOW

DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references …

Apr 17, 2025
CVE-2025-26268
3.3 LOW

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan …

Apr 17, 2025
CVE-2021-47671
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the …

Apr 17, 2025
CVE-2025-32415
2.9 LOW

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be …

Apr 17, 2025
CVE-2025-26478
3.1 LOW

Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading …

Apr 17, 2025
CVE-2025-29931
3.7 LOW

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not properly validate a length field in a …

Apr 17, 2025
CVE-2025-1525
3.5 LOW

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 17, 2025
CVE-2025-1524
3.5 LOW

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.