CVE Database

5223+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54781
2.8 LOW

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau in version 1.0.0, the himmelblaud_tasks service leaks …

Aug 2, 2025
CVE-2024-13978
2.5 LOW

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the …

Aug 1, 2025
CVE-2025-6011
3.7 LOW

A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially …

Aug 1, 2025
CVE-2023-44976
3.2 LOW

Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as …

Aug 1, 2025
CVE-2023-32251
3.7 LOW

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a …

Jul 31, 2025
CVE-2025-37109
3.5 LOW

Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

Jul 31, 2025
CVE-2025-37108
3.5 LOW

Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

Jul 31, 2025
CVE-2025-51385
3.5 LOW

D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.

Jul 31, 2025
CVE-2025-51384
3.5 LOW

D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.

Jul 31, 2025
CVE-2025-51383
3.5 LOW

D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.

Jul 31, 2025
CVE-2025-8380
3.5 LOW

A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/add_query_account.php. The manipulation …

Jul 31, 2025
CVE-2025-8365
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Jul 31, 2025
CVE-2025-54085
3.8 LOW

CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who …

Jul 31, 2025
CVE-2025-49082
2.7 LOW

CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who …

Jul 31, 2025
CVE-2025-8337
2.4 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the …

Jul 30, 2025
CVE-2025-36609
2.5 LOW

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit …

Jul 30, 2025
CVE-2025-53113
2.7 LOW

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses …

Jul 30, 2025
CVE-2025-54410
3.3 LOW

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. …

Jul 30, 2025
CVE-2025-52567
3.5 LOW

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through …

Jul 30, 2025
CVE-2025-8283
3.7 LOW

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may …

Jul 28, 2025
CVE-2025-54529
3.7 LOW

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

Jul 28, 2025
CVE-2025-8260
3.1 LOW

A security flaw has been discovered in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. This affects an unknown part of the file /grid/vgrid_server.php of the component Web …

Jul 28, 2025
CVE-2023-53161
2.9 LOW

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

Jul 28, 2025
CVE-2023-53160
2.9 LOW

The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.

Jul 28, 2025
CVE-2024-58266
3.2 LOW

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

Jul 27, 2025
CVE-2024-58265
3.1 LOW

The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.

Jul 27, 2025
CVE-2024-58264
3.2 LOW

The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.

Jul 27, 2025
CVE-2024-58263
3.7 LOW

The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.

Jul 27, 2025
CVE-2024-58262
2.9 LOW

The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.

Jul 27, 2025
CVE-2024-58261
2.9 LOW

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser …

Jul 27, 2025
CVE-2025-8225
3.3 LOW

A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component …

Jul 27, 2025
CVE-2025-8224
3.3 LOW

A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the …

Jul 27, 2025
CVE-2025-8222
3.5 LOW

A vulnerability, which was classified as problematic, has been found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. Affected by this issue is some unknown functionality …

Jul 27, 2025
CVE-2025-8211
3.5 LOW

A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the …

Jul 26, 2025
CVE-2025-8206
3.1 LOW

A vulnerability, which was classified as problematic, was found in Comodo Dragon up to 134.0.6998.179. This affects an unknown part of the component IP DNS …

Jul 26, 2025
CVE-2025-8205
3.7 LOW

A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by this issue is some unknown functionality of …

Jul 26, 2025
CVE-2025-8204
3.1 LOW

A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerability is an unknown functionality of the component HSTS …

Jul 26, 2025
CVE-2025-8191
3.5 LOW

A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of …

Jul 26, 2025
CVE-2025-8167
3.5 LOW

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 25, 2025
CVE-2025-43712
2.9 LOW

JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the …

Jul 25, 2025
CVE-2025-8155
3.5 LOW

A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vb.htm …

Jul 25, 2025
CVE-2025-8129
3.5 LOW

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of …

Jul 25, 2025
CVE-2025-54568
3.7 LOW

Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separately for each edge node.

Jul 25, 2025
CVE-2025-0253
2.0 LOW

HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.

Jul 25, 2025
CVE-2025-0252
2.6 LOW

HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.

Jul 25, 2025
CVE-2025-0251
2.6 LOW

HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.

Jul 25, 2025
CVE-2025-0250
2.2 LOW

HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner …

Jul 25, 2025
CVE-2025-0249
3.3 LOW

HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access …

Jul 25, 2025
CVE-2025-8115
3.5 LOW

A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 24, 2025
CVE-2025-46686
3.5 LOW

Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates …

Jul 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.