CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4067
5.3 MEDIUM

A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to …

Apr 29, 2025
CVE-2025-4092
6.5 MEDIUM

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Apr 29, 2025
CVE-2025-4090
5.3 MEDIUM

A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed in Firefox 138 and Thunderbird …

Apr 29, 2025
CVE-2025-4089
5.1 MEDIUM

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading …

Apr 29, 2025
CVE-2025-4088
6.5 MEDIUM

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the …

Apr 29, 2025
CVE-2025-4087
4.8 MEDIUM

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to …

Apr 29, 2025
CVE-2025-4086
6.5 MEDIUM

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug …

Apr 29, 2025
CVE-2025-4084
5.7 MEDIUM

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially …

Apr 29, 2025
CVE-2025-4082
5.9 MEDIUM

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug …

Apr 29, 2025
CVE-2025-4064
5.3 MEDIUM

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation …

Apr 29, 2025
CVE-2025-4063
5.3 MEDIUM

A vulnerability was found in code-projects Student Information Management System 1.0 and classified as critical. Affected by this issue is the function cancel. The manipulation …

Apr 29, 2025
CVE-2025-4062
5.3 MEDIUM

A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by this vulnerability is the function cancel. The …

Apr 29, 2025
CVE-2025-4061
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0. Affected is the function add_item. The manipulation …

Apr 29, 2025
CVE-2025-4035
4.3 MEDIUM

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains …

Apr 29, 2025
CVE-2025-4059
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affects the function addrecord of the component Prison_Mgmt_Sys. The manipulation …

Apr 29, 2025
CVE-2025-3929
6.1 MEDIUM

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript …

Apr 29, 2025
CVE-2025-1194
6.5 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability …

Apr 29, 2025
CVE-2024-58099
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported connectivity issues with Cilium's service …

Apr 29, 2025
CVE-2025-3452
4.3 MEDIUM

The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'secupress_reinstall_plugins_admin_ajax_cb' …

Apr 29, 2025
CVE-2025-2893
6.4 MEDIUM

The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown …

Apr 29, 2025
CVE-2025-46343
5.0 MEDIUM

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows …

Apr 29, 2025
CVE-2025-46338
6.1 MEDIUM

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to …

Apr 29, 2025
CVE-2025-31203
6.5 MEDIUM

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-31202
5.5 MEDIUM

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, …

Apr 29, 2025
CVE-2025-31197
5.7 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, …

Apr 29, 2025
CVE-2025-30445
6.5 MEDIUM

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-24271
5.4 MEDIUM

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-24270
5.7 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-24251
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, …

Apr 29, 2025
CVE-2025-24179
5.7 MEDIUM

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, …

Apr 29, 2025
CVE-2025-4038
5.3 MEDIUM

A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is the function Reservation …

Apr 28, 2025
CVE-2025-4037
4.4 MEDIUM

A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function moneyDeposit/moneyWithdraw. The manipulation leads to business …

Apr 28, 2025
CVE-2024-11922
6.3 MEDIUM

Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails …

Apr 28, 2025
CVE-2024-10635
6.1 MEDIUM

Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending …

Apr 28, 2025
CVE-2025-4036
6.3 MEDIUM

A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBookChapter of the file src/main/java/io/github/xxyopen/novel/controller/author/AuthorController.java of the component …

Apr 28, 2025
CVE-2025-4032
5.0 MEDIUM

A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the function subprocess.run/subprocess.Popen of the file …

Apr 28, 2025
CVE-2025-34490
6.5 MEDIUM

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests …

Apr 28, 2025
CVE-2025-4029
5.3 MEDIUM

A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by this issue is the function addrecord of the …

Apr 28, 2025
CVE-2024-32499
4.9 MEDIUM

Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.

Apr 28, 2025
CVE-2023-42404
4.9 MEDIUM

OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.

Apr 28, 2025
CVE-2025-43857
6.5 MEDIUM

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial …

Apr 28, 2025
CVE-2025-43854
6.1 MEDIUM

DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, …

Apr 28, 2025
CVE-2023-35817
5.0 MEDIUM

DevExpress before 23.1.3 allows AsyncDownloader SSRF.

Apr 28, 2025
CVE-2022-41871
6.0 MEDIUM

SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user …

Apr 28, 2025
CVE-2025-25776
5.0 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute …

Apr 28, 2025
CVE-2025-23377
4.2 MEDIUM

Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could …

Apr 28, 2025
CVE-2025-4022
6.3 MEDIUM

A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file …

Apr 28, 2025
CVE-2025-4021
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 28, 2025
CVE-2025-32472
5.3 MEDIUM

The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowloris-type attack, causing the …

Apr 28, 2025
CVE-2025-4018
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file …

Apr 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.