CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4017
4.3 MEDIUM

A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This vulnerability affects the function list of the file nnovel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation …

Apr 28, 2025
CVE-2025-4016
5.4 MEDIUM

A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIndex of the file novel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation …

Apr 28, 2025
CVE-2025-4015
5.3 MEDIUM

A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of …

Apr 28, 2025
CVE-2025-39367
5.3 MEDIUM

Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4.

Apr 28, 2025
CVE-2025-4006
4.7 MEDIUM

A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the file /admin/theme/Upload.html of the component Document …

Apr 28, 2025
CVE-2025-4003
5.5 MEDIUM

A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects the function InternalApfsTranslateBlock of the file Library/RP_ApfsLib/RP_ApfsIo.c. The manipulation …

Apr 28, 2025
CVE-2024-13688
5.3 MEDIUM

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection …

Apr 28, 2025
CVE-2025-4002
5.5 MEDIUM

A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB and classified as problematic. Affected by this issue is the function GetDebugLogFile of the file Library/MemLogLib/BootLog.c. The …

Apr 28, 2025
CVE-2025-3997
4.3 MEDIUM

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-profile-ajax-1 of the component Personal …

Apr 28, 2025
CVE-2025-3706
6.1 MEDIUM

The eHRMS from 104 Corporation has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Apr 28, 2025
CVE-2025-31144
5.8 MEDIUM

Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker …

Apr 28, 2025
CVE-2025-27937
6.5 MEDIUM

Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an …

Apr 28, 2025
CVE-2025-46690
5.0 MEDIUM

Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.

Apr 27, 2025
CVE-2025-46689
5.4 MEDIUM

Ververica Platform 2.14.0 contain an Reflected XSS vulnerability via a namespaces/default/formats URI.

Apr 27, 2025
CVE-2025-3987
6.3 MEDIUM

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The …

Apr 27, 2025
CVE-2025-3986
4.3 MEDIUM

A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerController.java. The manipulation …

Apr 27, 2025
CVE-2025-46688
5.6 MEDIUM

quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.

Apr 27, 2025
CVE-2025-46687
5.6 MEDIUM

quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.

Apr 27, 2025
CVE-2025-3984
5.0 MEDIUM

A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java of …

Apr 27, 2025
CVE-2025-3983
4.7 MEDIUM

A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 27, 2025
CVE-2025-3982
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/nodes/object_nodes/getsetprop_mk2.py of the component …

Apr 27, 2025
CVE-2025-3981
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This issue affects some unknown processing of …

Apr 27, 2025
CVE-2025-2866
5.5 MEDIUM

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the …

Apr 27, 2025
CVE-2025-3980
4.3 MEDIUM

A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability affects unknown code of the file /v1/prescription/list. The …

Apr 27, 2025
CVE-2025-3979
4.3 MEDIUM

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password …

Apr 27, 2025
CVE-2025-3978
4.3 MEDIUM

A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Apr 27, 2025
CVE-2025-3977
4.3 MEDIUM

A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Apr 27, 2025
CVE-2025-3975
5.3 MEDIUM

A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads …

Apr 27, 2025
CVE-2025-3969
6.3 MEDIUM

A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 27, 2025
CVE-2025-3968
6.3 MEDIUM

A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 27, 2025
CVE-2025-3967
5.4 MEDIUM

A vulnerability was found in itwanger paicoding 1.0.3. It has been classified as critical. This affects an unknown part of the file /article/api/post of the …

Apr 27, 2025
CVE-2025-3966
4.3 MEDIUM

A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/home?userId=1&homeSelectType=read of …

Apr 27, 2025
CVE-2025-3964
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in withstars Books-Management-System 1.0. Affected is an unknown function of the file /api/article/del of the component …

Apr 27, 2025
CVE-2024-52888
5.4 MEDIUM

For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.

Apr 27, 2025
CVE-2025-3959
4.3 MEDIUM

A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Apr 27, 2025
CVE-2025-3957
6.3 MEDIUM

A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main\resources\mapper\sys\SysLogDao.xml. The manipulation of …

Apr 27, 2025
CVE-2025-3956
6.3 MEDIUM

A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the function RestResp of the file novel-cloud-master/novel-book/novel-book-service/src/main/resources/mapper/BookInfoMapper.xml. The manipulation …

Apr 27, 2025
CVE-2025-46578
6.5 MEDIUM

There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database …

Apr 27, 2025
CVE-2025-46577
6.5 MEDIUM

There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.

Apr 27, 2025
CVE-2025-46576
5.4 MEDIUM

There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.

Apr 27, 2025
CVE-2025-46575
4.9 MEDIUM

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

Apr 27, 2025
CVE-2025-46574
4.1 MEDIUM

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

Apr 27, 2025
CVE-2025-46673
4.9 MEDIUM

NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space …

Apr 27, 2025
CVE-2025-3955
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This affects an unknown part of the file /edit_rpatient.php.php. …

Apr 27, 2025
CVE-2025-46655
4.9 MEDIUM

CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of …

Apr 26, 2025
CVE-2025-46654
4.9 MEDIUM

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that …

Apr 26, 2025
CVE-2025-46652
6.1 MEDIUM

In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is …

Apr 26, 2025
CVE-2025-46646
4.5 MEDIUM

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

Apr 26, 2025
CVE-2024-53636
6.4 MEDIUM

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the …

Apr 26, 2025
CVE-2024-13812
6.5 MEDIUM

The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.1.1. This is due …

Apr 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.