CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20656
6.8 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Apr 7, 2025
CVE-2025-20655
5.3 MEDIUM

In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a …

Apr 7, 2025
CVE-2024-58116
4.0 MEDIUM

Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2025
CVE-2024-58115
4.0 MEDIUM

Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2025
CVE-2024-58113
5.3 MEDIUM

Vulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2025
CVE-2024-58110
4.6 MEDIUM

Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2025
CVE-2024-58109
4.6 MEDIUM

Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2025
CVE-2024-58108
4.6 MEDIUM

Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2025
CVE-2024-58106
4.6 MEDIUM

Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2025
CVE-2025-22851
6.5 MEDIUM

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.

Apr 7, 2025
CVE-2025-3325
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part of the file /core/admin/pwd of the …

Apr 6, 2025
CVE-2025-3324
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality of the file …

Apr 6, 2025
CVE-2025-3323
6.3 MEDIUM

A vulnerability classified as critical was found in godcheese/code-projects Nimrod 0.8. Affected by this vulnerability is the function searchAllByName of the file ViewMenuCategoryRestController.java. The manipulation …

Apr 6, 2025
CVE-2025-3318
6.3 MEDIUM

A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. …

Apr 6, 2025
CVE-2025-3317
4.3 MEDIUM

A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation …

Apr 6, 2025
CVE-2025-32369
6.4 MEDIUM

Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.

Apr 6, 2025
CVE-2025-1264
6.5 MEDIUM

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to SQL Injection via the 'orderBy' parameter …

Apr 6, 2025
CVE-2024-58133
4.0 MEDIUM

In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarting this node, concurrent writes by logger.go to a …

Apr 6, 2025
CVE-2024-58132
4.0 MEDIUM

In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal nodes to perform concurrent read and write operations …

Apr 6, 2025
CVE-2024-58131
4.0 MEDIUM

FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified …

Apr 6, 2025
CVE-2025-3305
4.3 MEDIUM

A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerability affects the function addInterceptors of the file MvcConfig.java of the …

Apr 5, 2025
CVE-2025-32366
4.8 MEDIUM

In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=ntohs(rr->rdlen) and memcpy(response+offset,*end,*rdlen) without a check …

Apr 5, 2025
CVE-2025-3304
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_not.php. …

Apr 5, 2025
CVE-2025-32365
4.0 MEDIUM

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

Apr 5, 2025
CVE-2025-32364
4.0 MEDIUM

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

Apr 5, 2025
CVE-2025-3303
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0. Affected by this issue is some unknown functionality …

Apr 5, 2025
CVE-2025-32360
4.2 MEDIUM

In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged …

Apr 5, 2025
CVE-2025-32359
4.8 MEDIUM

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their …

Apr 5, 2025
CVE-2025-32358
4.0 MEDIUM

In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are triggered as POST requests when certain conditions …

Apr 5, 2025
CVE-2025-32357
4.3 MEDIUM

In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that …

Apr 5, 2025
CVE-2024-56370
6.5 MEDIUM

Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically …

Apr 5, 2025
CVE-2024-52322
5.5 MEDIUM

WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically …

Apr 5, 2025
CVE-2024-58036
5.5 MEDIUM

Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically …

Apr 5, 2025
CVE-2024-57868
5.5 MEDIUM

Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically …

Apr 5, 2025
CVE-2024-57835
5.5 MEDIUM

Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. String::Random defaults to Perl's built-in predictable random number generator, the rand() function, which is not cryptographically …

Apr 5, 2025
CVE-2025-30401
6.7 MEDIUM

A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based …

Apr 5, 2025
CVE-2025-3298
4.3 MEDIUM

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Apr 5, 2025
CVE-2025-3296
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file …

Apr 5, 2025
CVE-2025-2789
5.3 MEDIUM

The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to …

Apr 5, 2025
CVE-2025-1233
4.3 MEDIUM

The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_options_upload' AJAX function in all versions up …

Apr 5, 2025
CVE-2025-0839
6.4 MEDIUM

The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization …

Apr 5, 2025
CVE-2025-32352
4.8 MEDIUM

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that …

Apr 5, 2025
CVE-2025-2544
6.4 MEDIUM

The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 …

Apr 5, 2025
CVE-2025-1500
5.5 MEDIUM

IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if …

Apr 5, 2025
CVE-2025-2889
6.4 MEDIUM

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 …

Apr 5, 2025
CVE-2025-3268
5.3 MEDIUM

A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The …

Apr 4, 2025
CVE-2025-3267
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknown part of the file /http/http_conn.cpp. The …

Apr 4, 2025
CVE-2025-29477
5.5 MEDIUM

An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.

Apr 4, 2025
CVE-2025-29476
5.5 MEDIUM

Buffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0 and before.

Apr 4, 2025
CVE-2025-3257
4.3 MEDIUM

A vulnerability classified as problematic has been found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation leads to …

Apr 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.