CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21997
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xsk: fix an integer overflow in xp_create_and_assign_umem() Since the i and pool->chunk_size variables are of …

Apr 3, 2025
CVE-2025-21996
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse() On the off chance that command stream passed …

Apr 3, 2025
CVE-2025-21995
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix fence reference count leak The last_scheduled fence leaks when an entity is being …

Apr 3, 2025
CVE-2025-1663
6.4 MEDIUM

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 …

Apr 3, 2025
CVE-2024-13673
6.4 MEDIUM

The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' shortcode in all versions up to, and including, …

Apr 3, 2025
CVE-2025-30485
6.2 MEDIUM

UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attaching to the affected product an external storage …

Apr 3, 2025
CVE-2025-3143
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The …

Apr 3, 2025
CVE-2025-3142
6.3 MEDIUM

A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 3, 2025
CVE-2025-31334
6.8 MEDIUM

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists …

Apr 3, 2025
CVE-2025-2055
6.8 MEDIUM

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users …

Apr 3, 2025
CVE-2025-3141
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 3, 2025
CVE-2025-3140
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 3, 2025
CVE-2025-3139
5.3 MEDIUM

A vulnerability was found in code-projects Bus Reservation System 1.0 and classified as critical. Affected by this issue is the function Login of the component …

Apr 3, 2025
CVE-2025-3153
6.5 MEDIUM

Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are …

Apr 3, 2025
CVE-2025-3135
6.3 MEDIUM

A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The …

Apr 3, 2025
CVE-2025-3134
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation …

Apr 3, 2025
CVE-2025-3123
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme …

Apr 2, 2025
CVE-2025-3130
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1.

Apr 2, 2025
CVE-2025-3129
4.8 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.

Apr 2, 2025
CVE-2025-3120
6.3 MEDIUM

A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 2, 2025
CVE-2025-3119
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /tutor/courses/manage_course.php. …

Apr 2, 2025
CVE-2025-30218
5.9 MEDIUM

Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this …

Apr 2, 2025
CVE-2025-0257
6.3 MEDIUM

HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its …

Apr 2, 2025
CVE-2025-3118
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. …

Apr 2, 2025
CVE-2025-29719
6.1 MEDIUM

SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.

Apr 2, 2025
CVE-2025-31286
4.6 MEDIUM

An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has …

Apr 2, 2025
CVE-2025-31285
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-31284
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then …

Apr 2, 2025
CVE-2025-31283
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-31282
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-20203
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Apr 2, 2025
CVE-2025-20120
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to …

Apr 2, 2025
CVE-2025-0154
5.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers.

Apr 2, 2025
CVE-2024-56476
5.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.

Apr 2, 2025
CVE-2024-56475
5.4 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Apr 2, 2025
CVE-2024-56474
4.3 MEDIUM

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …

Apr 2, 2025
CVE-2025-31728
5.5 MEDIUM

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe …

Apr 2, 2025
CVE-2025-31727
5.5 MEDIUM

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by …

Apr 2, 2025
CVE-2025-31726
5.5 MEDIUM

Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be …

Apr 2, 2025
CVE-2025-31725
5.5 MEDIUM

Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read …

Apr 2, 2025
CVE-2025-31724
4.3 MEDIUM

Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be …

Apr 2, 2025
CVE-2025-31723
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to change and reset the build queue order.

Apr 2, 2025
CVE-2025-31721
4.3 MEDIUM

A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an …

Apr 2, 2025
CVE-2025-31720
4.3 MEDIUM

A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy …

Apr 2, 2025
CVE-2024-56341
5.4 MEDIUM

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Apr 2, 2025
CVE-2024-25051
6.6 MEDIUM

IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on …

Apr 2, 2025
CVE-2025-21994
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field of smb_acl parse_dcal() validate num_aces to allocate posix_ace_state_array. …

Apr 2, 2025
CVE-2024-50597
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial …

Apr 2, 2025
CVE-2024-50596
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial …

Apr 2, 2025
CVE-2024-50595
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead …

Apr 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.