CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30163
3.4 LOW

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node …

Mar 24, 2025
CVE-2025-30162
3.2 LOW

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and …

Mar 24, 2025
CVE-2025-2700
3.5 LOW

A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link …

Mar 24, 2025
CVE-2025-2699
3.5 LOW

A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Mar 24, 2025
CVE-2025-1203
3.5 LOW

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege …

Mar 24, 2025
CVE-2025-1062
3.5 LOW

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege …

Mar 24, 2025
CVE-2024-13124
3.5 LOW

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such …

Mar 24, 2025
CVE-2024-10558
3.5 LOW

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such …

Mar 24, 2025
CVE-2025-2673
3.5 LOW

A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file /home_employee.php. The manipulation …

Mar 24, 2025
CVE-2025-2650
3.5 LOW

A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the …

Mar 23, 2025
CVE-2025-2645
3.5 LOW

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

Mar 23, 2025
CVE-2025-2623
3.5 LOW

A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Mar 22, 2025
CVE-2025-2617
2.4 LOW

A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department …

Mar 22, 2025
CVE-2025-1972
2.7 LOW

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() …

Mar 22, 2025
CVE-2025-2616
2.4 LOW

A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown function of the component Role Management Page. …

Mar 22, 2025
CVE-2025-2590
2.4 LOW

A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic. Affected is the function UpdateRecruitmentById of the file …

Mar 21, 2025
CVE-2025-2588
3.3 LOW

A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation …

Mar 21, 2025
CVE-2025-27715
3.3 LOW

Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining …

Mar 21, 2025
CVE-2025-2583
3.5 LOW

A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php. The manipulation …

Mar 21, 2025
CVE-2025-2582
3.5 LOW

A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The …

Mar 21, 2025
CVE-2025-30345
3.5 LOW

An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of …

Mar 21, 2025
CVE-2025-30343
3.0 LOW

A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users …

Mar 21, 2025
CVE-2025-2555
2.9 LOW

A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unknown function of the component FTP Credentials. …

Mar 20, 2025
CVE-2025-29923
3.7 LOW

go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redis potentially responds out of order when …

Mar 20, 2025
CVE-2024-7598
3.1 LOW

A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The …

Mar 20, 2025
CVE-2024-13922
2.7 LOW

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the …

Mar 20, 2025
CVE-2025-30259
3.5 LOW

The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote …

Mar 20, 2025
CVE-2025-30258
2.7 LOW

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has …

Mar 19, 2025
CVE-2025-30197
3.1 LOW

Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture …

Mar 19, 2025
CVE-2024-42176
2.6 LOW

HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an …

Mar 19, 2025
CVE-2025-30235
3.5 LOW

Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed authentication attempts, but instead allows hundreds of …

Mar 19, 2025
CVE-2025-25040
3.3 LOW

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and …

Mar 18, 2025
CVE-2025-2491
2.4 LOW

A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit …

Mar 18, 2025
CVE-2025-2490
2.4 LOW

A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file …

Mar 18, 2025
CVE-2025-2397
2.4 LOW

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects …

Mar 17, 2025
CVE-2025-29431
3.2 LOW

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the id, code, and name parameters.

Mar 17, 2025
CVE-2025-25618
3.3 LOW

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.

Mar 17, 2025
CVE-2025-1398
3.3 LOW

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via …

Mar 17, 2025
CVE-2019-17659
3.7 LOW

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as …

Mar 17, 2025
CVE-2025-2377
3.5 LOW

A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Mar 17, 2025
CVE-2025-2375
3.5 LOW

A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unknown function of the file …

Mar 17, 2025
CVE-2025-2371
3.5 LOW

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown …

Mar 17, 2025
CVE-2025-2366
2.4 LOW

A vulnerability, which was classified as problematic, was found in gougucms 4.08.18. This affects the function add of the file /admin/department/add of the component Add …

Mar 17, 2025
CVE-2025-2364
3.5 LOW

A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the file blogserver/src/main/java/org/sang/service/ArticleService.java. …

Mar 17, 2025
CVE-2025-2356
3.7 LOW

A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the function deviceDelete of the component API …

Mar 17, 2025
CVE-2025-2355
3.3 LOW

A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic. Affected by this issue is some unknown functionality of the component …

Mar 17, 2025
CVE-2025-2352
2.4 LOW

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/indexConfigs/save of …

Mar 16, 2025
CVE-2025-2349
3.1 LOW

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as problematic. Affected by this vulnerability is an unknown …

Mar 16, 2025
CVE-2025-2341
3.1 LOW

A vulnerability was found in IROAD Dash Cam X5 up to 20250203. It has been rated as problematic. This issue affects some unknown processing of …

Mar 16, 2025
CVE-2025-2340
2.4 LOW

A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the function saveOptions of the file /options/save …

Mar 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.