CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2552
4.3 MEDIUM

A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/formTcpipSetup. …

Mar 20, 2025
CVE-2025-2551
4.3 MEDIUM

A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been classified as problematic. This affects an unknown part of the file /goform/formSetPortTr. …

Mar 20, 2025
CVE-2025-2550
4.3 MEDIUM

A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Mar 20, 2025
CVE-2025-2549
4.3 MEDIUM

A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 20, 2025
CVE-2025-2548
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file /goform/formSetDomainFilter. The …

Mar 20, 2025
CVE-2025-2547
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02. This issue affects some unknown processing of the file …

Mar 20, 2025
CVE-2025-2546
4.3 MEDIUM

A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component …

Mar 20, 2025
CVE-2024-48591
6.1 MEDIUM

Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon …

Mar 20, 2025
CVE-2025-29412
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML …

Mar 20, 2025
CVE-2025-29410
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting …

Mar 20, 2025
CVE-2025-1496
6.5 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse.This issue affects Coslat Hotspot: before 6.26.0.R.20250227.

Mar 20, 2025
CVE-2025-0254
5.9 MEDIUM

HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially …

Mar 20, 2025
CVE-2025-27888
5.4 MEDIUM

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open …

Mar 20, 2025
CVE-2025-1802
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in …

Mar 20, 2025
CVE-2024-13920
4.9 MEDIUM

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via …

Mar 20, 2025
CVE-2025-1474
5.5 MEDIUM

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, …

Mar 20, 2025
CVE-2025-0508
5.9 MEDIUM

A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows …

Mar 20, 2025
CVE-2025-0281
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can inject malicious JavaScript into the SAML IdP XML metadata, …

Mar 20, 2025
CVE-2025-0192
5.4 MEDIUM

A stored Cross-site Scripting (XSS) vulnerability exists in the latest version of wandb/openui. The vulnerability is present in the edit HTML functionality, where an attacker …

Mar 20, 2025
CVE-2025-0191
6.5 MEDIUM

A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-data …

Mar 20, 2025
CVE-2025-0188
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacker to construct a response link by saving the …

Mar 20, 2025
CVE-2025-0184
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX files. If …

Mar 20, 2025
CVE-2025-0183
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts …

Mar 20, 2025
CVE-2024-9900
6.1 MEDIUM

mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vulnerability arises due to improper sanitization of user input, allowing the …

Mar 20, 2025
CVE-2024-9699
5.4 MEDIUM

A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript …

Mar 20, 2025
CVE-2024-9617
6.5 MEDIUM

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of …

Mar 20, 2025
CVE-2024-9612
6.5 MEDIUM

In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be …

Mar 20, 2025
CVE-2024-9447
6.5 MEDIUM

An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to …

Mar 20, 2025
CVE-2024-9418
6.5 MEDIUM

In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of …

Mar 20, 2025
CVE-2024-9365
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the victim's browser. This includes creating …

Mar 20, 2025
CVE-2024-9311
6.1 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The …

Mar 20, 2025
CVE-2024-9308
6.1 MEDIUM

An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. …

Mar 20, 2025
CVE-2024-9159
6.5 MEDIUM

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete …

Mar 20, 2025
CVE-2024-9107
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in …

Mar 20, 2025
CVE-2024-9098
6.1 MEDIUM

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing …

Mar 20, 2025
CVE-2024-9000
6.5 MEDIUM

In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. This missing …

Mar 20, 2025
CVE-2024-8982
6.2 MEDIUM

A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw …

Mar 20, 2025
CVE-2024-8736
6.5 MEDIUM

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site …

Mar 20, 2025
CVE-2024-8556
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view …

Mar 20, 2025
CVE-2024-8400
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing …

Mar 20, 2025
CVE-2024-8251
5.3 MEDIUM

A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly …

Mar 20, 2025
CVE-2024-8101
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` …

Mar 20, 2025
CVE-2024-8057
4.3 MEDIUM

In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises …

Mar 20, 2025
CVE-2024-8029
6.1 MEDIUM

An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click …

Mar 20, 2025
CVE-2024-8027
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS attacks during …

Mar 20, 2025
CVE-2024-8021
6.1 MEDIUM

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL …

Mar 20, 2025
CVE-2024-7771
6.5 MEDIUM

A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low …

Mar 20, 2025
CVE-2024-7476
4.3 MEDIUM

A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending …

Mar 20, 2025
CVE-2024-7058
4.4 MEDIUM

A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. …

Mar 20, 2025
CVE-2024-7046
4.3 MEDIUM

An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an …

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.