CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27018
6.3 MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql …

Mar 19, 2025
CVE-2024-12136
6.9 MEDIUM

Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass.This issue affects ANKA JPD-00028: before V.01.01.

Mar 19, 2025
CVE-2024-50629
5.3 MEDIUM

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, …

Mar 19, 2025
CVE-2025-2290
5.3 MEDIUM

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability …

Mar 19, 2025
CVE-2024-10445
4.3 MEDIUM

Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 …

Mar 19, 2025
CVE-2024-57151
6.8 MEDIUM

SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function

Mar 18, 2025
CVE-2025-30138
4.6 MEDIUM

An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized …

Mar 18, 2025
CVE-2025-29790
5.4 MEDIUM

Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. …

Mar 18, 2025
CVE-2025-27080
6.0 MEDIUM

Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to …

Mar 18, 2025
CVE-2025-25042
4.3 MEDIUM

A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an …

Mar 18, 2025
CVE-2025-2487
4.9 MEDIUM

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the …

Mar 18, 2025
CVE-2025-26138
6.5 MEDIUM

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users …

Mar 18, 2025
CVE-2025-25586
4.2 MEDIUM

yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.

Mar 18, 2025
CVE-2025-25582
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

Mar 18, 2025
CVE-2024-57170
6.5 MEDIUM

SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences …

Mar 18, 2025
CVE-2025-30110
6.5 MEDIUM

On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism relies solely on MAC address verification, …

Mar 18, 2025
CVE-2025-30109
6.5 MEDIUM

In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded …

Mar 18, 2025
CVE-2025-25590
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.

Mar 18, 2025
CVE-2025-25580
6.1 MEDIUM

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.

Mar 18, 2025
CVE-2024-49822
4.1 MEDIUM

IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Mar 18, 2025
CVE-2024-44314
6.5 MEDIUM

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the …

Mar 18, 2025
CVE-2025-2495
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to upload XML files to the server with JavaScript …

Mar 18, 2025
CVE-2025-0694
6.6 MEDIUM

Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

Mar 18, 2025
CVE-2024-41975
5.3 MEDIUM

An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the …

Mar 18, 2025
CVE-2025-2471
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unknown function of the file /boat-details.php. The …

Mar 18, 2025
CVE-2025-2420
4.3 MEDIUM

A vulnerability classified as problematic was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. Affected by this vulnerability is an unknown functionality. The manipulation leads to …

Mar 17, 2025
CVE-2025-2419
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /InsertFeedback.php. …

Mar 17, 2025
CVE-2025-29781
6.5 MEDIUM

The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator enables users to load Secret from arbitrary …

Mar 17, 2025
CVE-2024-40635
4.6 MEDIUM

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User …

Mar 17, 2025
CVE-2025-2393
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the …

Mar 17, 2025
CVE-2025-29426
4.6 MEDIUM

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters.

Mar 17, 2025
CVE-2025-2392
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing …

Mar 17, 2025
CVE-2025-26393
5.4 MEDIUM

SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.

Mar 17, 2025
CVE-2025-24185
5.5 MEDIUM

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Parsing …

Mar 17, 2025
CVE-2024-54565
6.2 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.

Mar 17, 2025
CVE-2024-54559
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.

Mar 17, 2025
CVE-2025-2390
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /user_dashboard/add_donor.php. The …

Mar 17, 2025
CVE-2025-2389
4.7 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 17, 2025
CVE-2025-29427
5.9 MEDIUM

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.

Mar 17, 2025
CVE-2025-29425
5.5 MEDIUM

Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.

Mar 17, 2025
CVE-2025-26042
6.0 MEDIUM

Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it …

Mar 17, 2025
CVE-2024-8510
5.3 MEDIUM

N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is …

Mar 17, 2025
CVE-2024-44866
6.8 MEDIUM

A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) …

Mar 17, 2025
CVE-2025-29430
4.1 MEDIUM

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.

Mar 17, 2025
CVE-2025-29429
6.1 MEDIUM

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.

Mar 17, 2025
CVE-2024-48828
5.5 MEDIUM

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit …

Mar 17, 2025
CVE-2024-48017
6.5 MEDIUM

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high …

Mar 17, 2025
CVE-2024-48015
6.7 MEDIUM

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high …

Mar 17, 2025
CVE-2025-22474
6.8 MEDIUM

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially …

Mar 17, 2025
CVE-2025-30143
5.4 MEDIUM

Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in …

Mar 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.