CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1892
2.4 LOW

A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component …

Mar 4, 2025
CVE-2025-27221
3.2 LOW

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is …

Mar 4, 2025
CVE-2025-1880
2.0 LOW

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the …

Mar 3, 2025
CVE-2025-1879
2.4 LOW

A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component …

Mar 3, 2025
CVE-2025-1878
3.1 LOW

A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability affects unknown code of the component …

Mar 3, 2025
CVE-2025-24023
3.7 LOW

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server …

Mar 3, 2025
CVE-2025-1830
2.4 LOW

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown processing of the component …

Mar 2, 2025
CVE-2025-0895
2.4 LOW

IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log …

Mar 2, 2025
CVE-2024-55907
2.0 LOW

IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming technique, interface, …

Mar 2, 2025
CVE-2025-1817
2.4 LOW

A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown code of the file /admin of the component Admin …

Mar 2, 2025
CVE-2025-1807
3.5 LOW

A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknown part of the file /directRouter.rfc of the component …

Mar 2, 2025
CVE-2025-27400
2.9 LOW

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of …

Feb 28, 2025
CVE-2025-0914
3.8 LOW

An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments …

Feb 27, 2025
CVE-2025-0759
3.3 LOW

IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization.

Feb 27, 2025
CVE-2024-56812
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56811
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56810
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56496
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56495
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56494
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56493
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2025-1693
3.9 LOW

The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into …

Feb 27, 2025
CVE-2025-26698
2.7 LOW

Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using …

Feb 26, 2025
CVE-2025-0760
2.7 LOW

A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials due to lack of encryption.

Feb 26, 2025
CVE-2025-22211
3.4 LOW

A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management …

Feb 25, 2025
CVE-2024-53879
2.8 LOW

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed …

Feb 25, 2025
CVE-2024-53878
2.8 LOW

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed …

Feb 25, 2025
CVE-2024-53877
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause a NULL pointer exception by passing a …

Feb 25, 2025
CVE-2024-53876
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53875
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53874
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53873
3.3 LOW

NVIDIA CUDA toolkit for Windows contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF …

Feb 25, 2025
CVE-2024-53872
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53871
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2024-53870
3.3 LOW

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed …

Feb 25, 2025
CVE-2025-27146
2.7 LOW

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command …

Feb 25, 2025
CVE-2025-26977
3.8 LOW

Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through …

Feb 25, 2025
CVE-2024-51539
2.3 LOW

The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulnerability due to improper neutralization of special elements …

Feb 25, 2025
CVE-2024-10545
3.5 LOW

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege …

Feb 25, 2025
CVE-2025-27145
3.6 LOW

copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a …

Feb 25, 2025
CVE-2025-26532
3.1 LOW

Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.

Feb 24, 2025
CVE-2025-26531
3.1 LOW

Insufficient capability checks made it possible to disable badges a user does not have permission to access.

Feb 24, 2025
CVE-2025-26528
3.4 LOW

The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

Feb 24, 2025
CVE-2025-1632
3.3 LOW

A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The …

Feb 24, 2025
CVE-2025-1412
3.1 LOW

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted …

Feb 24, 2025
CVE-2025-1629
3.5 LOW

A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function …

Feb 24, 2025
CVE-2025-1617
2.4 LOW

A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part of the component Wireless 2.4G Menu. The …

Feb 24, 2025
CVE-2025-1615
2.4 LOW

A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT …

Feb 24, 2025
CVE-2025-1614
2.4 LOW

A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown function of the file /goform/portForwardingCfg of the …

Feb 24, 2025
CVE-2025-1613
2.4 LOW

A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects some unknown processing of the file …

Feb 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.