CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24071
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Mar 11, 2025
CVE-2025-24055
4.3 MEDIUM

Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.

Mar 11, 2025
CVE-2025-24054
6.5 MEDIUM KEV

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Mar 11, 2025
CVE-2025-21247
4.3 MEDIUM

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

Mar 11, 2025
CVE-2025-21199
6.7 MEDIUM

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-0149
6.5 MEDIUM

Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.

Mar 11, 2025
CVE-2024-56338
4.8 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to …

Mar 11, 2025
CVE-2025-27602
4.9 MEDIUM

Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via …

Mar 11, 2025
CVE-2025-27601
4.3 MEDIUM

Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior …

Mar 11, 2025
CVE-2025-25747
5.4 MEDIUM

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the …

Mar 11, 2025
CVE-2024-55597
5.5 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code …

Mar 11, 2025
CVE-2024-54026
4.3 MEDIUM

An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 …

Mar 11, 2025
CVE-2024-52960
4.3 MEDIUM

A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at …

Mar 11, 2025
CVE-2024-51322
5.4 MEDIUM

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp …

Mar 11, 2025
CVE-2024-51320
5.4 MEDIUM

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components

Mar 11, 2025
CVE-2024-46663
6.7 MEDIUM

A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or …

Mar 11, 2025
CVE-2024-33501
4.2 MEDIUM

Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, …

Mar 11, 2025
CVE-2024-32123
6.7 MEDIUM

Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 …

Mar 11, 2025
CVE-2023-42784
5.6 MEDIUM

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows …

Mar 11, 2025
CVE-2025-2193
5.4 MEDIUM

A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component …

Mar 11, 2025
CVE-2025-2192
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Stoque Zeev.it 4.24. This affects an unknown part of the file /Login?inpLostSession=1 of the component …

Mar 11, 2025
CVE-2025-25267
6.2 MEDIUM

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application …

Mar 11, 2025
CVE-2025-25266
6.8 MEDIUM

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application …

Mar 11, 2025
CVE-2024-52285
5.3 MEDIUM

A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < V6.4.8). Affected devices expose several …

Mar 11, 2025
CVE-2025-27911
6.5 MEDIUM

An issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system "Event body limit …

Mar 11, 2025
CVE-2025-1434
6.1 MEDIUM

The Spreadsheet view is vulnerable to a XSS attack, where a remote unauthorised attacker can read a limited amount of values or DoS the affected …

Mar 11, 2025
CVE-2024-58102
5.7 MEDIUM

An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested …

Mar 11, 2025
CVE-2025-2175
4.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the function _vbi_strndup_iconv. The manipulation …

Mar 11, 2025
CVE-2025-2174
5.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been declared as problematic. Affected by this vulnerability is the function vbi_strndup_iconv_ucs2 of the …

Mar 11, 2025
CVE-2025-2173
5.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The …

Mar 11, 2025
CVE-2025-26706
5.4 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

Mar 11, 2025
CVE-2025-26705
5.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2025-26704
6.4 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2025-26703
4.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

Mar 11, 2025
CVE-2025-26702
4.9 MEDIUM

Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

Mar 11, 2025
CVE-2024-13228
4.3 MEDIUM

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the …

Mar 11, 2025
CVE-2025-0629
4.8 MEDIUM

The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such …

Mar 11, 2025
CVE-2024-13853
6.1 MEDIUM

The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 11, 2025
CVE-2024-13580
4.3 MEDIUM

The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Mar 11, 2025
CVE-2024-13413
6.1 MEDIUM

The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all versions up to, and including, 1.0.24 due to …

Mar 11, 2025
CVE-2025-26707
5.3 MEDIUM

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mar 11, 2025
CVE-2024-13436
6.1 MEDIUM

The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing …

Mar 11, 2025
CVE-2025-27436
4.3 MEDIUM

The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact …

Mar 11, 2025
CVE-2025-27433
4.3 MEDIUM

The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank …

Mar 11, 2025
CVE-2025-27431
5.4 MEDIUM

User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload …

Mar 11, 2025
CVE-2025-26660
4.3 MEDIUM

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This …

Mar 11, 2025
CVE-2025-26659
6.1 MEDIUM

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to …

Mar 11, 2025
CVE-2025-26658
6.8 MEDIUM

The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. …

Mar 11, 2025
CVE-2025-26656
4.3 MEDIUM

OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has …

Mar 11, 2025
CVE-2025-25245
5.4 MEDIUM

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this …

Mar 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.