CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27926
4.3 MEDIUM

In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.

Mar 10, 2025
CVE-2025-27924
5.4 MEDIUM

Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.

Mar 10, 2025
CVE-2025-25908
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Mar 10, 2025
CVE-2025-0660
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin …

Mar 10, 2025
CVE-2022-48610
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2. An app …

Mar 10, 2025
CVE-2025-26695
5.3 MEDIUM

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of …

Mar 10, 2025
CVE-2024-56188
5.1 MEDIUM

there is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no …

Mar 10, 2025
CVE-2024-56187
6.6 MEDIUM

In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the code. This could lead to …

Mar 10, 2025
CVE-2024-56186
5.1 MEDIUM

In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Mar 10, 2025
CVE-2024-56185
5.1 MEDIUM

In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband …

Mar 10, 2025
CVE-2024-56184
5.1 MEDIUM

In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local …

Mar 10, 2025
CVE-2024-54560
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. …

Mar 10, 2025
CVE-2024-54473
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to access …

Mar 10, 2025
CVE-2024-54469
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura …

Mar 10, 2025
CVE-2024-54467
6.5 MEDIUM

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, …

Mar 10, 2025
CVE-2024-54463
5.5 MEDIUM

This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without …

Mar 10, 2025
CVE-2024-44192
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS …

Mar 10, 2025
CVE-2025-1296
6.5 MEDIUM

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, …

Mar 10, 2025
CVE-2024-55199
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file …

Mar 10, 2025
CVE-2024-53307
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /mw/ endpoint of Evisions MAPS v6.10.2.267 allows attackers to execute arbitrary code in the context of a …

Mar 10, 2025
CVE-2024-52812
5.4 MEDIUM

LF Edge eKuiper is an internet-of-things data analytics and stream processing engine. Prior to version 2.0.8, auser with rights to modify the service (e.g. kuiperUser …

Mar 10, 2025
CVE-2024-47109
5.3 MEDIUM

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further …

Mar 10, 2025
CVE-2025-25620
5.4 MEDIUM

Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.

Mar 10, 2025
CVE-2024-12604
6.5 MEDIUM

Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery …

Mar 10, 2025
CVE-2025-2153
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 …

Mar 10, 2025
CVE-2025-2152
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the …

Mar 10, 2025
CVE-2025-25616
4.3 MEDIUM

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.

Mar 10, 2025
CVE-2024-57492
5.5 MEDIUM

An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton.

Mar 10, 2025
CVE-2025-2151
6.3 MEDIUM

A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of …

Mar 10, 2025
CVE-2025-2148
5.0 MEDIUM

A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple …

Mar 10, 2025
CVE-2025-1944
6.5 MEDIUM

picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. …

Mar 10, 2025
CVE-2025-2147
5.3 MEDIUM

A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is …

Mar 10, 2025
CVE-2025-24387
4.8 MEDIUM

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS …

Mar 10, 2025
CVE-2025-27257
6.1 MEDIUM

Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature …

Mar 10, 2025
CVE-2025-27253
6.1 MEDIUM

A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker …

Mar 10, 2025
CVE-2025-2150
5.4 MEDIUM

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which …

Mar 10, 2025
CVE-2025-1926
4.3 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Mar 10, 2025
CVE-2025-2132
4.7 MEDIUM

A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/index.php/web/ajax_all_lists of the component Search. The …

Mar 9, 2025
CVE-2025-2129
5.6 MEDIUM

A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default …

Mar 9, 2025
CVE-2025-2127
4.3 MEDIUM

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the …

Mar 9, 2025
CVE-2025-2126
6.3 MEDIUM

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file …

Mar 9, 2025
CVE-2025-2125
4.3 MEDIUM

A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao/?companyId=1 of …

Mar 9, 2025
CVE-2025-27636
5.6 MEDIUM

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from …

Mar 9, 2025
CVE-2025-2121
6.3 MEDIUM

A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the component …

Mar 9, 2025
CVE-2025-2117
6.3 MEDIUM

A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. Affected by this issue is …

Mar 9, 2025
CVE-2025-2116
4.3 MEDIUM

A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic. Affected by this vulnerability …

Mar 9, 2025
CVE-2025-2115
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. …

Mar 9, 2025
CVE-2025-1382
6.1 MEDIUM

The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as …

Mar 9, 2025
CVE-2025-1362
4.3 MEDIUM

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which …

Mar 9, 2025
CVE-2023-52971
4.9 MEDIUM

MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.

Mar 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.