CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1612
3.5 LOW

A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unknown code of the file wireless5g_basic.asp. The manipulation …

Feb 24, 2025
CVE-2025-1597
3.5 LOW

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic. Affected is an unknown function of the file …

Feb 23, 2025
CVE-2025-1592
2.4 LOW

A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Feb 23, 2025
CVE-2025-1591
2.4 LOW

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 23, 2025
CVE-2025-1586
3.5 LOW

A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /Blood/A-.php. …

Feb 23, 2025
CVE-2025-1585
2.4 LOW

A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5. This issue affects the function OptionsService of the file …

Feb 23, 2025
CVE-2025-1579
2.4 LOW

A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/user.php. The …

Feb 23, 2025
CVE-2025-1577
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of …

Feb 23, 2025
CVE-2024-47896
3.3 LOW

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU …

Feb 22, 2025
CVE-2025-1553
3.5 LOW

A vulnerability was found in pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6. It has been classified as problematic. Affected is an unknown function of the file /scale/project. …

Feb 22, 2025
CVE-2024-45674
3.3 LOW

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for …

Feb 22, 2025
CVE-2025-25878
3.8 LOW

A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The attack can use SQL …

Feb 21, 2025
CVE-2025-25877
3.8 LOW

A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /admin.php. The attack can use SQL …

Feb 21, 2025
CVE-2025-1548
3.5 LOW

A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/archives/edit. The …

Feb 21, 2025
CVE-2024-13585
3.5 LOW

The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Feb 21, 2025
CVE-2024-13314
3.5 LOW

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege …

Feb 21, 2025
CVE-2024-12173
3.5 LOW

The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor …

Feb 19, 2025
CVE-2025-27113
2.9 LOW

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.

Feb 18, 2025
CVE-2024-57257
2.0 LOW

A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.

Feb 18, 2025
CVE-2024-4028
3.8 LOW

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource …

Feb 18, 2025
CVE-2025-1392
3.5 LOW

A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. …

Feb 17, 2025
CVE-2025-1378
3.3 LOW

A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component …

Feb 17, 2025
CVE-2025-1377
3.3 LOW

A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of …

Feb 17, 2025
CVE-2025-1376
2.5 LOW

A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. …

Feb 17, 2025
CVE-2025-1373
3.3 LOW

A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the …

Feb 17, 2025
CVE-2025-1371
3.3 LOW

A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the …

Feb 17, 2025
CVE-2025-1368
2.3 LOW

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects the function ReadConfiguration of the …

Feb 17, 2025
CVE-2025-1360
3.5 LOW

A vulnerability, which was classified as problematic, was found in Internet Web Solutions Sublime CRM up to 20250207. Affected is an unknown function of the …

Feb 16, 2025
CVE-2025-1341
3.7 LOW

A vulnerability, which was classified as problematic, was found in PMWeb 7.2.0. This affects an unknown part of the component Setting Handler. The manipulation leads …

Feb 16, 2025
CVE-2025-1337
3.5 LOW

A vulnerability was found in Eastnets PaymentSafe 2.5.26.0. It has been classified as problematic. This affects an unknown part of the component BIC Search. The …

Feb 16, 2025
CVE-2025-1332
2.4 LOW

A vulnerability has been found in FastCMS up to 0.1.5 and classified as problematic. This vulnerability affects unknown code of the file /fastcms.html#/template/menu of the …

Feb 16, 2025
CVE-2024-31144
3.8 LOW

For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-overview Xapi contains functionality to backup and restore metadata about Virtual Machines and Storage Repositories (SRs). The …

Feb 14, 2025
CVE-2025-0503
3.1 LOW

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other …

Feb 14, 2025
CVE-2023-34406
3.3 LOW

An issue was discovered on Mercedes Benz NTG 6. A possible integer overflow exists in the user data import/export function of NTG (New Telematics Generation) …

Feb 13, 2025
CVE-2023-34401
3.7 LOW

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary …

Feb 13, 2025
CVE-2025-25899
3.5 LOW

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'gw' parameter at /userRpm/WanDynamicIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of …

Feb 13, 2025
CVE-2024-47266
2.7 LOW

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, …

Feb 13, 2025
CVE-2025-0692
3.5 LOW

The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Feb 13, 2025
CVE-2024-13125
3.5 LOW

The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 13, 2025
CVE-2024-13121
3.5 LOW

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some …

Feb 13, 2025
CVE-2024-34521
3.5 LOW

A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an administrative user to access system files with the …

Feb 12, 2025
CVE-2024-39286
3.3 LOW

Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 may allow an authenticated user to …

Feb 12, 2025
CVE-2024-39271
2.6 LOW

Improper restriction of communication channel to intended endpoints in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software before version 23.80 may allow an unauthenticated user …

Feb 12, 2025
CVE-2024-37020
3.8 LOW

Sequence of processor instructions leads to unexpected behavior in the Intel(R) DSA V1.0 for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially …

Feb 12, 2025
CVE-2024-26021
2.3 LOW

Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local …

Feb 12, 2025
CVE-2024-25571
2.3 LOW

Improper input validation in some Intel(R) SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to potentially enable denial of service via local access.

Feb 12, 2025
CVE-2025-1215
2.8 LOW

A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the …

Feb 12, 2025
CVE-2025-1213
3.5 LOW

A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Feb 12, 2025
CVE-2025-1209
3.5 LOW

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of …

Feb 12, 2025
CVE-2025-1208
3.5 LOW

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /Profile.php. …

Feb 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.