CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45658
2.7 LOW

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Feb 4, 2025
CVE-2025-20895
3.2 LOW

Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.

Feb 4, 2025
CVE-2025-22475
3.7 LOW

Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote …

Feb 4, 2025
CVE-2025-0148
2.6 LOW

Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via …

Feb 3, 2025
CVE-2025-20643
3.9 LOW

In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an …

Feb 3, 2025
CVE-2025-0972
3.5 LOW

A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part of the component New Ticket Handler. …

Feb 3, 2025
CVE-2025-0971
3.5 LOW

A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Feb 3, 2025
CVE-2025-0961
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Job Recruitment 1.0. Affected by this issue is some unknown functionality of the …

Feb 1, 2025
CVE-2024-53296
2.7 LOW

Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer Overflow vulnerability in the RestAPI. A high privileged attacker with remote access …

Feb 1, 2025
CVE-2020-11936
3.1 LOW

gdbus setgid privilege escalation

Jan 31, 2025
CVE-2025-24336
3.3 LOW

SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed.

Jan 31, 2025
CVE-2023-6195
2.6 LOW

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

Jan 31, 2025
CVE-2025-0146
3.9 LOW

Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via …

Jan 30, 2025
CVE-2025-0144
3.1 LOW

Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.

Jan 30, 2025
CVE-2025-0871
3.5 LOW

A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/admin/index.php?u=article-edit of the component Add Article. …

Jan 30, 2025
CVE-2024-55416
3.5 LOW

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can …

Jan 30, 2025
CVE-2025-0800
2.4 LOW

A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component …

Jan 29, 2025
CVE-2025-0797
3.3 LOW

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects unknown code of the file …

Jan 29, 2025
CVE-2025-0795
3.5 LOW

A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the file /todolistjump.jsp. The manipulation …

Jan 29, 2025
CVE-2025-0794
3.5 LOW

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown functionality of the file /todoDetail.jsp. The …

Jan 29, 2025
CVE-2025-0790
3.5 LOW

A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the file /doneDetail.jsp. The manipulation of the argument …

Jan 29, 2025
CVE-2025-0787
3.5 LOW

A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Jan 28, 2025
CVE-2025-0785
3.5 LOW

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing of the file /SysConfig.jsp. The manipulation of …

Jan 28, 2025
CVE-2025-0784
3.7 LOW

A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of …

Jan 28, 2025
CVE-2024-11954
2.4 LOW

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation …

Jan 28, 2025
CVE-2024-0149
3.3 LOW

NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files. A successful exploit of this vulnerability might …

Jan 28, 2025
CVE-2025-24145
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia …

Jan 27, 2025
CVE-2025-24141
3.3 LOW

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to …

Jan 27, 2025
CVE-2025-24121
3.3 LOW

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may …

Jan 27, 2025
CVE-2025-24100
3.3 LOW

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may …

Jan 27, 2025
CVE-2024-54516
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to …

Jan 27, 2025
CVE-2024-54475
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS …

Jan 27, 2025
CVE-2024-44172
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.3, macOS …

Jan 27, 2025
CVE-2025-0730
3.7 LOW

A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi …

Jan 27, 2025
CVE-2024-43446
3.5 LOW

An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This …

Jan 27, 2025
CVE-2024-13116
3.8 LOW

The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 27, 2025
CVE-2024-28766
2.4 LOW

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks …

Jan 27, 2025
CVE-2025-0720
3.3 LOW

A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes …

Jan 26, 2025
CVE-2024-13450
3.8 LOW

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Jan 25, 2025
CVE-2025-0710
3.5 LOW

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the …

Jan 24, 2025
CVE-2025-0709
2.4 LOW

A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown processing of the file /admin/auth/roles of the …

Jan 24, 2025
CVE-2025-0708
3.5 LOW

A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/model/addOrUpdate of the …

Jan 24, 2025
CVE-2025-0706
2.4 LOW

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this issue is some unknown functionality of the file …

Jan 24, 2025
CVE-2024-35122
2.8 LOW

IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local …

Jan 24, 2025
CVE-2025-24034
3.2 LOW

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to versions 0.7.15 and 0.8.3, Himmelblau is …

Jan 23, 2025
CVE-2024-52328
2.3 LOW

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem …

Jan 23, 2025
CVE-2024-12079
3.3 LOW

ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the …

Jan 23, 2025
CVE-2024-42186
2.8 LOW

BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handling of SSL certificates validation.

Jan 23, 2025
CVE-2024-42185
2.5 LOW

BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability …

Jan 23, 2025
CVE-2024-42184
2.5 LOW

BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using …

Jan 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.