CVE Database

5223+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46326
3.3 LOW

snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When …

Apr 28, 2025
CVE-2025-0049
3.5 LOW

When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server …

Apr 28, 2025
CVE-2025-46614
3.3 LOW

In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive …

Apr 28, 2025
CVE-2023-35816
3.5 LOW

DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.

Apr 28, 2025
CVE-2023-35815
3.5 LOW

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

Apr 28, 2025
CVE-2023-35814
3.5 LOW

DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

Apr 28, 2025
CVE-2025-23376
2.3 LOW

Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged …

Apr 28, 2025
CVE-2025-4012
2.7 LOW

A vulnerability was found in playeduxyz PlayEdu 开源培训系统 up to 1.8 and classified as problematic. This issue affects some unknown processing of the file /api/backend/v1/user/create …

Apr 28, 2025
CVE-2025-4011
3.5 LOW

A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation …

Apr 28, 2025
CVE-2025-32471
3.7 LOW

The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.

Apr 28, 2025
CVE-2025-0627
3.5 LOW

The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high …

Apr 28, 2025
CVE-2024-9771
3.5 LOW

The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Apr 28, 2025
CVE-2025-4001
3.3 LOW

A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability is the function main of the …

Apr 28, 2025
CVE-2025-4000
3.5 LOW

A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function of the …

Apr 28, 2025
CVE-2025-3999
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unknown processing …

Apr 28, 2025
CVE-2025-3996
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Apr 28, 2025
CVE-2025-3995
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Apr 28, 2025
CVE-2025-3994
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unknown function of the file /home.htm of the …

Apr 28, 2025
CVE-2025-3985
2.7 LOW

A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation …

Apr 27, 2025
CVE-2025-3970
3.5 LOW

A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. The manipulation …

Apr 27, 2025
CVE-2025-3965
3.5 LOW

A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. …

Apr 27, 2025
CVE-2024-52887
3.5 LOW

Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.

Apr 27, 2025
CVE-2025-3962
3.5 LOW

A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects unknown code of the file /api/comment/add of the component Comment Handler. …

Apr 27, 2025
CVE-2025-3961
3.5 LOW

A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unknown part of the file /admin/article/add/do. The manipulation of the …

Apr 27, 2025
CVE-2025-3958
3.5 LOW

A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is an unknown function of the file /book_edit_do.html of the …

Apr 27, 2025
CVE-2025-46675
3.5 LOW

In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.

Apr 27, 2025
CVE-2025-46674
3.5 LOW

NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.

Apr 27, 2025
CVE-2025-46672
3.5 LOW

NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.

Apr 27, 2025
CVE-2025-46656
2.9 LOW

python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.

Apr 26, 2025
CVE-2025-3954
3.7 LOW

A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some unknown functionality of the component Referer …

Apr 26, 2025
CVE-2025-46653
3.1 LOW

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as …

Apr 26, 2025
CVE-2025-2850
3.5 LOW

A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 …

Apr 26, 2025
CVE-2025-46618
3.5 LOW

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

Apr 25, 2025
CVE-2025-3637
3.1 LOW

A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This …

Apr 25, 2025
CVE-2025-3635
3.5 LOW

A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection …

Apr 25, 2025
CVE-2024-57375
2.4 LOW

Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) …

Apr 25, 2025
CVE-2025-46546
3.5 LOW

In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, …

Apr 25, 2025
CVE-2024-30127
3.2 LOW

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

Apr 24, 2025
CVE-2023-37516
3.2 LOW

Missing "no cache" headers in HCL Leap permits user directory information to be cached.

Apr 24, 2025
CVE-2024-30114
3.7 LOW

Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

Apr 24, 2025
CVE-2025-41423
3.1 LOW

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or …

Apr 24, 2025
CVE-2025-25046
3.7 LOW

IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using …

Apr 23, 2025
CVE-2024-58251
2.5 LOW

In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a …

Apr 23, 2025
CVE-2025-46394
3.2 LOW

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

Apr 23, 2025
CVE-2025-46393
2.9 LOW

In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).

Apr 23, 2025
CVE-2025-43965
2.9 LOW

In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.

Apr 23, 2025
CVE-2025-23253
2.5 LOW

NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a …

Apr 22, 2025
CVE-2025-3850
3.7 LOW

A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The …

Apr 22, 2025
CVE-2025-2987
3.8 LOW

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, …

Apr 22, 2025
CVE-2025-3841
3.3 LOW

A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of …

Apr 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.