CVE Database

46519+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13412
7.5 HIGH

The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions …

Mar 19, 2025
CVE-2025-30236
8.6 HIGH

Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a …

Mar 19, 2025
CVE-2025-1232
8.8 HIGH

The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform …

Mar 19, 2025
CVE-2024-50631
7.5 HIGH

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, …

Mar 19, 2025
CVE-2024-50630
7.5 HIGH

Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain …

Mar 19, 2025
CVE-2025-30234
8.3 HIGH

SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image …

Mar 19, 2025
CVE-2024-12295
8.8 HIGH

The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is …

Mar 19, 2025
CVE-2024-10444
7.5 HIGH

Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication …

Mar 19, 2025
CVE-2025-30140
7.5 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered …

Mar 18, 2025
CVE-2024-12563
8.8 HIGH

The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This …

Mar 18, 2025
CVE-2025-30142
8.1 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism …

Mar 18, 2025
CVE-2025-30141
7.5 HIGH

An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream. It exposes API endpoints …

Mar 18, 2025
CVE-2025-29907
7.5 HIGH

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU …

Mar 18, 2025
CVE-2025-24801
8.5 HIGH

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the …

Mar 18, 2025
CVE-2025-24799
7.5 HIGH

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is …

Mar 18, 2025
CVE-2025-26137
7.5 HIGH

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by …

Mar 18, 2025
CVE-2025-27688
7.8 HIGH

Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation …

Mar 18, 2025
CVE-2025-25589
8.1 HIGH

An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted …

Mar 18, 2025
CVE-2025-30117
7.3 HIGH

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can …

Mar 18, 2025
CVE-2025-30116
7.5 HIGH

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. …

Mar 18, 2025
CVE-2025-30111
7.5 HIGH

On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained …

Mar 18, 2025
CVE-2025-30107
7.5 HIGH

On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. A vulnerability in the …

Mar 18, 2025
CVE-2025-25585
7.3 HIGH

Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.

Mar 18, 2025
CVE-2024-44313
8.1 HIGH

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to …

Mar 18, 2025
CVE-2025-30106
8.8 HIGH

On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi range …

Mar 18, 2025
CVE-2025-2450
8.8 HIGH

NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Mar 18, 2025
CVE-2025-2449
8.8 HIGH

NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of …

Mar 18, 2025
CVE-2025-25500
7.5 HIGH

An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows …

Mar 18, 2025
CVE-2024-21760
8.4 HIGH

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 …

Mar 18, 2025
CVE-2025-2493
7.5 HIGH

Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘/softdial/scheduler/load.php’ endpoint to …

Mar 18, 2025
CVE-2025-1468
7.5 HIGH

An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.

Mar 18, 2025
CVE-2024-23942
7.1 HIGH

A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or …

Mar 18, 2025
CVE-2025-25220
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vulnerability …

Mar 18, 2025
CVE-2025-24306
7.2 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.0_1101. If this vulnerability …

Mar 18, 2025
CVE-2025-0755
8.4 HIGH

The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final …

Mar 18, 2025
CVE-2025-2262
7.3 HIGH

The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in …

Mar 18, 2025
CVE-2025-2473
7.3 HIGH

A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 18, 2025
CVE-2025-2472
7.3 HIGH

A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 18, 2025
CVE-2025-2398
7.2 HIGH

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been rated as critical. This issue affects …

Mar 17, 2025
CVE-2025-29910
7.5 HIGH

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the …

Mar 17, 2025
CVE-2025-2391
7.3 HIGH

A vulnerability classified as critical was found in code-projects Blood Bank Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_login.php of the …

Mar 17, 2025
CVE-2024-54525
8.8 HIGH

A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS …

Mar 17, 2025
CVE-2024-44276
7.3 HIGH

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user …

Mar 17, 2025
CVE-2025-2388
7.3 HIGH

A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Mar 17, 2025
CVE-2025-2387
7.3 HIGH

A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file …

Mar 17, 2025
CVE-2025-26125
7.3 HIGH

An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

Mar 17, 2025
CVE-2025-22473
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

Mar 17, 2025
CVE-2025-22472
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

Mar 17, 2025
CVE-2024-49561
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit …

Mar 17, 2025
CVE-2024-49559
8.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially …

Mar 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.