CVE Database

46519+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1651
7.8 HIGH

A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1650
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1649
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1433
7.8 HIGH

A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1432
7.8 HIGH

A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a …

Mar 13, 2025
CVE-2025-1431
7.8 HIGH

A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1430
7.8 HIGH

A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute …

Mar 13, 2025
CVE-2025-1429
7.8 HIGH

A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1428
7.8 HIGH

A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1427
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2024-53406
8.8 HIGH

Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a …

Mar 13, 2025
CVE-2025-29363
7.5 HIGH

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to buffer overflow via the schedStartTime and schedEndTime parameters at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of …

Mar 13, 2025
CVE-2025-29362
7.5 HIGH

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/setPptpUserList. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Mar 13, 2025
CVE-2025-29361
7.5 HIGH

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/SetVirtualServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Mar 13, 2025
CVE-2025-29360
7.5 HIGH

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the time and timeZone parameters at /goform/SetSysTimeCfg. This vulnerability allows attackers to cause a Denial of …

Mar 13, 2025
CVE-2025-29359
7.5 HIGH

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the deviceId parameter at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Mar 13, 2025
CVE-2025-29358
7.5 HIGH

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the firewallEn parameter at /goform/SetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Mar 13, 2025
CVE-2025-29357
7.5 HIGH

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the startIp and endIp parameters at /goform/SetPptpServerCfg. This vulnerability allows attackers to cause a Denial of …

Mar 13, 2025
CVE-2025-2280
8.1 HIGH

Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature.

Mar 13, 2025
CVE-2025-2277
7.5 HIGH

Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to …

Mar 13, 2025
CVE-2024-10942
7.5 HIGH

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization …

Mar 13, 2025
CVE-2025-25175
7.8 HIGH

A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All versions < V2406.0002). The affected application contains a …

Mar 13, 2025
CVE-2025-2271
7.7 HIGH

A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insecure Direct …

Mar 13, 2025
CVE-2025-1119
7.3 HIGH

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and …

Mar 13, 2025
CVE-2025-1487
7.1 HIGH

The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 13, 2025
CVE-2025-1486
7.1 HIGH

The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 13, 2025
CVE-2025-1436
7.1 HIGH

The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which …

Mar 13, 2025
CVE-2025-1401
7.1 HIGH

The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Mar 13, 2025
CVE-2024-13891
7.1 HIGH

The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 13, 2025
CVE-2024-13885
7.1 HIGH

The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Mar 13, 2025
CVE-2024-13884
7.1 HIGH

The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 13, 2025
CVE-2025-1561
7.2 HIGH

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in all versions up to, and …

Mar 13, 2025
CVE-2025-2107
7.5 HIGH

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the printResultAndDie() function in all versions up to, and including, …

Mar 13, 2025
CVE-2025-2106
7.5 HIGH

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of the limpia() function in all versions up to, …

Mar 13, 2025
CVE-2025-25293
7.5 HIGH

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of …

Mar 12, 2025
CVE-2025-25975
7.5 HIGH

An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function

Mar 12, 2025
CVE-2025-0118
8.0 HIGH

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated …

Mar 12, 2025
CVE-2025-0114
7.5 HIGH

A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable …

Mar 12, 2025
CVE-2025-26260
8.8 HIGH

Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The …

Mar 12, 2025
CVE-2025-25711
8.8 HIGH

An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/admin/updateUser] API endpoint

Mar 12, 2025
CVE-2025-20209
7.5 HIGH

A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent an …

Mar 12, 2025
CVE-2025-20146
8.6 HIGH

A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance …

Mar 12, 2025
CVE-2025-20142
8.6 HIGH

A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR …

Mar 12, 2025
CVE-2025-20141
7.4 HIGH

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release …

Mar 12, 2025
CVE-2025-20138
8.8 HIGH

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying …

Mar 12, 2025
CVE-2025-20115
8.6 HIGH

A vulnerability in confederation implementation for the Border Gateway Protocol (BGP)&nbsp;in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial …

Mar 12, 2025
CVE-2025-1683
7.8 HIGH

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged …

Mar 12, 2025
CVE-2025-2240
7.5 HIGH

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. …

Mar 12, 2025
CVE-2025-27788
7.5 HIGH

JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of …

Mar 12, 2025
CVE-2025-25709
7.5 HIGH

An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the addUser and updateUser endpoints

Mar 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.