CVE Database

46519+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23398
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions …

Mar 11, 2025
CVE-2025-23397
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions …

Mar 11, 2025
CVE-2025-23396
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versions < V2312.0009), Teamcenter Visualization V2406 (All versions …

Mar 11, 2025
CVE-2024-56182
8.2 HIGH

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions …

Mar 11, 2025
CVE-2024-56181
8.2 HIGH

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < …

Mar 11, 2025
CVE-2025-2177
7.3 HIGH

A vulnerability classified as critical was found in libzvbi up to 0.2.43. This vulnerability affects the function vbi_search_new of the file src/search.c. The manipulation of …

Mar 11, 2025
CVE-2025-2176
7.3 HIGH

A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim_load_caption of the file src/io-sim.c. The manipulation leads …

Mar 11, 2025
CVE-2025-27912
8.8 HIGH

An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect authentication is …

Mar 11, 2025
CVE-2025-2190
8.1 HIGH

The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks.

Mar 11, 2025
CVE-2024-13864
7.1 HIGH

The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 11, 2025
CVE-2024-13862
7.1 HIGH

The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading …

Mar 11, 2025
CVE-2024-13836
7.1 HIGH

The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Mar 11, 2025
CVE-2024-13574
7.1 HIGH

The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Mar 11, 2025
CVE-2025-2169
7.3 HIGH

The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.0.4. …

Mar 11, 2025
CVE-2024-12010
7.2 HIGH

A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator …

Mar 11, 2025
CVE-2024-12009
7.2 HIGH

A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator …

Mar 11, 2025
CVE-2024-11253
7.2 HIGH

A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier could allow an …

Mar 11, 2025
CVE-2025-27434
8.8 HIGH

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged …

Mar 11, 2025
CVE-2025-26661
8.8 HIGH

Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation …

Mar 11, 2025
CVE-2025-1828
8.8 HIGH

Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptographic functions. If the Provider is not specified and …

Mar 11, 2025
CVE-2025-27925
8.5 HIGH

Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

Mar 10, 2025
CVE-2025-27610
7.5 HIGH

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` …

Mar 10, 2025
CVE-2025-27910
8.0 HIGH

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a …

Mar 10, 2025
CVE-2025-25907
8.8 HIGH

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a …

Mar 10, 2025
CVE-2025-2137
8.8 HIGH

Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a …

Mar 10, 2025
CVE-2025-2136
8.8 HIGH

Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 10, 2025
CVE-2025-2135
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Mar 10, 2025
CVE-2025-1920
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Mar 10, 2025
CVE-2024-56192
7.8 HIGH

In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Mar 10, 2025
CVE-2024-56191
8.4 HIGH

In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional …

Mar 10, 2025
CVE-2025-27913
7.5 HIGH

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with …

Mar 10, 2025
CVE-2022-43454
7.8 HIGH

A double free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, …

Mar 10, 2025
CVE-2025-27616
8.5 HIGH

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webhook …

Mar 10, 2025
CVE-2025-27615
8.2 HIGH

umatiGateway is software for connecting OPC Unified Architecture servers with an MQTT broker utilizing JSON messages. The user interface may possibly be publicly accessible with …

Mar 10, 2025
CVE-2025-26696
7.0 HIGH

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being …

Mar 10, 2025
CVE-2025-22603
8.1 HIGH

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Versions prior to autogpt-platform-beta-v0.4.2 contains …

Mar 10, 2025
CVE-2024-54546
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected system …

Mar 10, 2025
CVE-2024-44227
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be …

Mar 10, 2025
CVE-2025-25382
7.5 HIGH

An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

Mar 10, 2025
CVE-2025-26933
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order Without Payment wc-place-order-without-payment allows …

Mar 10, 2025
CVE-2025-26910
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1.

Mar 10, 2025
CVE-2025-25614
8.8 HIGH

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

Mar 10, 2025
CVE-2024-13919
8.0 HIGH

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode …

Mar 10, 2025
CVE-2024-13918
8.0 HIGH

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode …

Mar 10, 2025
CVE-2025-27256
8.3 HIGH

Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the …

Mar 10, 2025
CVE-2025-27255
8.0 HIGH

Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable …

Mar 10, 2025
CVE-2025-27254
8.0 HIGH

CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry …

Mar 10, 2025
CVE-2024-11638
8.8 HIGH

The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated …

Mar 10, 2025
CVE-2024-43107
7.2 HIGH

Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to be sent to the Plugin. This issue …

Mar 10, 2025
CVE-2024-41724
8.7 HIGH

Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of …

Mar 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.