CVE Database

46519+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1914
8.8 HIGH

Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out of bounds memory access via a …

Mar 5, 2025
CVE-2025-1966
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. …

Mar 5, 2025
CVE-2024-0114
8.1 HIGH

NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the …

Mar 5, 2025
CVE-2025-1965
7.3 HIGH

A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation …

Mar 5, 2025
CVE-2025-1964
7.3 HIGH

A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Mar 5, 2025
CVE-2025-1963
7.3 HIGH

A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. …

Mar 5, 2025
CVE-2025-1962
7.3 HIGH

A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been classified as critical. This affects an unknown part of the file /admin/addroom.php. …

Mar 5, 2025
CVE-2025-1959
7.3 HIGH

A vulnerability, which was classified as critical, was found in Codezips Gym Management System 1.0. Affected is an unknown function of the file /change_s_pwd.php. The …

Mar 4, 2025
CVE-2025-25426
7.2 HIGH

yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.

Mar 4, 2025
CVE-2025-1956
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component …

Mar 4, 2025
CVE-2025-1954
7.3 HIGH

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Mar 4, 2025
CVE-2021-41719
7.5 HIGH

Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive …

Mar 4, 2025
CVE-2020-23438
7.8 HIGH

Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.

Mar 4, 2025
CVE-2025-1259
7.7 HIGH

On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result …

Mar 4, 2025
CVE-2025-1080
7.8 HIGH

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In …

Mar 4, 2025
CVE-2025-1952
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/password-recovery.php. …

Mar 4, 2025
CVE-2024-41147
7.7 HIGH

An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker …

Mar 4, 2025
CVE-2024-10930
7.8 HIGH

An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

Mar 4, 2025
CVE-2025-27111
7.5 HIGH

Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by …

Mar 4, 2025
CVE-2025-23368
8.1 HIGH

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time …

Mar 4, 2025
CVE-2024-9149
8.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection.This issue affects E-Commerce …

Mar 4, 2025
CVE-2024-50705
7.1 HIGH

Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.

Mar 4, 2025
CVE-2025-1943
8.2 HIGH

Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Mar 4, 2025
CVE-2025-1940
7.1 HIGH

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching …

Mar 4, 2025
CVE-2025-1937
7.5 HIGH

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of …

Mar 4, 2025
CVE-2025-1936
7.3 HIGH

jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the …

Mar 4, 2025
CVE-2025-1933
7.6 HIGH

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them …

Mar 4, 2025
CVE-2025-1932
8.1 HIGH

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox …

Mar 4, 2025
CVE-2025-1931
7.5 HIGH

It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was …

Mar 4, 2025
CVE-2025-1930
8.8 HIGH

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led …

Mar 4, 2025
CVE-2025-22226
7.1 HIGH KEV

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a …

Mar 4, 2025
CVE-2025-22225
8.2 HIGH KEV

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an …

Mar 4, 2025
CVE-2024-58045
8.6 HIGH

Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.

Mar 4, 2025
CVE-2024-58044
8.4 HIGH

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

Mar 4, 2025
CVE-2024-58043
7.3 HIGH

Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-48248
8.6 HIGH KEV

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across …

Mar 4, 2025
CVE-2025-0360
7.8 HIGH

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to …

Mar 4, 2025
CVE-2025-0359
8.5 HIGH

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access …

Mar 4, 2025
CVE-2025-1306
8.8 HIGH

The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or …

Mar 4, 2025
CVE-2025-1903
7.3 HIGH

A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Mar 4, 2025
CVE-2025-1902
7.3 HIGH

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. …

Mar 4, 2025
CVE-2025-1901
7.3 HIGH

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file …

Mar 4, 2025
CVE-2025-1900
7.3 HIGH

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 4, 2025
CVE-2025-1639
8.8 HIGH

The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() …

Mar 4, 2025
CVE-2025-1894
7.3 HIGH

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 4, 2025
CVE-2024-51962
8.7 HIGH

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when …

Mar 3, 2025
CVE-2024-51961
7.5 HIGH

There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that …

Mar 3, 2025
CVE-2024-51954
8.5 HIGH

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a …

Mar 3, 2025
CVE-2025-27501
8.6 HIGH

OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed …

Mar 3, 2025
CVE-2025-27500
8.2 HIGH

OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed …

Mar 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.