CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1084
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this issue is some unknown functionality. The manipulation …

Feb 7, 2025
CVE-2025-21404
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Feb 6, 2025
CVE-2025-21283
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 6, 2025
CVE-2025-21279
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 6, 2025
CVE-2025-21267
4.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Feb 6, 2025
CVE-2025-21253
5.3 MEDIUM

Microsoft Edge for IOS and Android Spoofing Vulnerability

Feb 6, 2025
CVE-2024-53586
5.3 MEDIUM

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads …

Feb 6, 2025
CVE-2024-48589
6.3 MEDIUM

Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php

Feb 6, 2025
CVE-2024-25883
5.3 MEDIUM

The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.

Feb 6, 2025
CVE-2020-36085
6.3 MEDIUM

Stored Cross Site Scripting(XSS) vulnerability in Egavilan Media Resumes Management and Job Application Website 1.0 allows remote attackers to inject arbitrary code via First and …

Feb 6, 2025
CVE-2025-1004
5.3 MEDIUM

Certain HP LaserJet Pro printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer via IPP …

Feb 6, 2025
CVE-2025-0158
5.5 MEDIUM

IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.

Feb 6, 2025
CVE-2025-22936
5.7 MEDIUM

An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi …

Feb 6, 2025
CVE-2024-57673
5.5 MEDIUM

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

Feb 6, 2025
CVE-2024-57672
5.5 MEDIUM

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing module.

Feb 6, 2025
CVE-2024-52892
6.1 MEDIUM

IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in …

Feb 6, 2025
CVE-2024-47256
6.0 MEDIUM

Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to read hardcoded AES passphrase, which may be used …

Feb 6, 2025
CVE-2024-13417
4.6 MEDIUM

Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it gets back to fully working …

Feb 6, 2025
CVE-2024-57523
4.5 MEDIUM

Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests …

Feb 6, 2025
CVE-2024-13416
4.3 MEDIUM

Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has released an updated …

Feb 6, 2025
CVE-2024-36557
6.6 MEDIUM

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious …

Feb 6, 2025
CVE-2025-22866
4.0 MEDIUM

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars …

Feb 6, 2025
CVE-2025-1078
5.3 MEDIUM

A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection …

Feb 6, 2025
CVE-2024-57599
4.8 MEDIUM

Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in …

Feb 6, 2025
CVE-2024-57429
5.4 MEDIUM

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an …

Feb 6, 2025
CVE-2024-57427
6.1 MEDIUM

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a …

Feb 6, 2025
CVE-2024-13614
5.3 MEDIUM

Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small …

Feb 6, 2025
CVE-2022-40490
4.8 MEDIUM

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via …

Feb 6, 2025
CVE-2025-1076
4.8 MEDIUM

A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload …

Feb 6, 2025
CVE-2025-1074
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component …

Feb 6, 2025
CVE-2024-24911
5.3 MEDIUM

In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the …

Feb 6, 2025
CVE-2024-57962
6.1 MEDIUM

Vulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this vulnerability may affect availability.

Feb 6, 2025
CVE-2024-57961
6.8 MEDIUM

Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57959
6.1 MEDIUM

Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57958
5.7 MEDIUM

Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 6, 2025
CVE-2024-57957
6.6 MEDIUM

Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-57955
6.1 MEDIUM

Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-57954
6.2 MEDIUM

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-12602
6.2 MEDIUM

Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Feb 6, 2025
CVE-2024-45626
6.5 MEDIUM

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in …

Feb 6, 2025
CVE-2025-0859
6.5 MEDIUM

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up …

Feb 6, 2025
CVE-2025-24845
5.5 MEDIUM

Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially …

Feb 6, 2025
CVE-2025-24483
5.5 MEDIUM

NULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of …

Feb 6, 2025
CVE-2025-0522
4.7 MEDIUM

The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Feb 6, 2025
CVE-2025-0799
6.5 MEDIUM

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system …

Feb 6, 2025
CVE-2024-49800
4.3 MEDIUM

IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

Feb 6, 2025
CVE-2024-49798
4.3 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information …

Feb 6, 2025
CVE-2024-49797
5.9 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker …

Feb 6, 2025
CVE-2024-49796
5.4 MEDIUM

IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web …

Feb 6, 2025
CVE-2024-49795
4.3 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that …

Feb 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.