CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-42233
6.1 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.

Jan 13, 2025
CVE-2023-42230
6.1 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.

Jan 13, 2025
CVE-2023-42229
6.5 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the …

Jan 13, 2025
CVE-2025-22619
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22618
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22617
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22616
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22615
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22614
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22613
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22134
4.2 MEDIUM

When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not …

Jan 13, 2025
CVE-2025-23026
6.1 MEDIUM

jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTML templates with `script` tags or …

Jan 13, 2025
CVE-2025-22142
5.4 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have …

Jan 13, 2025
CVE-2024-46921
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, …

Jan 13, 2025
CVE-2024-44771
6.1 MEDIUM

BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function.

Jan 13, 2025
CVE-2024-46920
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to …

Jan 13, 2025
CVE-2024-6352
4.3 MEDIUM

A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert

Jan 13, 2025
CVE-2024-57488
6.5 MEDIUM

Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

Jan 13, 2025
CVE-2024-57487
6.5 MEDIUM

In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a …

Jan 13, 2025
CVE-2024-54999
6.5 MEDIUM

MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.

Jan 13, 2025
CVE-2024-48883
4.3 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, …

Jan 13, 2025
CVE-2024-46919
5.3 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to …

Jan 13, 2025
CVE-2024-12211
5.4 MEDIUM

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

Jan 13, 2025
CVE-2025-22800
4.3 MEDIUM

Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= …

Jan 13, 2025
CVE-2025-22828
4.3 MEDIUM

CloudStack users can add and read comments (annotations) on resources they are authorised to access. Due to an access validation issue that affects Apache CloudStack …

Jan 13, 2025
CVE-2024-52937
6.7 MEDIUM

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU …

Jan 13, 2025
CVE-2024-52936
4.4 MEDIUM

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU …

Jan 13, 2025
CVE-2024-52935
4.1 MEDIUM

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU …

Jan 13, 2025
CVE-2024-12568
4.8 MEDIUM

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workflow settings, which could allow high privilege …

Jan 13, 2025
CVE-2024-12567
4.8 MEDIUM

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege …

Jan 13, 2025
CVE-2024-12566
4.8 MEDIUM

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users …

Jan 13, 2025
CVE-2024-11636
4.8 MEDIUM

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high …

Jan 13, 2025
CVE-2025-0410
6.3 MEDIUM

A vulnerability classified as critical was found in liujianview gymxmjpa 1.0. This vulnerability affects the function MenberDaoInpl of the file src/main/java/com/liujian/gymxmjpa/controller/MenberConntroller.java. The manipulation of the …

Jan 13, 2025
CVE-2025-0409
6.3 MEDIUM

A vulnerability classified as critical has been found in liujianview gymxmjpa 1.0. This affects the function MembertypeDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/MembertypeController.java. The manipulation of the …

Jan 13, 2025
CVE-2025-0408
6.3 MEDIUM

A vulnerability was found in liujianview gymxmjpa 1.0. It has been rated as critical. Affected by this issue is the function LoosDaoImpl of the file …

Jan 13, 2025
CVE-2025-0407
6.3 MEDIUM

A vulnerability was found in liujianview gymxmjpa 1.0. It has been declared as critical. Affected by this vulnerability is the function EquipmentDaoImpl of the file …

Jan 13, 2025
CVE-2025-0406
6.3 MEDIUM

A vulnerability was found in liujianview gymxmjpa 1.0. It has been classified as critical. Affected is the function SubjectDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/SubjectController.java. The manipulation …

Jan 13, 2025
CVE-2025-0405
6.3 MEDIUM

A vulnerability was found in liujianview gymxmjpa 1.0 and classified as critical. This issue affects the function GoodsDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/GoodsController.java. The manipulation of …

Jan 13, 2025
CVE-2025-0404
6.3 MEDIUM

A vulnerability has been found in liujianview gymxmjpa 1.0 and classified as critical. This vulnerability affects the function CoachController of the file src/main/java/com/liujian/gymxmjpa/controller/CoachController.java. The manipulation …

Jan 13, 2025
CVE-2025-0403
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in 1902756969 reggie 1.0. Affected by this issue is some unknown functionality of the file …

Jan 13, 2025
CVE-2025-0402
6.3 MEDIUM

A vulnerability classified as critical was found in 1902756969 reggie 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/itheima/reggie/controller/CommonController.java. The manipulation …

Jan 13, 2025
CVE-2025-0401
5.3 MEDIUM

A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the file src/main/java/com/itheima/reggie/controller/CommonController.java. The manipulation of the …

Jan 13, 2025
CVE-2025-0399
4.7 MEDIUM

A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController of the file src/main/java/com/siro/mall/controller/common/uploadController.java. The …

Jan 12, 2025
CVE-2024-51456
5.9 MEDIUM

IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through …

Jan 12, 2025
CVE-2024-49785
5.4 MEDIUM

IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an …

Jan 12, 2025
CVE-2021-29669
5.4 MEDIUM

IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Jan 12, 2025
CVE-2024-57881
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't call pfn_to_page() on possibly non-existent PFN in split_large_buddy() In split_large_buddy(), we might call …

Jan 11, 2025
CVE-2024-57880
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array The code uses the …

Jan 11, 2025
CVE-2024-57879
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: iso: Always release hdev at the end of iso_listen_bis Since hci_get_route holds the device …

Jan 11, 2025
CVE-2024-57878
6.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_FPMR Currently fpmr_set() doesn't initialize the temporary 'fpmr' variable, …

Jan 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.