CVE Database

58655+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10481
6.5 MEDIUM

A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host malicious websites that, when visited by authenticated ComfyUI users, …

Mar 20, 2025
CVE-2024-10457
6.5 MEDIUM

Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt repository, specifically in the GitHub Integration and Web Search blocks. These vulnerabilities affect version …

Mar 20, 2025
CVE-2024-10366
6.5 MEDIUM

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment …

Mar 20, 2025
CVE-2024-10363
5.4 MEDIUM

In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the …

Mar 20, 2025
CVE-2024-10359
4.6 MEDIUM

In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This …

Mar 20, 2025
CVE-2024-10330
6.5 MEDIUM

In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of …

Mar 20, 2025
CVE-2024-10274
6.5 MEDIUM

An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms, allowing unauthorized users to access sensitive information about …

Mar 20, 2025
CVE-2024-10273
6.5 MEDIUM

In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for …

Mar 20, 2025
CVE-2024-10047
5.3 MEDIUM

parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending …

Mar 20, 2025
CVE-2024-10019
6.7 MEDIUM

A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the …

Mar 20, 2025
CVE-2024-0640
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via …

Mar 20, 2025
CVE-2024-0245
5.5 MEDIUM

A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious applications to inherit permissions of the vulnerable …

Mar 20, 2025
CVE-2024-54016
4.3 MEDIUM

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): through <=2.2.0. Users are recommended to …

Mar 20, 2025
CVE-2025-2108
6.4 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Site Title’ widget's 'title_tag' …

Mar 20, 2025
CVE-2025-1766
5.3 MEDIUM

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Mar 20, 2025
CVE-2025-1314
4.3 MEDIUM

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Mar 20, 2025
CVE-2025-30092
6.1 MEDIUM

Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts.

Mar 19, 2025
CVE-2025-27776
5.3 MEDIUM

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 240 in …

Mar 19, 2025
CVE-2025-27775
5.3 MEDIUM

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 143 in …

Mar 19, 2025
CVE-2025-27774
5.3 MEDIUM

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 156 in …

Mar 19, 2025
CVE-2025-26816
6.5 MEDIUM

A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see …

Mar 19, 2025
CVE-2024-55009
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context …

Mar 19, 2025
CVE-2025-2536
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through …

Mar 19, 2025
CVE-2024-7631
4.3 MEDIUM

A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters …

Mar 19, 2025
CVE-2025-29925
5.3 MEDIUM

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if …

Mar 19, 2025
CVE-2025-29405
6.3 MEDIUM

An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a …

Mar 19, 2025
CVE-2024-25132
4.3 MEDIUM

A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to …

Mar 19, 2025
CVE-2025-29118
6.5 MEDIUM

Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.

Mar 19, 2025
CVE-2025-0431
5.8 MEDIUM

Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity …

Mar 19, 2025
CVE-2024-53970
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Mar 19, 2025
CVE-2024-53969
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in …

Mar 19, 2025
CVE-2024-53968
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in …

Mar 19, 2025
CVE-2024-53967
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in …

Mar 19, 2025
CVE-2025-30196
6.5 MEDIUM

Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulting in a stored …

Mar 19, 2025
CVE-2025-30152
6.5 MEDIUM

The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows …

Mar 19, 2025
CVE-2025-30144
6.5 MEDIUM

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly validate the iss claim based on the RFC …

Mar 19, 2025
CVE-2025-2324
5.9 MEDIUM

Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 …

Mar 19, 2025
CVE-2025-29770
6.5 MEDIUM

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the backends used by vLLM to support …

Mar 19, 2025
CVE-2025-26486
6.0 MEDIUM

Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable …

Mar 19, 2025
CVE-2025-26485
5.8 MEDIUM

A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usage of a wrong …

Mar 19, 2025
CVE-2025-26475
5.5 MEDIUM

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping containers running during daemon restarts, reducing …

Mar 19, 2025
CVE-2025-23382
5.5 MEDIUM

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A …

Mar 19, 2025
CVE-2025-1758
4.3 MEDIUM

Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 …

Mar 19, 2025
CVE-2025-1472
4.3 MEDIUM

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No …

Mar 19, 2025
CVE-2025-2511
4.9 MEDIUM

The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.6 due …

Mar 19, 2025
CVE-2024-45644
4.7 MEDIUM

IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

Mar 19, 2025
CVE-2025-27018
6.3 MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql …

Mar 19, 2025
CVE-2024-12136
6.9 MEDIUM

Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass.This issue affects ANKA JPD-00028: before V.01.01.

Mar 19, 2025
CVE-2024-50629
5.3 MEDIUM

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, …

Mar 19, 2025
CVE-2025-2290
5.3 MEDIUM

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability …

Mar 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.