CVE Database

5223+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0537
2.4 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the …

Jan 17, 2025
CVE-2024-54681
3.5 LOW

Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full …

Jan 17, 2025
CVE-2025-0530
3.5 LOW

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/_feedback_system.php. The manipulation …

Jan 17, 2025
CVE-2024-37181
2.6 LOW

Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosure via adjacent …

Jan 16, 2025
CVE-2024-57611
3.5 LOW

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.

Jan 16, 2025
CVE-2024-57159
3.5 LOW

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.

Jan 16, 2025
CVE-2024-55503
3.3 LOW

An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES component.

Jan 15, 2025
CVE-2024-53407
3.3 LOW

In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access …

Jan 15, 2025
CVE-2025-0485
3.5 LOW

A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been classified as problematic. Affected is an unknown function of the file /fladmin/sysconfig_doedit.php. The manipulation …

Jan 15, 2025
CVE-2025-0483
3.5 LOW

A vulnerability has been found in Fanli2012 native-php-cms 1.0 and classified as problematic. This vulnerability affects unknown code of the file /fladmin/jump.php. The manipulation of …

Jan 15, 2025
CVE-2024-40839
2.4 LOW

This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an …

Jan 15, 2025
CVE-2024-5198
3.3 LOW

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a …

Jan 15, 2025
CVE-2024-57898
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear link ID from bitmap during link delete after clean up Currently, during …

Jan 15, 2025
CVE-2024-55891
3.1 LOW

TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in …

Jan 14, 2025
CVE-2025-23074
2.4 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfile Extension allows Functionality Misuse.This issue affects Mediawiki - SocialProfile Extension: …

Jan 14, 2025
CVE-2025-23073
3.5 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data. This issue briefly impacted …

Jan 14, 2025
CVE-2025-21312
2.4 LOW

Windows Smart Card Reader Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-0464
2.4 LOW

A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jan 14, 2025
CVE-2024-29980
2.3 LOW

Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel …

Jan 14, 2025
CVE-2024-29979
2.3 LOW

Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel …

Jan 14, 2025
CVE-2024-55593
2.7 LOW

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information …

Jan 14, 2025
CVE-2024-52967
3.5 LOW

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code …

Jan 14, 2025
CVE-2024-52963
3.7 LOW

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a …

Jan 14, 2025
CVE-2024-50564
3.3 LOW

A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged …

Jan 14, 2025
CVE-2024-46669
3.5 LOW

An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may …

Jan 14, 2025
CVE-2024-46665
3.7 LOW

An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to …

Jan 14, 2025
CVE-2024-36506
3.7 LOW

An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow …

Jan 14, 2025
CVE-2024-51491
3.3 LOW

notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security …

Jan 13, 2025
CVE-2023-42242
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of …

Jan 13, 2025
CVE-2023-42241
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of …

Jan 13, 2025
CVE-2023-42240
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of …

Jan 13, 2025
CVE-2023-42239
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of …

Jan 13, 2025
CVE-2023-42238
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of …

Jan 13, 2025
CVE-2023-42237
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of …

Jan 13, 2025
CVE-2023-42236
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of …

Jan 13, 2025
CVE-2023-42235
3.8 LOW

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.

Jan 13, 2025
CVE-2025-0400
2.4 LOW

A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/categories/update. The …

Jan 12, 2025
CVE-2024-42181
1.6 LOW

HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel …

Jan 12, 2025
CVE-2024-42180
1.6 LOW

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and …

Jan 12, 2025
CVE-2024-42179
2.0 LOW

HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.

Jan 12, 2025
CVE-2025-0398
2.4 LOW

A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /resources/..;/inport/updateInport …

Jan 12, 2025
CVE-2025-0397
3.5 LOW

A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown function of the file /;/admin/role/edit. The manipulation of …

Jan 12, 2025
CVE-2024-42175
2.6 LOW

HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to …

Jan 11, 2025
CVE-2024-42174
3.7 LOW

HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of …

Jan 11, 2025
CVE-2025-23113
3.4 LOW

An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containing …

Jan 10, 2025
CVE-2024-13308
3.8 LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: …

Jan 9, 2025
CVE-2024-13293
3.1 LOW

Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects POST File: from 0.0.0 before 1.0.2.

Jan 9, 2025
CVE-2024-13261
3.5 LOW

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before …

Jan 9, 2025
CVE-2025-22151
3.7 LOW

Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's …

Jan 9, 2025
CVE-2024-10106
3.7 LOW

A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.

Jan 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.