Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-23209 KEV |
|
[KEV] Code Injection in Craft cms craft-cms (CVE-2025-23209)
code injection in Craft cms craft-cms (CVE-2025-23209). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-0624 |
|
Out-of-Bounds Write in CVE-2025-0624 (CVE-2025-0624)
out-of-bounds write in CVE-2025-0624 (CVE-2025-0624). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57256 |
|
Vulnerability in denx (CVE-2024-57256)
vulnerability in denx (CVE-2024-57256). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57258 |
|
Vulnerability in denx (CVE-2024-57258)
vulnerability in denx (CVE-2024-57258). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21702 |
|
Vulnerability in privilege-escalation (CVE-2025-21702)
vulnerability in privilege-escalation (CVE-2025-21702). Successful exploitation can lead to full system takeover. Exploitable via ``NET_XMIT_CN``.
|
| CVE-2025-0108 KEV |
|
[KEV] Vulnerability in Palo alto networks palo-alto-networks (CVE-2025-0108)
vulnerability in Palo alto networks palo-alto-networks (CVE-2025-0108). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-12651 |
|
Vulnerability in CVE-2024-12651 (CVE-2024-12651)
vulnerability in CVE-2024-12651 (CVE-2024-12651). Confidential information can be exposed externally.
|
| CVE-2025-21701 |
|
Vulnerability in c (CVE-2025-21701)
vulnerability in c (CVE-2025-21701). Successful exploitation can lead to full system takeover.
|
| CVE-2025-26569 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-26569)
vulnerability in csrf (CVE-2025-26569). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-26570 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-26570)
vulnerability in csrf (CVE-2025-26570). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-1247 |
|
Vulnerability in CVE-2025-1247 (CVE-2025-1247)
vulnerability in CVE-2025-1247 (CVE-2025-1247). Confidential information can be exposed externally.
|
| CVE-2024-57727 KEV |
|
[KEV] Path Traversal in Simplehelp path-traversal (CVE-2024-57727)
path traversal in Simplehelp path-traversal (CVE-2024-57727). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2025-1244 |
|
OS Command Injection in CVE-2025-1244 (CVE-2025-1244)
OS command injection in CVE-2025-1244 (CVE-2025-1244). Successful exploitation can lead to full system takeover.
|
| CVE-2024-12251 |
|
Command Injection in telerik (CVE-2024-12251)
command injection in telerik (CVE-2024-12251). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21699 |
|
Vulnerability in linux (CVE-2025-21699)
vulnerability in linux (CVE-2025-21699). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21697 |
|
Vulnerability in linux (CVE-2025-21697)
vulnerability in linux (CVE-2025-21697). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57952 |
|
Vulnerability in linux (CVE-2024-57952)
vulnerability in linux (CVE-2024-57952). Data can be tampered with by attackers.
|
| CVE-2024-57951 |
|
Use-After-Free in linux (CVE-2024-57951)
vulnerability in linux (CVE-2024-57951). Successful exploitation can lead to full system takeover.
|
| CVE-2025-24200 KEV |
|
[KEV] Authorization Flaw in Apple ios-and-ipados (CVE-2025-24200)
vulnerability in Apple ios-and-ipados (CVE-2025-24200). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-41710 KEV |
|
[KEV] Vulnerability in Mitel sip-phones (CVE-2024-41710)
vulnerability in Mitel sip-phones (CVE-2024-41710). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-40891 KEV |
|
[KEV] OS Command Injection in Zyxel dsl-cpe-devices (CVE-2024-40891)
OS command injection in Zyxel dsl-cpe-devices (CVE-2024-40891). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-40890 KEV |
|
[KEV] OS Command Injection in Zyxel dsl-cpe-devices (CVE-2024-40890)
OS command injection in Zyxel dsl-cpe-devices (CVE-2024-40890). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21418 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-21418)
vulnerability in Microsoft windows (CVE-2025-21418). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21391 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-21391)
vulnerability in Microsoft windows (CVE-2025-21391). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21687 |
|
Out-of-Bounds Read in linux (CVE-2025-21687)
vulnerability in linux (CVE-2025-21687). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21692 |
|
Vulnerability in c (CVE-2025-21692)
vulnerability in c (CVE-2025-21692). Successful exploitation can lead to full system takeover.
|
| CVE-2025-0994 KEV |
|
[KEV] Unsafe Deserialization in Trimble cityworks (CVE-2025-0994)
vulnerability in Trimble cityworks (CVE-2025-0994). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-15069 KEV |
|
[KEV] Vulnerability in Sophos xg-firewall (CVE-2020-15069)
vulnerability in Sophos xg-firewall (CVE-2020-15069). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-23748 KEV |
|
[KEV] Vulnerability in Audinate dante-discovery (CVE-2022-23748)
vulnerability in Audinate dante-discovery (CVE-2022-23748). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-0411 KEV |
|
[KEV] Vulnerability in 7-zip (CVE-2025-0411)
vulnerability in 7-zip (CVE-2025-0411). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-1022 |
|
Vulnerability in CVE-2025-1022 (CVE-2025-1022)
vulnerability in CVE-2025-1022 (CVE-2025-1022). Confidential information can be exposed externally.
|
| CVE-2024-53104 KEV |
|
[KEV] Out-of-Bounds Write in Linux kernel (CVE-2024-53104)
out-of-bounds write in Linux kernel (CVE-2024-53104). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-22205 |
|
Path Traversal in path-traversal (CVE-2025-22205)
path traversal in path-traversal (CVE-2025-22205). Confidential information can be exposed externally.
|
| CVE-2018-19410 KEV |
|
[KEV] Vulnerability in Paessler prtg-network-monitor (CVE-2018-19410)
vulnerability in Paessler prtg-network-monitor (CVE-2018-19410). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-9276 KEV |
|
[KEV] OS Command Injection in Paessler prtg-network-monitor (CVE-2018-9276)
OS command injection in Paessler prtg-network-monitor (CVE-2018-9276). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-29059 KEV |
|
[KEV] Vulnerability in Microsoft net-framework (CVE-2024-29059)
vulnerability in Microsoft net-framework (CVE-2024-29059). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-45195 KEV |
|
[KEV] Vulnerability in Apache ofbiz (CVE-2024-45195)
vulnerability in Apache ofbiz (CVE-2024-45195). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-34896 |
|
Vulnerability in CVE-2024-34896 (CVE-2024-34896)
vulnerability in CVE-2024-34896 (CVE-2024-34896). Confidential information can be exposed externally.
|
| CVE-2024-34897 |
|
Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
|
| CVE-2025-21682 |
|
Vulnerability in linux (CVE-2025-21682)
vulnerability in linux (CVE-2025-21682). Confidential information can be exposed externally.
|
| CVE-2025-21669 |
|
Vulnerability in linux (CVE-2025-21669)
vulnerability in linux (CVE-2025-21669). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21678 |
|
Vulnerability in c (CVE-2025-21678)
vulnerability in c (CVE-2025-21678). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21676 |
|
Vulnerability in linux (CVE-2025-21676)
vulnerability in linux (CVE-2025-21676). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-21677 |
|
Vulnerability in c (CVE-2025-21677)
vulnerability in c (CVE-2025-21677). Successful exploitation can lead to full system takeover.
|
| CVE-2025-24085 KEV |
|
[KEV] Use-After-Free in Apple multiple-products (CVE-2025-24085)
vulnerability in Apple multiple-products (CVE-2025-24085). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-13484 |
|
Vulnerability in github.com/redhat-developer/gitops-operator (CVE-2024-13484)
vulnerability in github.com/redhat-developer/gitops-operator (CVE-2024-13484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.16.2` or later.
|
| CVE-2024-48419 |
|
Command Injection in edimax (CVE-2024-48419)
command injection in edimax (CVE-2024-48419). Successful exploitation can lead to full system takeover.
|
| CVE-2024-48420 |
|
Vulnerability in edimax (CVE-2024-48420)
vulnerability in edimax (CVE-2024-48420). Successful exploitation can lead to full system takeover.
|
| CVE-2024-48416 |
|
Vulnerability in edimax (CVE-2024-48416)
vulnerability in edimax (CVE-2024-48416). Successful exploitation can lead to full system takeover.
|
| CVE-2024-48418 |
|
Cross-Site Request Forgery (CSRF) in edimax (CVE-2024-48418)
vulnerability in edimax (CVE-2024-48418). Successful exploitation can lead to full system takeover.
|