CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3874
6.5 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to …

May 1, 2025
CVE-2025-1529
6.4 MEDIUM

The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all versions up to, and including, 3.5.3 due …

May 1, 2025
CVE-2025-4162
7.3 HIGH

A vulnerability classified as critical was found in PCMan FTP Server up to 2.0.7. This vulnerability affects unknown code of the component ASCII Command Handler. …

May 1, 2025
CVE-2025-4161
7.3 HIGH

A vulnerability classified as critical has been found in PCMan FTP Server up to 2.0.7. This affects an unknown part of the component VERBOSE Command …

May 1, 2025
CVE-2025-27007
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.

May 1, 2025
CVE-2025-4160
7.3 HIGH

A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality …

May 1, 2025
CVE-2025-4159
7.3 HIGH

A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 1, 2025
CVE-2025-4158
7.3 HIGH

A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been classified as critical. Affected is an unknown function of the component …

May 1, 2025
CVE-2025-4157
6.3 MEDIUM

A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-details.php. The …

May 1, 2025
CVE-2025-4156
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-image.php. The …

May 1, 2025
CVE-2025-4155
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/edit-boat.php. The …

May 1, 2025
CVE-2025-47154
9.0 CRITICAL

LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary …

May 1, 2025
CVE-2025-4154
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this issue is some unknown functionality of …

May 1, 2025
CVE-2025-4153
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Park Ticketing Management System 2.0. Affected by this vulnerability is an unknown functionality of the file …

May 1, 2025
CVE-2025-4100
6.4 MEDIUM

The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_map' shortcode in all versions up to, and including, 2.0 …

May 1, 2025
CVE-2025-47153
6.5 MEDIUM

Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent …

May 1, 2025
CVE-2025-3521
6.4 MEDIUM

The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 1, 2025
CVE-2025-4152
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Online Birth Certificate System 1.0. Affected is an unknown function of the file /admin/bwdates-reports-details.php. The …

May 1, 2025
CVE-2025-4151
7.3 HIGH

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

May 1, 2025
CVE-2025-3504
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-3503
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-3502
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2024-13381
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-4150
8.8 HIGH

A vulnerability was found in Netgear EX6200 1.0.3.94. It has been declared as critical. This vulnerability affects the function sub_54340. The manipulation of the argument …

May 1, 2025
CVE-2025-4099
6.4 MEDIUM

The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' shortcode in all versions up to, and including, 2.1 …

May 1, 2025
CVE-2025-3952
8.1 HIGH

The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due …

May 1, 2025
CVE-2024-13845
5.5 MEDIUM

The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'process_feed' method …

May 1, 2025
CVE-2025-4149
8.8 HIGH

A vulnerability was found in Netgear EX6200 1.0.3.94. It has been classified as critical. This affects the function sub_54014. The manipulation of the argument host …

May 1, 2025
CVE-2025-4148
8.8 HIGH

A vulnerability was found in Netgear EX6200 1.0.3.94 and classified as critical. Affected by this issue is the function sub_503FC. The manipulation of the argument …

May 1, 2025
CVE-2025-2168
4.3 MEDIUM

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to …

May 1, 2025
CVE-2025-1305
8.8 HIGH

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing or …

May 1, 2025
CVE-2025-1304
8.8 HIGH

The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up …

May 1, 2025
CVE-2025-2816
8.1 HIGH

The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a …

May 1, 2025
CVE-2025-4147
8.8 HIGH

A vulnerability has been found in Netgear EX6200 1.0.3.94 and classified as critical. Affected by this vulnerability is the function sub_47F7C. The manipulation of the …

May 1, 2025
CVE-2025-4146
8.8 HIGH

A vulnerability, which was classified as critical, was found in Netgear EX6200 1.0.3.94. Affected is the function sub_41940. The manipulation of the argument host leads …

May 1, 2025
CVE-2025-4145
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Netgear EX6200 1.0.3.94. This issue affects the function sub_3D0BC. The manipulation of the argument …

May 1, 2025
CVE-2025-4144
9.8 CRITICAL

PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could …

May 1, 2025
CVE-2025-4143
6.1 MEDIUM

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of …

May 1, 2025
CVE-2025-4142
8.8 HIGH

A vulnerability has been found in Netgear EX6200 1.0.3.94 and classified as critical. This vulnerability affects the function sub_3C8EC. The manipulation of the argument host …

Apr 30, 2025
CVE-2025-4141
8.8 HIGH

A vulnerability, which was classified as critical, was found in Netgear EX6200 1.0.3.94. This affects the function sub_3C03C. The manipulation of the argument host leads …

Apr 30, 2025
CVE-2025-4140
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Netgear EX6120 1.0.3.94. Affected by this issue is the function sub_30394. The manipulation of …

Apr 30, 2025
CVE-2024-30146
4.1 MEDIUM

Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

Apr 30, 2025
CVE-2024-30145
6.5 MEDIUM

Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

Apr 30, 2025
CVE-2024-30115
6.3 MEDIUM

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

Apr 30, 2025
CVE-2023-4533

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. It was assigned as a duplicate of CVE-2023-52440

Apr 30, 2025
CVE-2023-45721
5.3 MEDIUM

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

Apr 30, 2025
CVE-2023-37535
7.1 HIGH

Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

Apr 30, 2025
CVE-2023-37517
3.2 LOW

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

Apr 30, 2025
CVE-2022-42450
4.6 MEDIUM

Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

Apr 30, 2025
CVE-2025-4139
8.8 HIGH

A vulnerability classified as critical was found in Netgear EX6120 1.0.0.68. Affected by this vulnerability is the function fwAcosCgiInbound. The manipulation of the argument host …

Apr 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.