CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46618
3.5 LOW

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

Apr 25, 2025
CVE-2025-46433
4.9 MEDIUM

In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

Apr 25, 2025
CVE-2025-46432
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs

Apr 25, 2025
CVE-2025-43862
7.6 HIGH

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though …

Apr 25, 2025
CVE-2025-43016
5.4 MEDIUM

In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

Apr 25, 2025
CVE-2025-3647
4.3 MEDIUM

A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.

Apr 25, 2025
CVE-2025-3645
4.3 MEDIUM

A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

Apr 25, 2025
CVE-2025-3644
4.3 MEDIUM

A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

Apr 25, 2025
CVE-2025-3643
5.4 MEDIUM

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

Apr 25, 2025
CVE-2025-3642
8.8 HIGH

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available …

Apr 25, 2025
CVE-2025-3641
8.8 HIGH

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available …

Apr 25, 2025
CVE-2025-3640
4.3 MEDIUM

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as …

Apr 25, 2025
CVE-2025-3638
8.8 HIGH

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request …

Apr 25, 2025
CVE-2025-3637
3.1 LOW

A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This …

Apr 25, 2025
CVE-2025-3636
4.3 MEDIUM

A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.

Apr 25, 2025
CVE-2025-3635
3.5 LOW

A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection …

Apr 25, 2025
CVE-2025-3628
4.3 MEDIUM

A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.

Apr 25, 2025
CVE-2025-3627
4.3 MEDIUM

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using …

Apr 25, 2025
CVE-2025-3625
7.1 HIGH

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into …

Apr 25, 2025
CVE-2025-32432
10.0 CRITICAL KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to …

Apr 25, 2025
CVE-2025-32045
5.3 MEDIUM

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

Apr 25, 2025
CVE-2025-32044
7.5 HIGH

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack …

Apr 25, 2025
CVE-2025-28076
6.5 MEDIUM

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) …

Apr 25, 2025
CVE-2025-3634
4.3 MEDIUM

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can …

Apr 25, 2025
CVE-2025-28354
6.5 MEDIUM

An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted …

Apr 25, 2025
CVE-2024-57375
2.4 LOW

Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) …

Apr 25, 2025
CVE-2024-6199

An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific …

Apr 25, 2025
CVE-2024-6198

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected …

Apr 25, 2025
CVE-2025-3912
5.3 MEDIUM

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to …

Apr 25, 2025
CVE-2025-2986
5.5 MEDIUM

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web …

Apr 25, 2025
CVE-2025-2470
9.8 CRITICAL

The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in …

Apr 25, 2025
CVE-2024-11917
8.1 HIGH

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to …

Apr 25, 2025
CVE-2025-1565
7.5 HIGH

The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/peaks/remote_dl.php file. This …

Apr 25, 2025
CVE-2025-3870
6.1 MEDIUM

The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.dec.2012. This is due to …

Apr 25, 2025
CVE-2025-1279
8.8 HIGH

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability …

Apr 25, 2025
CVE-2025-46535
5.4 MEDIUM

Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a …

Apr 25, 2025
CVE-2025-46482
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz wp-quiz allows Stored XSS.This issue affects WP Quiz: from n/a …

Apr 25, 2025
CVE-2025-46617
7.2 HIGH

Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. …

Apr 25, 2025
CVE-2025-46616
9.9 CRITICAL

Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, …

Apr 25, 2025
CVE-2025-3868
6.1 MEDIUM

The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 …

Apr 25, 2025
CVE-2025-3867
6.1 MEDIUM

The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due …

Apr 25, 2025
CVE-2025-3866
6.1 MEDIUM

The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Apr 25, 2025
CVE-2025-3743
5.3 MEDIUM

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due …

Apr 25, 2025
CVE-2025-2238
8.8 HIGH

The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in …

Apr 25, 2025
CVE-2025-46613
7.5 HIGH

OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.

Apr 25, 2025
CVE-2025-3923
5.3 MEDIUM

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 …

Apr 25, 2025
CVE-2025-3861
5.4 MEDIUM

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability …

Apr 25, 2025
CVE-2025-3511
7.5 HIGH

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link …

Apr 25, 2025
CVE-2025-2580
4.9 MEDIUM

The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Apr 25, 2025
CVE-2025-0671
6.1 MEDIUM

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as …

Apr 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.