CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46546
3.5 LOW

In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, …

Apr 25, 2025
CVE-2025-46545
4.4 MEDIUM

In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS …

Apr 25, 2025
CVE-2025-46544
6.4 MEDIUM

In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

Apr 25, 2025
CVE-2025-43865
8.2 HIGH

React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding …

Apr 25, 2025
CVE-2025-43864
7.5 HIGH

React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch …

Apr 25, 2025
CVE-2025-3606
7.5 HIGH

Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing sensitive information, such as credentials which could be …

Apr 25, 2025
CVE-2025-2185
8.0 HIGH

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker …

Apr 25, 2025
CVE-2025-46275
9.8 CRITICAL

WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials.

Apr 24, 2025
CVE-2025-46274
9.8 CRITICAL

UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.

Apr 24, 2025
CVE-2025-46273
9.8 CRITICAL

UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.

Apr 24, 2025
CVE-2025-46272
9.1 CRITICAL

WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system.

Apr 24, 2025
CVE-2025-46271
9.1 CRITICAL

UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

Apr 24, 2025
CVE-2025-3749
6.4 MEDIUM

The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due …

Apr 24, 2025
CVE-2025-1294
7.2 HIGH

The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to …

Apr 24, 2025
CVE-2025-43861
4.4 MEDIUM

ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review …

Apr 24, 2025
CVE-2025-29529
6.5 MEDIUM

ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.

Apr 24, 2025
CVE-2025-25777
8.0 HIGH

Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the …

Apr 24, 2025
CVE-2024-30127
3.2 LOW

Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

Apr 24, 2025
CVE-2023-37516
3.2 LOW

Missing "no cache" headers in HCL Leap permits user directory information to be cached.

Apr 24, 2025
CVE-2022-44760
4.6 MEDIUM

Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

Apr 24, 2025
CVE-2022-44759
4.6 MEDIUM

Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

Apr 24, 2025
CVE-2025-26382

Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue

Apr 24, 2025
CVE-2025-43859
9.1 CRITICAL

h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead …

Apr 24, 2025
CVE-2025-43858
9.2 CRITICAL

YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of …

Apr 24, 2025
CVE-2025-31324
10.0 CRITICAL KEV

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely …

Apr 24, 2025
CVE-2024-30147
6.5 MEDIUM

Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

Apr 24, 2025
CVE-2024-30114
3.7 LOW

Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

Apr 24, 2025
CVE-2024-30113
6.3 MEDIUM

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

Apr 24, 2025
CVE-2023-45720
5.3 MEDIUM

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

Apr 24, 2025
CVE-2023-37534
7.1 HIGH

Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

Apr 24, 2025
CVE-2025-46542
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeXpert Xpert Tab xpert-tab allows Stored XSS.This issue affects Xpert Tab: from n/a …

Apr 24, 2025
CVE-2025-46541
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elrata_ WP-reCAPTCHA-bp wp-recaptcha-bp allows Stored XSS.This issue affects WP-reCAPTCHA-bp: from n/a through <= …

Apr 24, 2025
CVE-2025-46540
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Mok GNA Search Shortcode gna-search-shortcode allows Stored XSS.This issue affects GNA Search …

Apr 24, 2025
CVE-2025-46538
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webplanetsoft Inline Text Popup inline-text-popup allows DOM-Based XSS.This issue affects Inline Text Popup: …

Apr 24, 2025
CVE-2025-46536
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RichardHarrison Carousel-of-post-images carousel-of-post-images allows DOM-Based XSS.This issue affects Carousel-of-post-images: from n/a through <= …

Apr 24, 2025
CVE-2025-46534
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DanielRiera Image Style Hover image-content-show-hover allows DOM-Based XSS.This issue affects Image Style Hover: …

Apr 24, 2025
CVE-2025-46533
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdrift.no Landing pages and Domain aliases for WordPress landing-pages-and-domain-aliases allows Stored XSS.This issue …

Apr 24, 2025
CVE-2025-46532
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haris Zulfiqar Tooltip wp-tooltip allows DOM-Based XSS.This issue affects Tooltip: from n/a through …

Apr 24, 2025
CVE-2025-46531
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) woozap allows Server Side Request Forgery.This issue affects WP AVCL Automation …

Apr 24, 2025
CVE-2025-46530
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment hacklog-remote-attachment allows Stored XSS.This issue affects Hacklog Remote Attachment: from n/a through <= 1.3.2.

Apr 24, 2025
CVE-2025-46529
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StressFree Sites Business Contact Widget business-contact-widget allows Stored XSS.This issue affects Business Contact …

Apr 24, 2025
CVE-2025-46528
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calendar: from n/a through <= 0.2.4.

Apr 24, 2025
CVE-2025-46525
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in msmitley WP Cookie Consent wp-cookie-consent allows Stored XSS.This issue affects WP Cookie Consent: …

Apr 24, 2025
CVE-2025-46524
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in stesvis WP Filter Post Category wp-filter-post-categories allows Stored XSS.This issue affects WP Filter Post Category: from n/a through <= …

Apr 24, 2025
CVE-2025-46523
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 …

Apr 24, 2025
CVE-2025-46522
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Billy Bryant Tabs gt-tabs allows Stored XSS.This issue affects Tabs: from n/a through <= 4.0.3.

Apr 24, 2025
CVE-2025-46521
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Silver Muru WS Force Login Page ws-force-login-page allows Stored XSS.This issue affects WS …

Apr 24, 2025
CVE-2025-46520
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in alphasis Related Posts via Taxonomies related-posts-via-taxonomies allows Stored XSS.This issue affects Related Posts via Taxonomies: from n/a through <= …

Apr 24, 2025
CVE-2025-46519
4.3 MEDIUM

Missing Authorization vulnerability in M.Code Media Library Downloader media-library-downloader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Library Downloader: from n/a through …

Apr 24, 2025
CVE-2025-46517
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Blog Manager WP blog-manager-wp allows Stored XSS.This issue affects Blog Manager WP: …

Apr 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.