CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46242
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This issue affects Watu Quiz: …

Apr 22, 2025
CVE-2025-46241
8.2 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

Apr 22, 2025
CVE-2025-46240
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored XSS.This issue affects Simple Download …

Apr 22, 2025
CVE-2025-46239
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This issue affects Theme Switcha: from …

Apr 22, 2025
CVE-2025-46238
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer List Last Changes list-last-changes allows Stored XSS.This issue affects List Last Changes: …

Apr 22, 2025
CVE-2025-46237
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affects Link Library: from …

Apr 22, 2025
CVE-2025-46236
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Stored XSS.This issue affects HTML Forms: …

Apr 22, 2025
CVE-2025-46235
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a …

Apr 22, 2025
CVE-2025-46233
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv: …

Apr 22, 2025
CVE-2025-46232
4.3 MEDIUM

Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from …

Apr 22, 2025
CVE-2025-46231
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Cross Site Request Forgery.This issue affects affiliate-toolkit: from n/a through <= 3.7.3.

Apr 22, 2025
CVE-2025-46229
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= …

Apr 22, 2025
CVE-2025-46228
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows DOM-Based XSS.This issue affects Event post: from …

Apr 22, 2025
CVE-2025-46227
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts custom-related-posts allows Stored XSS.This issue affects Custom Related Posts: …

Apr 22, 2025
CVE-2025-46226
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher mpl-publisher allows Stored XSS.This issue affects MPL-Publisher: from n/a through <= …

Apr 22, 2025
CVE-2025-46225
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post …

Apr 22, 2025
CVE-2025-3519

An authorization bypass in Unblu Spark allows a participant of a conversation to replace an existing, uploaded file. Every uploaded file in Unblu gets assigned …

Apr 22, 2025
CVE-2025-3518
4.3 MEDIUM

It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can …

Apr 22, 2025
CVE-2025-26413
7.5 HIGH

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an …

Apr 22, 2025
CVE-2025-3814
6.4 MEDIUM

The Tax Switch for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class-name’ parameter in all versions up to, and including, …

Apr 22, 2025
CVE-2025-2839
6.4 MEDIUM

The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, …

Apr 22, 2025
CVE-2025-2594
8.1 HIGH

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing …

Apr 22, 2025
CVE-2024-13569
7.1 HIGH

The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Apr 22, 2025
CVE-2025-3616
8.8 HIGH

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Apr 22, 2025
CVE-2025-2300
5.5 MEDIUM

Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 …

Apr 22, 2025
CVE-2024-46899
7.1 HIGH

Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: …

Apr 22, 2025
CVE-2025-3577
4.9 MEDIUM

**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with …

Apr 22, 2025
CVE-2025-1732
6.7 MEDIUM

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an …

Apr 22, 2025
CVE-2025-1731
7.8 HIGH

An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow …

Apr 22, 2025
CVE-2025-3856
6.3 MEDIUM

A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/searchByPage. The manipulation …

Apr 22, 2025
CVE-2025-3855
4.3 MEDIUM

A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the …

Apr 22, 2025
CVE-2025-3854
8.0 HIGH

A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6Params/EditWlanMacList/Edit_List_SSID of the file /goform/aspForm of …

Apr 22, 2025
CVE-2025-3850
3.7 LOW

A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The …

Apr 22, 2025
CVE-2024-58250
9.3 CRITICAL

The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.

Apr 22, 2025
CVE-2025-3849
4.3 MEDIUM

A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument …

Apr 22, 2025
CVE-2025-2987
3.8 LOW

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, …

Apr 22, 2025
CVE-2025-3847
7.3 HIGH

A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httprequest.cpp of the …

Apr 21, 2025
CVE-2025-3846
7.3 HIGH

A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Apr 21, 2025
CVE-2025-3845
7.3 HIGH

A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulnerability is the function Buffer::HasWritten of …

Apr 21, 2025
CVE-2025-3843
4.3 MEDIUM

A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request …

Apr 21, 2025
CVE-2025-3842
6.3 MEDIUM

A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUserPic.action of the file src/com/phn/action/FileUpload.java. The manipulation of …

Apr 21, 2025
CVE-2025-32958
9.8 CRITICAL

Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to upload the mac-standalone artifact. This artifact …

Apr 21, 2025
CVE-2025-32956
8.0 HIGH

ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a namespace in Special:ManageWiki/namespaces …

Apr 21, 2025
CVE-2025-32955
6.0 MEDIUM

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `disable-sudo` …

Apr 21, 2025
CVE-2025-3841
3.3 LOW

A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of …

Apr 21, 2025
CVE-2025-28104
9.1 CRITICAL

Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.

Apr 21, 2025
CVE-2025-28103
6.4 MEDIUM

Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.

Apr 21, 2025
CVE-2025-27086
8.1 HIGH

A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.

Apr 21, 2025
CVE-2024-57394
8.8 HIGH

The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. …

Apr 21, 2025
CVE-2025-29446
3.3 LOW

open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.

Apr 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.