CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43929
4.1 MEDIUM

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted …

Apr 20, 2025
CVE-2025-43928
5.8 MEDIUM

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username …

Apr 20, 2025
CVE-2025-43921
5.3 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that …

Apr 20, 2025
CVE-2025-43920
5.4 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters …

Apr 20, 2025
CVE-2025-43919
5.8 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private …

Apr 20, 2025
CVE-2025-43918
6.4 MEDIUM

SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain …

Apr 19, 2025
CVE-2023-30421
2.9 LOW

mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 8891110122900e913013935755114.

Apr 19, 2025
CVE-2023-26819
2.9 LOW

cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

Apr 19, 2025
CVE-2025-3820
8.8 HIGH

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysUplinkCheckSet of the file …

Apr 19, 2025
CVE-2022-47112
2.5 LOW

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

Apr 19, 2025
CVE-2022-47111
2.5 LOW

7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.

Apr 19, 2025
CVE-2025-3819
7.3 HIGH

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 19, 2025
CVE-2025-3818
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of …

Apr 19, 2025
CVE-2025-43917
8.2 HIGH

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new …

Apr 19, 2025
CVE-2025-3817
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file …

Apr 19, 2025
CVE-2025-3816
4.7 MEDIUM

A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task …

Apr 19, 2025
CVE-2025-3808
4.3 MEDIUM

A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. …

Apr 19, 2025
CVE-2025-3807
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/UploadController.java of the component …

Apr 19, 2025
CVE-2025-3806
2.4 LOW

A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this issue is some unknown functionality of …

Apr 19, 2025
CVE-2025-3805
5.3 MEDIUM

A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file check_id.py …

Apr 19, 2025
CVE-2025-3804
5.3 MEDIUM

A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 …

Apr 19, 2025
CVE-2025-3803
8.8 HIGH

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleRebootSet of the file …

Apr 19, 2025
CVE-2025-3802
8.8 HIGH

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSet of the file …

Apr 19, 2025
CVE-2025-3801
2.4 LOW

A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System …

Apr 19, 2025
CVE-2025-3800
7.3 HIGH

A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php. The …

Apr 19, 2025
CVE-2025-3799
7.3 HIGH

A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of the …

Apr 19, 2025
CVE-2025-3798
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminController.php of the …

Apr 19, 2025
CVE-2025-3661
6.4 MEDIUM

The SB Chart block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.2.6 …

Apr 19, 2025
CVE-2025-3404
8.8 HIGH

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions …

Apr 19, 2025
CVE-2021-4455
9.8 CRITICAL

The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up …

Apr 19, 2025
CVE-2025-3797
4.7 MEDIUM

A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=delall. The manipulation of the …

Apr 19, 2025
CVE-2025-3809
7.2 HIGH

The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log in all versions up to, and including, …

Apr 19, 2025
CVE-2025-2111
7.5 HIGH

The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due …

Apr 19, 2025
CVE-2024-13926
7.5 HIGH

The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post containing a large number of tags, thereby …

Apr 19, 2025
CVE-2025-3103
7.5 HIGH

The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vulnerable to arbitrary file read …

Apr 19, 2025
CVE-2025-3275
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, …

Apr 19, 2025
CVE-2025-1457
6.4 MEDIUM

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 19, 2025
CVE-2025-1093
9.8 CRITICAL

The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up …

Apr 19, 2025
CVE-2025-43901

Rejected reason: Not used

Apr 19, 2025
CVE-2025-43900

Rejected reason: Not used

Apr 19, 2025
CVE-2025-43899

Rejected reason: Not used

Apr 19, 2025
CVE-2025-43898

Rejected reason: Not used

Apr 19, 2025
CVE-2025-43897

Rejected reason: Not used

Apr 19, 2025
CVE-2025-43896

Rejected reason: Not used

Apr 19, 2025
CVE-2025-43895

Rejected reason: Not used

Apr 19, 2025
CVE-2025-43894

Rejected reason: Not used

Apr 19, 2025
CVE-2025-43893

Rejected reason: Not used

Apr 19, 2025
CVE-2025-3284
4.3 MEDIUM

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Apr 19, 2025
CVE-2025-3278
9.8 CRITICAL

The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4. This is due to the plugin allowing …

Apr 19, 2025
CVE-2025-2010
7.5 HIGH

The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injection via the 'jobwp_upload_resume' parameter in …

Apr 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.