CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3295
4.9 MEDIUM

The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for …

Apr 17, 2025
CVE-2025-3294
7.2 HIGH

The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, …

Apr 17, 2025
CVE-2025-1525
3.5 LOW

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 17, 2025
CVE-2025-1524
3.5 LOW

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 17, 2025
CVE-2025-1523
3.5 LOW

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 17, 2025
CVE-2024-13925
7.5 HIGH

The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with …

Apr 17, 2025
CVE-2024-11924
3.5 LOW

The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high …

Apr 17, 2025
CVE-2025-43717
5.4 MEDIUM

In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.

Apr 17, 2025
CVE-2025-43715
8.1 HIGH

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory …

Apr 17, 2025
CVE-2025-31340

A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through …

Apr 17, 2025
CVE-2025-31339

An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro versions 5.0 through 5.2 allows remote authenticated …

Apr 17, 2025
CVE-2025-31338

A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user …

Apr 17, 2025
CVE-2025-43708
3.3 LOW

VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an …

Apr 17, 2025
CVE-2025-1290
8.1 HIGH

A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during …

Apr 17, 2025
CVE-2025-43704
4.7 MEDIUM

Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.

Apr 16, 2025
CVE-2025-2400

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 16, 2025
CVE-2025-2073
8.8 HIGH

Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, …

Apr 16, 2025
CVE-2025-24911
4.9 MEDIUM

Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define …

Apr 16, 2025
CVE-2025-24910
4.9 MEDIUM

Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define …

Apr 16, 2025
CVE-2025-24909
4.4 MEDIUM

Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that …

Apr 16, 2025
CVE-2025-24908
6.8 MEDIUM

Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled …

Apr 16, 2025
CVE-2025-24907
6.8 MEDIUM

Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled …

Apr 16, 2025
CVE-2025-1704
6.5 MEDIUM

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via …

Apr 16, 2025
CVE-2025-1568
8.8 HIGH

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into …

Apr 16, 2025
CVE-2025-1566
7.5 HIGH

DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to …

Apr 16, 2025
CVE-2025-0758
6.1 MEDIUM

Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) …

Apr 16, 2025
CVE-2025-0757
4.4 MEDIUM

Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that …

Apr 16, 2025
CVE-2025-0756
9.1 CRITICAL

Overview The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an …

Apr 16, 2025
CVE-2025-43703
6.1 MEDIUM

An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the …

Apr 16, 2025
CVE-2025-32791
4.3 MEDIUM

The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some …

Apr 16, 2025
CVE-2025-32789
3.1 LOW

EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by their password hash. This flaw allows an …

Apr 16, 2025
CVE-2025-32787
3.1 LOW

SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerable to NULL dereference in `DeleteIPv6DefaultRouterInRA` called by `StorePacket`. Before dereferencing, …

Apr 16, 2025
CVE-2025-32783
4.7 MEDIUM

XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured …

Apr 16, 2025
CVE-2025-32433
10.0 CRITICAL KEV

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker …

Apr 16, 2025
CVE-2025-31478
8.2 HIGH

Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign …

Apr 16, 2025
CVE-2025-25230
7.8 HIGH

Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able …

Apr 16, 2025
CVE-2025-3730
3.3 LOW

A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to …

Apr 16, 2025
CVE-2025-3729
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of …

Apr 16, 2025
CVE-2025-3728
5.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability affects the function Login. The manipulation of the argument …

Apr 16, 2025
CVE-2025-3727
7.3 HIGH

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component STATUS Command Handler. The …

Apr 16, 2025
CVE-2025-3620
8.8 HIGH

Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Apr 16, 2025
CVE-2025-3619
8.8 HIGH

Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Apr 16, 2025
CVE-2025-29710
6.1 MEDIUM

SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.

Apr 16, 2025
CVE-2025-29709
9.8 CRITICAL

SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.

Apr 16, 2025
CVE-2025-29708
9.8 CRITICAL

SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.

Apr 16, 2025
CVE-2025-28072
7.5 HIGH

PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.

Apr 16, 2025
CVE-2025-26153
5.4 MEDIUM

A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, …

Apr 16, 2025
CVE-2024-55372
9.8 CRITICAL

Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The …

Apr 16, 2025
CVE-2024-55371
9.8 CRITICAL

Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. …

Apr 16, 2025
CVE-2025-3726
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Apr 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.