CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3086
7.1 HIGH

Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of …

Apr 4, 2025
CVE-2025-32111
8.7 HIGH

The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.

Apr 4, 2025
CVE-2025-2797
5.4 MEDIUM

The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing …

Apr 4, 2025
CVE-2025-2780
8.8 HIGH

The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the …

Apr 4, 2025
CVE-2025-3214
4.3 MEDIUM

A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability is the function engine.getTemplate of the …

Apr 4, 2025
CVE-2025-3213
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. This vulnerability affects unknown code of the file /view-note.php?noteid=11. The manipulation of …

Apr 4, 2025
CVE-2025-3211
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /birthing_print.php. The …

Apr 4, 2025
CVE-2025-2836
6.4 MEDIUM

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘payment_method’ parameter …

Apr 4, 2025
CVE-2025-2317
7.5 HIGH

The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL Injection via the filtersDataBackend parameter in all versions up to, and including, …

Apr 4, 2025
CVE-2025-2279
5.9 MEDIUM

The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Apr 4, 2025
CVE-2025-2270
8.1 HIGH

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Apr 4, 2025
CVE-2025-2159

Stored XSS in Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows allows authenticated local user to run scripts via UI

Apr 4, 2025
CVE-2024-42208
3.5 LOW

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by …

Apr 4, 2025
CVE-2024-13898
4.4 MEDIUM

The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Apr 4, 2025
CVE-2024-13708
7.2 HIGH

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient …

Apr 4, 2025
CVE-2024-13645
9.8 CRITICAL

The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. This makes …

Apr 4, 2025
CVE-2025-3210
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 4, 2025
CVE-2025-3209
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 4, 2025
CVE-2025-3208
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Apr 4, 2025
CVE-2025-3197
7.3 HIGH

Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into …

Apr 4, 2025
CVE-2025-3194
7.5 HIGH

Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.

Apr 4, 2025
CVE-2025-3192
8.2 HIGH

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user …

Apr 4, 2025
CVE-2025-3191
6.1 MEDIUM

All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in …

Apr 4, 2025
CVE-2025-2075
8.8 HIGH

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and …

Apr 4, 2025
CVE-2024-13744
8.1 HIGH

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions …

Apr 4, 2025
CVE-2025-3207
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /birthing_form.php. …

Apr 4, 2025
CVE-2025-3206
6.3 MEDIUM

A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/doctor-specilization.php. The …

Apr 4, 2025
CVE-2025-3205
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.php. The …

Apr 4, 2025
CVE-2025-3204
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in CodeAstro Car Rental System 1.0. Affected by this issue is some unknown functionality of …

Apr 4, 2025
CVE-2025-3203
4.3 MEDIUM

A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the function formSetAccountList of the file /goform/setModules. The manipulation …

Apr 4, 2025
CVE-2025-3202
7.3 HIGH

A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. The manipulation …

Apr 4, 2025
CVE-2025-3199
7.3 HIGH

A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file …

Apr 4, 2025
CVE-2025-3198
3.3 LOW

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c …

Apr 4, 2025
CVE-2025-3196
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp …

Apr 4, 2025
CVE-2025-3195
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Online Blood Bank Management System 1.0. This issue affects some unknown processing of …

Apr 4, 2025
CVE-2025-26401
6.5 MEDIUM

Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated …

Apr 4, 2025
CVE-2025-25061
5.8 MEDIUM

Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to …

Apr 4, 2025
CVE-2025-24317
5.3 MEDIUM

Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker …

Apr 4, 2025
CVE-2025-24310
4.3 MEDIUM

Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attacker to trick the …

Apr 4, 2025
CVE-2025-3188
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul e-Diary Management System 1.0. This affects an unknown part of the file /add-notes.php. The manipulation …

Apr 4, 2025
CVE-2025-3187
7.3 HIGH

A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Apr 4, 2025
CVE-2025-29815
7.6 HIGH

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Apr 4, 2025
CVE-2025-29796
4.7 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Apr 4, 2025
CVE-2025-25001
4.3 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Apr 4, 2025
CVE-2025-25000
8.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Apr 4, 2025
CVE-2025-3186
7.3 HIGH

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Apr 4, 2025
CVE-2025-3185
7.3 HIGH

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been classified as critical. Affected is an unknown function of the …

Apr 3, 2025
CVE-2025-3184
7.3 HIGH

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file …

Apr 3, 2025
CVE-2025-3183
7.3 HIGH

A vulnerability has been found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Apr 3, 2025
CVE-2025-3182
7.3 HIGH

A vulnerability, which was classified as critical, was found in projectworlds Online Doctor Appointment Booking System 1.0. This affects an unknown part of the file …

Apr 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.