CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31730
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Marketer Addons marketer-addons allows Stored XSS.This issue affects Marketer Addons: from n/a …

Apr 1, 2025
CVE-2025-31132
8.1 HIGH

Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fixed in …

Apr 1, 2025
CVE-2025-31131
8.6 HIGH

YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the …

Apr 1, 2025
CVE-2025-31121
5.4 MEDIUM

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is …

Apr 1, 2025
CVE-2025-30676
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are …

Apr 1, 2025
CVE-2025-30354
4.3 MEDIUM

Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to run in Developer Mode, …

Apr 1, 2025
CVE-2025-30224

MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors to read arbitrary files from client systems via …

Apr 1, 2025
CVE-2025-30210
6.1 MEDIUM

Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which internally use react-tooltip were setting the …

Apr 1, 2025
CVE-2025-28398
7.1 HIGH

D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.

Apr 1, 2025
CVE-2025-28395
7.1 HIGH

D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.

Apr 1, 2025
CVE-2025-3035
5.3 MEDIUM

By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak …

Apr 1, 2025
CVE-2025-3034
8.1 HIGH

Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Apr 1, 2025
CVE-2025-3033
7.7 HIGH

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other …

Apr 1, 2025
CVE-2025-3032
7.4 HIGH

Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 …

Apr 1, 2025
CVE-2025-3031
6.5 MEDIUM

An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and …

Apr 1, 2025
CVE-2025-3030
8.1 HIGH

Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and …

Apr 1, 2025
CVE-2025-3029
7.3 HIGH

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was …

Apr 1, 2025
CVE-2025-3028
6.5 MEDIUM

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, …

Apr 1, 2025
CVE-2025-31408
4.3 MEDIUM

Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through <= …

Apr 1, 2025
CVE-2025-22231
7.8 HIGH

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance …

Apr 1, 2025
CVE-2025-1660
7.8 HIGH

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute …

Apr 1, 2025
CVE-2025-1659
7.8 HIGH

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause …

Apr 1, 2025
CVE-2025-1658
7.8 HIGH

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause …

Apr 1, 2025
CVE-2025-3085
8.1 HIGH

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the …

Apr 1, 2025
CVE-2025-3084
6.5 MEDIUM

When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router …

Apr 1, 2025
CVE-2025-3083
7.5 HIGH

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects …

Apr 1, 2025
CVE-2025-30177
6.5 MEDIUM

Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users …

Apr 1, 2025
CVE-2025-2906
6.4 MEDIUM

The Contempo Real Estate Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.6.3 due to …

Apr 1, 2025
CVE-2025-2237
9.8 CRITICAL

The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions up to, and including, 1.6.26. This …

Apr 1, 2025
CVE-2024-13553
9.8 CRITICAL

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, …

Apr 1, 2025
CVE-2025-3082
3.1 LOW

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view …

Apr 1, 2025
CVE-2025-27130
8.8 HIGH

Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote …

Apr 1, 2025
CVE-2024-56325
9.8 CRITICAL

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST …

Apr 1, 2025
CVE-2025-30065
9.8 CRITICAL

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade …

Apr 1, 2025
CVE-2025-2891
8.8 HIGH

The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in …

Apr 1, 2025
CVE-2025-29868
6.5 MEDIUM

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally …

Apr 1, 2025
CVE-2025-27427
4.3 MEDIUM

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by …

Apr 1, 2025
CVE-2025-1512
6.4 MEDIUM

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Cursor Extension in all …

Apr 1, 2025
CVE-2025-1267
5.5 MEDIUM

The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions up to, and including, 3.7.4.1 due to insufficient …

Apr 1, 2025
CVE-2024-12278
7.2 HIGH

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typically sanitizes data using wp_kses, like comments, in …

Apr 1, 2025
CVE-2024-12189
6.4 MEDIUM

The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom …

Apr 1, 2025
CVE-2025-31415
7.6 HIGH

Missing Authorization vulnerability in YayCommerce YayExtra yayextra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayExtra: from n/a through <= 1.5.2.

Apr 1, 2025
CVE-2025-31409
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a …

Apr 1, 2025
CVE-2025-31095
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard allows Authentication Bypass.This issue affects Material Dashboard: from n/a through <= …

Apr 1, 2025
CVE-2025-31087
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows Object Injection.This issue affects Multiple Shipping And Billing Address …

Apr 1, 2025
CVE-2025-31084
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through <= 3.4.10.

Apr 1, 2025
CVE-2025-31074
8.8 HIGH

Deserialization of Untrusted Data vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Object Injection.This issue affects Mobile DJ Manager: from n/a through <= 1.7.5.2.

Apr 1, 2025
CVE-2025-31024
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows SQL Injection.This issue affects RJ Quickcharts: …

Apr 1, 2025
CVE-2025-31001
7.5 HIGH

Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit gtm-kit allows Retrieve Embedded Sensitive Data.This issue affects GTM Kit: from n/a through <= …

Apr 1, 2025
CVE-2025-30971
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Random Quotes xv-random-quotes allows SQL Injection.This issue affects …

Apr 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.