CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2989
5.3 MEDIUM

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/AdvSetWrl of the …

Mar 31, 2025
CVE-2025-31410
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Church Donation wp-church-donation allows Cross Site Request Forgery.This issue affects WP Church Donation: from n/a through …

Mar 31, 2025
CVE-2025-31406
4.3 MEDIUM

Missing Authorization vulnerability in ELEXtensions ELEX WooCommerce Request a Quote elex-request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WooCommerce Request a …

Mar 31, 2025
CVE-2025-30961
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tinuzz Trackserver trackserver allows DOM-Based XSS.This issue affects Trackserver: from n/a through <= …

Mar 31, 2025
CVE-2025-2985
6.3 MEDIUM

A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affects an unknown part of the file update_account.php. …

Mar 31, 2025
CVE-2025-2984
6.3 MEDIUM

A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Mar 31, 2025
CVE-2025-2072

A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in FAST LTA Silent Brick WebUI, allowing attackers to inject malicious JavaScript code into web pages …

Mar 31, 2025
CVE-2025-2071

A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote attackers to execute arbitrary operating system commands …

Mar 31, 2025
CVE-2025-2983
5.5 MEDIUM

A vulnerability has been found in Legrand SMS PowerView 1.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of …

Mar 31, 2025
CVE-2025-2982
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown function. The manipulation of the argument redirect …

Mar 31, 2025
CVE-2025-3019
7.2 HIGH

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a …

Mar 31, 2025
CVE-2025-2981
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Legrand SMS PowerView 1.x. This issue affects some unknown processing. The manipulation of the …

Mar 31, 2025
CVE-2025-2980
3.5 LOW

A vulnerability classified as problematic was found in Legrand SMS PowerView 1.x. This vulnerability affects unknown code. The manipulation of the argument redirect leads to …

Mar 31, 2025
CVE-2025-2402
8.6 HIGH

A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote …

Mar 31, 2025
CVE-2025-31417
4.3 MEDIUM

Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through < …

Mar 31, 2025
CVE-2025-31414
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder allows Stored XSS.This issue affects Cost Calculator Builder: …

Mar 31, 2025
CVE-2025-31412
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetProductGallery jet-woo-product-gallery allows DOM-Based XSS.This issue affects JetProductGallery: from n/a through <= …

Mar 31, 2025
CVE-2025-31387
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InstaWP InstaWP Connect instawp-connect allows PHP Local File Inclusion.This …

Mar 31, 2025
CVE-2025-31043
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= …

Mar 31, 2025
CVE-2025-31016
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows PHP Local File Inclusion.This issue …

Mar 31, 2025
CVE-2025-30987
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: …

Mar 31, 2025
CVE-2025-30855
7.5 HIGH

Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads by WPQuads: from …

Mar 31, 2025
CVE-2025-30835
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Accounting for WooCommerce accounting-for-woocommerce allows PHP Local …

Mar 31, 2025
CVE-2025-2979
2.4 LOW

A vulnerability classified as problematic has been found in WCMS 11. This affects an unknown part of the file /index.php?anonymous/setregister of the component Registration. The …

Mar 31, 2025
CVE-2025-2978
6.3 MEDIUM

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=container&CKEditorFuncNum=1 …

Mar 31, 2025
CVE-2025-0613
6.1 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated …

Mar 31, 2025
CVE-2025-31103
7.5 HIGH

Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. …

Mar 31, 2025
CVE-2025-2977
3.5 LOW

A vulnerability was found in GFI KerioConnect 10.0.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component …

Mar 31, 2025
CVE-2025-2976
3.5 LOW

A vulnerability was found in GFI KerioConnect 10.0.6. It has been classified as problematic. Affected is an unknown function of the component File Upload. The …

Mar 31, 2025
CVE-2025-26689
9.8 CRITICAL

Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to …

Mar 31, 2025
CVE-2025-25211
9.8 CRITICAL

Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker …

Mar 31, 2025
CVE-2025-24852
4.6 MEDIUM

Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an attacker who can …

Mar 31, 2025
CVE-2025-24517
7.5 HIGH

Use of client-side authentication issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a remote attacker may obtain the …

Mar 31, 2025
CVE-2025-3014

Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or …

Mar 31, 2025
CVE-2025-3013

Insecure Direct Object References (IDOR) in access control in Customer Portal before 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request …

Mar 31, 2025
CVE-2025-3011
9.8 CRITICAL

SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Mar 31, 2025
CVE-2025-2975
3.5 LOW

A vulnerability was found in GFI KerioConnect 10.0.6 and classified as problematic. This issue affects some unknown processing of the file Settings/Email/Signature/EditHtmlSource of the component …

Mar 31, 2025
CVE-2025-2974
3.5 LOW

A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability affects unknown code of the file /contract …

Mar 31, 2025
CVE-2025-2973
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file /Admin/student.php. The …

Mar 31, 2025
CVE-2025-2972

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 31, 2025
CVE-2025-2971

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 31, 2025
CVE-2025-2970

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 31, 2025
CVE-2025-2969

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 31, 2025
CVE-2025-1268
9.4 CRITICAL

Out-of-bounds vulnerability in EMF Recode processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver …

Mar 31, 2025
CVE-2025-2968

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 31, 2025
CVE-2025-2967

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 31, 2025
CVE-2025-2966

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 31, 2025
CVE-2025-2965

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 30, 2025
CVE-2025-2964

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 30, 2025
CVE-2025-2963

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.