CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22638
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce allows Stored XSS.This issue affects Product Table …

Mar 27, 2025
CVE-2025-22637
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in verkkovaraani Print PDF Generator and Publisher nopeamedia allows Cross Site Request Forgery.This issue affects Print PDF Generator and Publisher: …

Mar 27, 2025
CVE-2025-22634
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MD Abu Jubayer Hossain Easy Booked – Appointment Booking and Scheduling Management System for WordPress easy-booked allows Cross Site …

Mar 27, 2025
CVE-2025-22629
5.3 MEDIUM

Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iNET Webkit: from n/a through <= 1.2.2.

Mar 27, 2025
CVE-2025-22628
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision Filled In filled-in allows Stored XSS.This issue affects Filled In: from n/a …

Mar 27, 2025
CVE-2025-22497
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bramwaas Simple Google Calendar Outlook Events Block Widget simple-google-icalendar-widget allows Stored XSS.This issue …

Mar 27, 2025
CVE-2025-22496
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MarMar8x Notif Bell notif-bell allows Stored XSS.This issue affects Notif Bell: from n/a …

Mar 27, 2025
CVE-2025-22278
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes Whitish Lite allows Stored XSS.This issue affects Whitish Lite: from n/a through …

Mar 27, 2025
CVE-2025-31181
6.2 MEDIUM

A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-31180
6.2 MEDIUM

A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-31179
6.2 MEDIUM

A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

Mar 27, 2025
CVE-2025-31178
6.2 MEDIUM

A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-31176
6.2 MEDIUM

A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-30358
8.1 HIGH

Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers …

Mar 27, 2025
CVE-2025-30221
4.3 MEDIUM

Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with …

Mar 27, 2025
CVE-2025-30067
7.2 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the …

Mar 27, 2025
CVE-2025-2854
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file update_employee.php. …

Mar 27, 2025
CVE-2025-2516

The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered …

Mar 27, 2025
CVE-2025-29497
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.

Mar 27, 2025
CVE-2025-29496
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29494
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29493
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29492
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.

Mar 27, 2025
CVE-2025-29491
6.5 MEDIUM

An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.

Mar 27, 2025
CVE-2025-29490
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29489
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.

Mar 27, 2025
CVE-2025-29488
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.

Mar 27, 2025
CVE-2025-29487
7.5 HIGH

An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.

Mar 27, 2025
CVE-2025-29486
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.

Mar 27, 2025
CVE-2025-29485
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29484
7.5 HIGH

An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.

Mar 27, 2025
CVE-2025-29483
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.

Mar 27, 2025
CVE-2025-22671
4.3 MEDIUM

Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation disable-elementor-editor-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from …

Mar 27, 2025
CVE-2025-22670
6.5 MEDIUM

Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VikBooking Hotel Booking …

Mar 27, 2025
CVE-2025-22669
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Cross Site Request Forgery.This issue affects Awesome Event Booking: from n/a through <= …

Mar 27, 2025
CVE-2025-22668
6.5 MEDIUM

Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Event Booking: from n/a through …

Mar 27, 2025
CVE-2025-22667
4.3 MEDIUM

Missing Authorization vulnerability in Creative Werk Designs Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets wpsyncsheets-woocommerce.This issue affects Export Order, Product, Customer …

Mar 27, 2025
CVE-2025-22665
4.3 MEDIUM

Missing Authorization vulnerability in Shakeeb Sadikeen RapidLoad unusedcss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RapidLoad: from n/a through <= 2.4.4.

Mar 27, 2025
CVE-2025-22660
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wolfgang Include Mastodon Feed include-mastodon-feed allows DOM-Based XSS.This issue affects Include Mastodon Feed: …

Mar 27, 2025
CVE-2025-22659
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle themeisle-companion allows Stored XSS.This issue affects Orbit Fox …

Mar 27, 2025
CVE-2025-22658
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Listings for Appfolio Listings for Appfolio listings-for-appfolio allows Stored XSS.This issue affects Listings for Appfolio: from n/a through <= …

Mar 27, 2025
CVE-2025-22652
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kendysond Payment Forms for Paystack payment-forms-for-paystack allows SQL Injection.This issue affects …

Mar 27, 2025
CVE-2025-22649
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: …

Mar 27, 2025
CVE-2025-22648
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Blog, Posts and Category Filter for Elementor blog-posts-and-category-for-elementor allows Stored XSS.This …

Mar 27, 2025
CVE-2025-22647
4.3 MEDIUM

Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …

Mar 27, 2025
CVE-2025-22646
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite allows Stored XSS.This issue affects aThemes …

Mar 27, 2025
CVE-2025-22644
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce vayu-blocks allows Stored …

Mar 27, 2025
CVE-2025-21892
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix the recovery flow of the UMR QP This patch addresses an issue in …

Mar 27, 2025
CVE-2025-21891
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipvlan: ensure network headers are in skb linear part syzbot found that ipvlan_process_v6_outbound() was assuming …

Mar 27, 2025
CVE-2025-21890
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: idpf: fix checksums set in idpf_rx_rsc() idpf_rx_rsc() uses skb_transport_offset(skb) while the transport header is not …

Mar 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.