CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30787
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows Stored XSS.This issue affects EZ SQL Reports Shortcode …

Mar 27, 2025
CVE-2025-30786
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama quotes-llama allows DOM-Based XSS.This issue affects Quotes llama: from n/a …

Mar 27, 2025
CVE-2025-30785
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite subscribe-to-download-lite allows PHP …

Mar 27, 2025
CVE-2025-30784
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Shuffle WP Subscription Forms wp-subscription-forms allows SQL Injection.This issue affects …

Mar 27, 2025
CVE-2025-30783
8.2 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows SQL Injection.This issue affects WP Google Review Slider: from n/a through <= …

Mar 27, 2025
CVE-2025-30781
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & …

Mar 27, 2025
CVE-2025-30780
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cubecolour Audio Album audio-album allows Stored XSS.This issue affects Audio Album: from n/a …

Mar 27, 2025
CVE-2025-30779
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick van Wobbie Doneren met Mollie doneren-met-mollie allows Stored XSS.This issue affects Doneren …

Mar 27, 2025
CVE-2025-30777
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a …

Mar 27, 2025
CVE-2025-30776
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit sitekit allows Stored XSS.This issue affects Sitekit: from n/a through <= …

Mar 27, 2025
CVE-2025-30775
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows SQL Injection.This issue affects WPGuppy: …

Mar 27, 2025
CVE-2025-30773
7.2 HIGH

Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.9.6.

Mar 27, 2025
CVE-2025-30772
8.8 HIGH

Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issue affects WPC Smart Upsell Funnel for WooCommerce: from n/a …

Mar 27, 2025
CVE-2025-30771
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alain-Aymerick FRANCOIS WP Cassify wp-cassify allows DOM-Based XSS.This issue affects WP Cassify: from …

Mar 27, 2025
CVE-2025-30770
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable charitable allows DOM-Based XSS.This issue affects Charitable: from n/a through …

Mar 27, 2025
CVE-2025-30769
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in alexvtn WIP WooCarousel Lite wip-woocarousel-lite allows Stored XSS.This issue affects WIP WooCarousel Lite: from n/a through <= 1.1.7.

Mar 27, 2025
CVE-2025-30768
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mlaza jAlbum Bridge jalbum-bridge allows Stored XSS.This issue affects jAlbum Bridge: from n/a …

Mar 27, 2025
CVE-2025-30767
5.4 MEDIUM

Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for WPForms: from n/a through …

Mar 27, 2025
CVE-2025-30766
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows DOM-Based XSS.This issue affects Happy Addons …

Mar 27, 2025
CVE-2025-30765
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPPOOL FlexStock stock-sync-with-google-sheet-for-woocommerce allows Blind SQL Injection.This issue affects FlexStock: from …

Mar 27, 2025
CVE-2025-30764
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool football-pool allows Cross Site Request Forgery.This issue affects Football Pool: from n/a through <= 2.12.2.

Mar 27, 2025
CVE-2025-30763
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP fw-integration-for-emailoctopus allows Stored XSS.This issue affects EO4WP: from n/a through …

Mar 27, 2025
CVE-2025-29993
5.3 MEDIUM

The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affected product to send email with a tampered …

Mar 27, 2025
CVE-2024-45361
6.5 MEDIUM

A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be …

Mar 27, 2025
CVE-2024-45356
7.3 HIGH

A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access …

Mar 27, 2025
CVE-2024-45355
5.5 MEDIUM

A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access …

Mar 27, 2025
CVE-2024-45354
4.3 MEDIUM

A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to …

Mar 27, 2025
CVE-2024-45353
4.3 MEDIUM

An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is caused by improper input validation and can be exploited …

Mar 27, 2025
CVE-2025-2685
6.4 MEDIUM

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘table-name’ parameter in all versions up …

Mar 27, 2025
CVE-2025-2332
9.8 CRITICAL

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Mar 27, 2025
CVE-2025-0273
5.5 MEDIUM

HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.

Mar 27, 2025
CVE-2025-31165

Cross-Site Scripting (XSS) vulnerability in the Logbug module of NightWolf Penetration Testing Platform 1.2.2 allows attackers to execute JavaScript through the markdown editor feature.

Mar 27, 2025
CVE-2025-31113

Rejected reason: Not used

Mar 27, 2025
CVE-2025-31112

Rejected reason: Not used

Mar 27, 2025
CVE-2025-31111

Rejected reason: Not used

Mar 27, 2025
CVE-2025-31110

Rejected reason: Not used

Mar 27, 2025
CVE-2025-31109

Rejected reason: Not used

Mar 27, 2025
CVE-2025-31108

Rejected reason: Not used

Mar 27, 2025
CVE-2025-31107

Rejected reason: Not used

Mar 27, 2025
CVE-2025-31106

Rejected reason: Not used

Mar 27, 2025
CVE-2025-31105

Rejected reason: Not used

Mar 27, 2025
CVE-2025-2835
4.3 MEDIUM

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of …

Mar 27, 2025
CVE-2025-2833
5.3 MEDIUM

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP …

Mar 27, 2025
CVE-2025-2832
4.3 MEDIUM

A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as problematic. This issue affects some unknown processing. The manipulation leads …

Mar 27, 2025
CVE-2025-2831
6.3 MEDIUM

A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. This vulnerability affects the function getBookList of the …

Mar 27, 2025
CVE-2025-2481
6.1 MEDIUM

The MediaView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id' parameter in all versions up to, and including, 1.1.2 due to …

Mar 27, 2025
CVE-2024-45352
8.8 HIGH

An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers …

Mar 27, 2025
CVE-2025-30355
7.1 HIGH

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating …

Mar 27, 2025
CVE-2025-2496

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 26, 2025
CVE-2025-20230
4.3 MEDIUM

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud …

Mar 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.