CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2224
5.3 MEDIUM

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a …

Mar 25, 2025
CVE-2025-27810
5.4 MEDIUM

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the …

Mar 25, 2025
CVE-2025-27809
5.4 MEDIUM

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client …

Mar 25, 2025
CVE-2025-1798
6.1 MEDIUM

The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting …

Mar 25, 2025
CVE-2025-1452
3.5 LOW

The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Mar 25, 2025
CVE-2025-0845
6.4 MEDIUM

The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient …

Mar 25, 2025
CVE-2025-0717
3.5 LOW

To exploit the vulnerability, it is necessary:

Mar 25, 2025
CVE-2024-9770
4.7 MEDIUM

The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL …

Mar 25, 2025
CVE-2024-44903
7.5 HIGH

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp …

Mar 25, 2025
CVE-2024-13863
7.1 HIGH

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading …

Mar 25, 2025
CVE-2024-13618
7.2 HIGH

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Mar 25, 2025
CVE-2024-13617
8.6 HIGH

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

Mar 25, 2025
CVE-2024-13123
3.5 LOW

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Mar 25, 2025
CVE-2024-13122
3.5 LOW

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Mar 25, 2025
CVE-2024-13118
4.3 MEDIUM

The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Mar 25, 2025
CVE-2024-12769
3.5 LOW

The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 25, 2025
CVE-2024-12682
6.1 MEDIUM

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-12109
4.1 MEDIUM

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, …

Mar 25, 2025
CVE-2024-11503
6.1 MEDIUM

The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 25, 2025
CVE-2024-11273
6.1 MEDIUM

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could …

Mar 25, 2025
CVE-2024-11272
6.1 MEDIUM

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could …

Mar 25, 2025
CVE-2024-10703
6.1 MEDIUM

The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users …

Mar 25, 2025
CVE-2024-10679
6.1 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users …

Mar 25, 2025
CVE-2024-10638
4.1 MEDIUM

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, …

Mar 25, 2025
CVE-2024-10566
6.1 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-10565
6.1 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-10560
3.5 LOW

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such …

Mar 25, 2025
CVE-2024-10554
3.5 LOW

The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 25, 2025
CVE-2024-10472
5.9 MEDIUM

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-10210

An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an authenticated network-based attacker …

Mar 25, 2025
CVE-2024-10105
5.9 MEDIUM

The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor …

Mar 25, 2025
CVE-2025-2736
7.3 HIGH

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

Mar 25, 2025
CVE-2025-2735
7.3 HIGH

A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Mar 25, 2025
CVE-2025-2734
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file …

Mar 25, 2025
CVE-2025-2733
6.3 MEDIUM

A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13. This affects an unknown part of the file app/tool/python_execute.py of the …

Mar 25, 2025
CVE-2024-8315

An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated local attacker to read credential …

Mar 25, 2025
CVE-2024-8314

An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may …

Mar 25, 2025
CVE-2024-8313

An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component …

Mar 25, 2025
CVE-2024-45484

An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used in B&R APROL <4.4-00P5 may allow an unauthenticated adjacent …

Mar 25, 2025
CVE-2024-45483

A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical attacker to alter the boot …

Mar 25, 2025
CVE-2024-45482

An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an authenticated local attacker from a …

Mar 25, 2025
CVE-2024-45481

An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may allow an authenticated local attacker to authenticate …

Mar 25, 2025
CVE-2024-45480

An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to …

Mar 25, 2025
CVE-2024-10209

An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read …

Mar 25, 2025
CVE-2024-10208

An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based …

Mar 25, 2025
CVE-2024-10207

A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to force the web …

Mar 25, 2025
CVE-2024-10206

A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web …

Mar 25, 2025
CVE-2025-2732
8.0 HIGH

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated …

Mar 25, 2025
CVE-2025-2731
8.0 HIGH

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared …

Mar 25, 2025
CVE-2025-2730
8.0 HIGH

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified …

Mar 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.