CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2639
4.3 MEDIUM

A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the …

Mar 23, 2025
CVE-2025-2638
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html of the …

Mar 23, 2025
CVE-2025-2637
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the …

Mar 23, 2025
CVE-2025-2628
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /art-enquiry.php. …

Mar 22, 2025
CVE-2025-2627
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. This issue affects some unknown processing of the …

Mar 22, 2025
CVE-2025-2626
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This vulnerability affects unknown code of the file edit_case.php. …

Mar 22, 2025
CVE-2025-2625
6.3 MEDIUM

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /system/cms/content/page. The manipulation of the …

Mar 22, 2025
CVE-2025-2624
6.3 MEDIUM

A vulnerability was found in westboy CicadasCMS 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Mar 22, 2025
CVE-2025-2623
3.5 LOW

A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Mar 22, 2025
CVE-2025-2622
6.3 MEDIUM

A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the …

Mar 22, 2025
CVE-2025-2621
9.8 CRITICAL

A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of …

Mar 22, 2025
CVE-2025-2620
9.8 CRITICAL

A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the …

Mar 22, 2025
CVE-2025-2619
9.8 CRITICAL

A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component …

Mar 22, 2025
CVE-2025-2618
9.8 CRITICAL

A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file …

Mar 22, 2025
CVE-2025-2617
2.4 LOW

A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department …

Mar 22, 2025
CVE-2025-2186
7.5 HIGH

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in …

Mar 22, 2025
CVE-2025-26796
5.4 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all …

Mar 22, 2025
CVE-2025-2577
6.4 MEDIUM

The Bitspecter Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due …

Mar 22, 2025
CVE-2025-2331
5.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 …

Mar 22, 2025
CVE-2025-1973
4.9 MEDIUM

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the …

Mar 22, 2025
CVE-2025-1972
2.7 LOW

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() …

Mar 22, 2025
CVE-2025-1971
7.2 HIGH

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via …

Mar 22, 2025
CVE-2025-1970
7.6 HIGH

The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via …

Mar 22, 2025
CVE-2025-2616
2.4 LOW

A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown function of the component Role Management Page. …

Mar 22, 2025
CVE-2024-13666
5.3 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions …

Mar 22, 2025
CVE-2025-2484
6.1 MEDIUM

The Multi Video Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'video_id' and 'group_id' parameters in all versions up to, and …

Mar 22, 2025
CVE-2025-2482
6.1 MEDIUM

The Gotcha | Gesture-based Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menu' parameter in all versions up to, and including, …

Mar 22, 2025
CVE-2025-2479
6.1 MEDIUM

The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, …

Mar 22, 2025
CVE-2025-2478
4.9 MEDIUM

The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due …

Mar 22, 2025
CVE-2025-2477
4.7 MEDIUM

The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ckemail’ parameter in all versions up to, and including, 2.4 due to …

Mar 22, 2025
CVE-2025-2303
8.8 HIGH

The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, …

Mar 22, 2025
CVE-2025-1311
6.5 MEDIUM

The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in the update_delivery_status() function in all …

Mar 22, 2025
CVE-2025-0807
4.3 MEDIUM

The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Mar 22, 2025
CVE-2024-13856
6.4 MEDIUM

The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, …

Mar 22, 2025
CVE-2024-13768
4.3 MEDIUM

The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Mar 22, 2025
CVE-2025-1408
4.3 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 22, 2025
CVE-2025-0724
8.8 HIGH

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 …

Mar 22, 2025
CVE-2025-0723
6.5 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters …

Mar 22, 2025
CVE-2024-13739
6.1 MEDIUM

The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9.9.7 due to …

Mar 22, 2025
CVE-2024-13737
4.3 MEDIUM

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on …

Mar 22, 2025
CVE-2025-30472
9.0 CRITICAL

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a …

Mar 22, 2025
CVE-2025-2610
7.6 HIGH

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with …

Mar 21, 2025
CVE-2025-2609
8.2 HIGH

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log …

Mar 21, 2025
CVE-2025-26500
4.6 MEDIUM

: Uncontrolled Resource Consumption vulnerability in Wind River Systems VxWorks 7 on VxWorks allows Excessive Allocation. Specifically crafted USB packets may lead to the system …

Mar 21, 2025
CVE-2025-30204
7.5 HIGH

golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via …

Mar 21, 2025
CVE-2025-2608
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown part of the file /admin/view-user-queries.php. The manipulation …

Mar 21, 2025
CVE-2025-2607
6.3 MEDIUM

A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mar 21, 2025
CVE-2025-2606
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 21, 2025
CVE-2025-2604
6.3 MEDIUM

A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 21, 2025
CVE-2025-2603
6.3 MEDIUM

A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the …

Mar 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.