CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13407
4.3 MEDIUM

The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to insufficient …

Mar 14, 2025
CVE-2024-13321
7.5 HIGH

The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to, and including, 2.0.0 due to insufficient …

Mar 14, 2025
CVE-2025-2221
7.5 HIGH

The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, 1.7.6 due …

Mar 14, 2025
CVE-2024-13824
9.8 CRITICAL

The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 via deserialization …

Mar 14, 2025
CVE-2025-2289
4.3 MEDIUM

The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoints in …

Mar 14, 2025
CVE-2025-2103
8.8 HIGH

The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check …

Mar 14, 2025
CVE-2025-1764
7.5 HIGH

The LoginPress | wp-login Custom Login Page Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.1. …

Mar 14, 2025
CVE-2025-0952
8.1 HIGH

The Eco Nature - Environment & Ecology WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial …

Mar 14, 2025
CVE-2024-13913
8.8 HIGH

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Mar 14, 2025
CVE-2024-13376
8.8 HIGH

The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on …

Mar 14, 2025
CVE-2025-2166
6.1 MEDIUM

The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use …

Mar 14, 2025
CVE-2025-2056
7.5 HIGH

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and …

Mar 14, 2025
CVE-2025-1528
4.3 MEDIUM

The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_meta_values' function …

Mar 14, 2025
CVE-2025-1285
5.3 MEDIUM

The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and …

Mar 14, 2025
CVE-2025-0955
5.3 MEDIUM

The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'vidorev_import_single_video' AJAX action in all versions …

Mar 14, 2025
CVE-2024-11286
9.8 CRITICAL

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin …

Mar 14, 2025
CVE-2024-11285
9.8 CRITICAL

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due …

Mar 14, 2025
CVE-2024-11284
9.8 CRITICAL

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due …

Mar 14, 2025
CVE-2024-11283
7.5 HIGH

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function …

Mar 14, 2025
CVE-2025-30022
6.8 MEDIUM

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.

Mar 14, 2025
CVE-2025-26163
9.8 CRITICAL

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.

Mar 14, 2025
CVE-2025-24855
7.8 HIGH

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is …

Mar 14, 2025
CVE-2024-55549
7.8 HIGH

xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.

Mar 14, 2025
CVE-2025-1266

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 13, 2025
CVE-2024-55060
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a …

Mar 13, 2025
CVE-2025-2230
7.7 HIGH

A flaw exists in the Windows login flow where an AuthContext token can be exploited for replay attacks and authentication bypass.

Mar 13, 2025
CVE-2025-2229
7.7 HIGH

A token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations.

Mar 13, 2025
CVE-2025-27496
3.3 LOW

Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 …

Mar 13, 2025
CVE-2025-25598
8.8 HIGH

Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable …

Mar 13, 2025
CVE-2025-25363
6.5 MEDIUM

An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator …

Mar 13, 2025
CVE-2025-24053
7.2 HIGH

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

Mar 13, 2025
CVE-2024-30143
4.3 MEDIUM

HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. …

Mar 13, 2025
CVE-2025-2284
7.5 HIGH

A denial-of-service vulnerability exists in the "GetWebLoginCredentials" function in "Sante PACS Server.exe".

Mar 13, 2025
CVE-2025-2265
7.8 HIGH

The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and stored in the USER table in the …

Mar 13, 2025
CVE-2025-2264
7.5 HIGH

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk …

Mar 13, 2025
CVE-2025-2263
9.8 CRITICAL

During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username and password. A fixed 0x80-byte stack-based …

Mar 13, 2025
CVE-2025-2081

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and …

Mar 13, 2025
CVE-2025-2080

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker …

Mar 13, 2025
CVE-2025-2079

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker …

Mar 13, 2025
CVE-2025-29773
5.8 MEDIUM

Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the …

Mar 13, 2025
CVE-2025-29768
4.4 MEDIUM

Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is …

Mar 13, 2025
CVE-2025-28011
6.1 MEDIUM

A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code …

Mar 13, 2025
CVE-2025-27138
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter …

Mar 13, 2025
CVE-2025-27107

Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft users who use Integrated Scripting prior to versions 1.21.1-1.0.17, …

Mar 13, 2025
CVE-2025-27103
6.5 MEDIUM

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users …

Mar 13, 2025
CVE-2025-24974
6.5 MEDIUM

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the …

Mar 13, 2025
CVE-2025-1767
6.5 MEDIUM

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the …

Mar 13, 2025
CVE-2025-1652
7.8 HIGH

A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1651
7.8 HIGH

A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025
CVE-2025-1650
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause …

Mar 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.