CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7296
2.7 LOW

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which …

Mar 13, 2025
CVE-2024-13891
7.1 HIGH

The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 13, 2025
CVE-2024-13885
7.1 HIGH

The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Mar 13, 2025
CVE-2024-13884
7.1 HIGH

The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 13, 2025
CVE-2024-13054
6.5 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of …

Mar 13, 2025
CVE-2024-12380
4.4 MEDIUM

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting …

Mar 13, 2025
CVE-2020-36843
4.3 MEDIUM

The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message …

Mar 13, 2025
CVE-2025-2104
4.3 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the …

Mar 13, 2025
CVE-2025-1561
7.2 HIGH

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in all versions up to, and …

Mar 13, 2025
CVE-2025-1503
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Roundup Recipe Name field in all versions up to, and …

Mar 13, 2025
CVE-2025-2250
4.9 MEDIUM

The WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all …

Mar 13, 2025
CVE-2024-13887
5.3 MEDIUM

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Mar 13, 2025
CVE-2025-2107
7.5 HIGH

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the printResultAndDie() function in all versions up to, and including, …

Mar 13, 2025
CVE-2025-2106
7.5 HIGH

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of the limpia() function in all versions up to, …

Mar 13, 2025
CVE-2025-1559
6.4 MEDIUM

The CC-IMG-Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'img' shortcode in all versions up to, and including, 1.1.0 due …

Mar 13, 2025
CVE-2024-13703
4.3 MEDIUM

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Mar 13, 2025
CVE-2025-25293
7.5 HIGH

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of …

Mar 12, 2025
CVE-2025-25292
9.8 CRITICAL

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and …

Mar 12, 2025
CVE-2025-25291
9.8 CRITICAL

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and …

Mar 12, 2025
CVE-2024-26290

Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System …

Mar 12, 2025
CVE-2025-27407
9.0 CRITICAL

graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a …

Mar 12, 2025
CVE-2025-25975
7.5 HIGH

An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function

Mar 12, 2025
CVE-2025-22870
4.4 MEDIUM

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is …

Mar 12, 2025
CVE-2025-0118
8.0 HIGH

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated …

Mar 12, 2025
CVE-2025-0117

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to …

Mar 12, 2025
CVE-2025-0116

A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame …

Mar 12, 2025
CVE-2025-0115

A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have …

Mar 12, 2025
CVE-2025-0114
7.5 HIGH

A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable …

Mar 12, 2025
CVE-2025-27017
6.5 MEDIUM

Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during …

Mar 12, 2025
CVE-2025-25774
6.5 MEDIUM

An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may …

Mar 12, 2025
CVE-2025-25683
5.6 MEDIUM

AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects AlekSIS-Core 3.0, 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, …

Mar 12, 2025
CVE-2024-34398
4.2 MEDIUM

An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers.

Mar 12, 2025
CVE-2025-2002
6.0 MEDIUM

CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, …

Mar 12, 2025
CVE-2025-27867
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: …

Mar 12, 2025
CVE-2025-26260
8.8 HIGH

Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The …

Mar 12, 2025
CVE-2025-25711
8.8 HIGH

An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/admin/updateUser] API endpoint

Mar 12, 2025
CVE-2025-25568
9.8 CRITICAL

SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is …

Mar 12, 2025
CVE-2025-25567
9.8 CRITICAL

SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: the Supplier disputes this because the behavior only enables a …

Mar 12, 2025
CVE-2025-25566
5.6 MEDIUM

Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function. NOTE: the Supplier disputes this because …

Mar 12, 2025
CVE-2025-25565
9.8 CRITICAL

SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the Supplier disputes this because the …

Mar 12, 2025
CVE-2025-20209
7.5 HIGH

A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent an …

Mar 12, 2025
CVE-2025-20177
6.7 MEDIUM

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR image signature verification …

Mar 12, 2025
CVE-2025-20146
8.6 HIGH

A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance …

Mar 12, 2025
CVE-2025-20145
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to …

Mar 12, 2025
CVE-2025-20144
4.0 MEDIUM

A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to …

Mar 12, 2025
CVE-2025-20143
6.7 MEDIUM

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot …

Mar 12, 2025
CVE-2025-20142
8.6 HIGH

A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR …

Mar 12, 2025
CVE-2025-20141
7.4 HIGH

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release …

Mar 12, 2025
CVE-2025-20138
8.8 HIGH

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying …

Mar 12, 2025
CVE-2025-20115
8.6 HIGH

A vulnerability in confederation implementation for the Border Gateway Protocol (BGP)&nbsp;in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial …

Mar 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.