CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9458
4.8 MEDIUM

The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 7, 2025
CVE-2024-13857
5.5 MEDIUM

The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Mar 7, 2025
CVE-2024-13805
6.4 MEDIUM

The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File …

Mar 7, 2025
CVE-2024-13668
7.1 HIGH

The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Mar 7, 2025
CVE-2024-13635
4.3 MEDIUM

The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. …

Mar 7, 2025
CVE-2024-13552
4.3 MEDIUM

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Mar 7, 2025
CVE-2025-21843
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_dev_query() 'priorities_info' is uninitialized, and the uninitialized value is copied …

Mar 7, 2025
CVE-2025-21842
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to init user queue The destructor of a gtt …

Mar 7, 2025
CVE-2025-21841
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting amd_pstate_update_limits() takes a cpufreq_policy reference but doesn't decrement the refcount …

Mar 7, 2025
CVE-2025-21840
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/netlink: Prevent userspace segmentation fault by adjusting UAPI header The intel-lpmd tool [1], which uses …

Mar 7, 2025
CVE-2025-21839
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop Move the conditional …

Mar 7, 2025
CVE-2025-21838
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: flush gadget workqueue after device removal device_del() can lead to new work …

Mar 7, 2025
CVE-2025-21837

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 7, 2025
CVE-2025-21836
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it …

Mar 7, 2025
CVE-2025-21835
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, …

Mar 7, 2025
CVE-2025-1315
9.8 CRITICAL

The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due …

Mar 7, 2025
CVE-2025-0959
8.8 HIGH

The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up …

Mar 7, 2025
CVE-2024-9658
8.8 HIGH

The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. …

Mar 7, 2025
CVE-2024-13904
5.3 MEDIUM

The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' …

Mar 7, 2025
CVE-2024-13781
6.5 MEDIUM

The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due …

Mar 7, 2025
CVE-2024-13431
6.1 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter …

Mar 7, 2025
CVE-2024-12876
9.8 CRITICAL

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and …

Mar 7, 2025
CVE-2024-12611
5.3 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and …

Mar 7, 2025
CVE-2024-12610
5.3 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' …

Mar 7, 2025
CVE-2024-12609
6.5 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, …

Mar 7, 2025
CVE-2024-12607
6.5 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all …

Mar 7, 2025
CVE-2024-12036
7.5 HIGH

The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This …

Mar 7, 2025
CVE-2024-12035
8.8 HIGH

The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions …

Mar 7, 2025
CVE-2024-10804
7.5 HIGH

The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via …

Mar 7, 2025
CVE-2025-27816
9.8 CRITICAL

A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of …

Mar 7, 2025
CVE-2025-26331
7.8 HIGH

Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local …

Mar 7, 2025
CVE-2025-1309
8.8 HIGH

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to …

Mar 7, 2025
CVE-2025-0863
6.4 MEDIUM

The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, …

Mar 7, 2025
CVE-2024-13906
7.2 HIGH

The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Mar 7, 2025
CVE-2024-12837
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.

Mar 7, 2025
CVE-2024-12576
5.5 MEDIUM

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU …

Mar 7, 2025
CVE-2025-1475
9.8 CRITICAL

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification …

Mar 7, 2025
CVE-2024-13655
8.1 HIGH

The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of …

Mar 7, 2025
CVE-2024-13320
7.5 HIGH

The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up …

Mar 7, 2025
CVE-2024-12809
6.4 MEDIUM

The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due …

Mar 7, 2025
CVE-2025-27796
4.5 MEDIUM

ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.

Mar 7, 2025
CVE-2025-27795
4.3 MEDIUM

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

Mar 7, 2025
CVE-2025-2067
7.3 HIGH

A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search.php. …

Mar 7, 2025
CVE-2025-2066
7.3 HIGH

A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /updateAgent.php. …

Mar 7, 2025
CVE-2025-2065
7.3 HIGH

A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. …

Mar 7, 2025
CVE-2025-2064
7.3 HIGH

A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0. Affected by this issue is some unknown functionality …

Mar 7, 2025
CVE-2025-2063
7.3 HIGH

A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mar 7, 2025
CVE-2025-2062
7.3 HIGH

A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The …

Mar 7, 2025
CVE-2025-2061
4.3 MEDIUM

A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Mar 7, 2025
CVE-2025-2060
7.3 HIGH

A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as critical. This affects an unknown part of the file …

Mar 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.