CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9217
6.1 MEDIUM

The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Mar 1, 2025
CVE-2024-9212
6.1 MEDIUM

The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Mar 1, 2025
CVE-2024-13750
6.5 MEDIUM

The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and …

Mar 1, 2025
CVE-2024-13746
6.5 MEDIUM

The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on the …

Mar 1, 2025
CVE-2024-13568
7.5 HIGH

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Mar 1, 2025
CVE-2024-13559
6.4 MEDIUM

The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wishlist_table' shortcode in all versions up to, and including, 3.2.9 …

Mar 1, 2025
CVE-2024-13518
4.3 MEDIUM

The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.12. This is due to missing …

Mar 1, 2025
CVE-2025-1780
4.3 MEDIUM

The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Mar 1, 2025
CVE-2024-13358
4.3 MEDIUM

The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Mar 1, 2025
CVE-2025-23119
7.5 HIGH

An Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a malicious actor with access to …

Mar 1, 2025
CVE-2025-23118
6.4 MEDIUM

An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the …

Mar 1, 2025
CVE-2025-23117
6.8 MEDIUM

An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to …

Mar 1, 2025
CVE-2025-23116
9.6 CRITICAL

An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Protect Cameras adjacent …

Mar 1, 2025
CVE-2025-23115
9.0 CRITICAL

A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect …

Mar 1, 2025
CVE-2025-27416

Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with scratch username and password form. Any …

Mar 1, 2025
CVE-2025-25723
8.4 HIGH

Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.

Feb 28, 2025
CVE-2025-25478
6.5 MEDIUM

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web …

Feb 28, 2025
CVE-2025-25476
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious …

Feb 28, 2025
CVE-2025-25379
9.6 CRITICAL

Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.

Feb 28, 2025
CVE-2025-26466
5.9 MEDIUM

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer …

Feb 28, 2025
CVE-2024-1509
9.1 CRITICAL

Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured …

Feb 28, 2025
CVE-2025-27414

MinIO is a high performance object storage. Starting in RELEASE.2024-06-06T09-36-42Z and prior to RELEASE.2025-02-28T09-55-16Z, a bug in evaluating the trust of the SSH key used …

Feb 28, 2025
CVE-2025-27413
6.5 MEDIUM

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an administrator to import raw data into the database, …

Feb 28, 2025
CVE-2025-27410
6.5 MEDIUM

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, …

Feb 28, 2025
CVE-2025-0769

PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function …

Feb 28, 2025
CVE-2025-25635
8.0 HIGH

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of …

Feb 28, 2025
CVE-2025-25610
8.0 HIGH

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of …

Feb 28, 2025
CVE-2025-25609
8.0 HIGH

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of …

Feb 28, 2025
CVE-2025-25429
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.

Feb 28, 2025
CVE-2025-25428
8.0 HIGH

TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Feb 28, 2025
CVE-2025-1795

During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator …

Feb 28, 2025
CVE-2025-0160
8.1 HIGH

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 …

Feb 28, 2025
CVE-2025-0159
9.1 CRITICAL

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 …

Feb 28, 2025
CVE-2025-27408
4.8 MEDIUM

Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifest employs a weak password hashing implementation that uses SHA3 without a salt. …

Feb 28, 2025
CVE-2025-25431
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.

Feb 28, 2025
CVE-2025-25430
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.

Feb 28, 2025
CVE-2025-24849
7.1 HIGH

Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.

Feb 28, 2025
CVE-2025-24843
5.1 MEDIUM

Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.

Feb 28, 2025
CVE-2025-24318
6.8 MEDIUM

Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.

Feb 28, 2025
CVE-2025-24316
5.3 MEDIUM

The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality.

Feb 28, 2025
CVE-2025-23405
5.3 MEDIUM

Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).

Feb 28, 2025
CVE-2025-20060
7.5 HIGH

An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

Feb 28, 2025
CVE-2025-20049
5.8 MEDIUM

The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.

Feb 28, 2025
CVE-2025-0985
5.5 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local …

Feb 28, 2025
CVE-2024-54175
5.5 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an …

Feb 28, 2025
CVE-2025-27400
2.9 LOW

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of …

Feb 28, 2025
CVE-2025-26263
5.1 MEDIUM

GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to improper memory handling in …

Feb 28, 2025
CVE-2025-26047
5.1 MEDIUM

Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.

Feb 28, 2025
CVE-2025-25461
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a malicious XSS …

Feb 28, 2025
CVE-2024-44754
6.8 MEDIUM

Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut …

Feb 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.