CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22280
7.6 HIGH

Missing Authorization vulnerability in revmakx DefendWP Firewall defend-wp-firewall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DefendWP Firewall: from n/a through <= 1.1.0.

Feb 27, 2025
CVE-2024-9334
8.2 HIGH

Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass.This issue affects …

Feb 27, 2025
CVE-2025-1739
7.1 HIGH

An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext …

Feb 27, 2025
CVE-2025-1738
6.2 MEDIUM

A Password Transmitted over Query String vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity, exposing this sensitive information to a third party.

Feb 27, 2025
CVE-2025-1693
3.9 LOW

The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into …

Feb 27, 2025
CVE-2025-1692
6.3 MEDIUM

The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text …

Feb 27, 2025
CVE-2025-1691
7.6 HIGH

The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the autocompletion feature …

Feb 27, 2025
CVE-2024-13402
6.4 MEDIUM

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due …

Feb 27, 2025
CVE-2025-1751
9.8 CRITICAL

A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via …

Feb 27, 2025
CVE-2024-13217
4.3 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and …

Feb 27, 2025
CVE-2024-10918
4.8 MEDIUM

Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a …

Feb 27, 2025
CVE-2025-1450
6.4 MEDIUM

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to …

Feb 27, 2025
CVE-2024-13734
6.4 MEDIUM

The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Profile Card widget in all versions up to, …

Feb 27, 2025
CVE-2025-1690
6.4 MEDIUM

The ThemeMakers Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stripe' shortcode in versions up to, and including, 1.0.1 due …

Feb 27, 2025
CVE-2025-1282
8.8 HIGH

The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the …

Feb 27, 2025
CVE-2025-1717
8.1 HIGH

The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. This is due to insecure authentication …

Feb 27, 2025
CVE-2024-5848
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper input validation. User-supplied data is directly included in server responses from …

Feb 27, 2025
CVE-2025-1689
6.4 MEDIUM

The ThemeMakers PayPal Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in versions up to, and including, 1.1.9 …

Feb 27, 2025
CVE-2024-13907
4.9 MEDIUM

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions …

Feb 27, 2025
CVE-2024-0392
5.4 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF token validation. This …

Feb 27, 2025
CVE-2025-1295
8.8 HIGH

The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.7. This is due to …

Feb 27, 2025
CVE-2024-6261
6.4 MEDIUM

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'FinalTilesGallery' shortcode in all versions up …

Feb 27, 2025
CVE-2024-2297
7.1 HIGH

The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks …

Feb 27, 2025
CVE-2025-1686
6.8 MEDIUM

Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A …

Feb 27, 2025
CVE-2025-0469
6.4 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider template …

Feb 27, 2025
CVE-2024-2321
5.6 MEDIUM

An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access …

Feb 27, 2025
CVE-2024-13905
5.3 MEDIUM

The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This …

Feb 27, 2025
CVE-2024-13647
4.3 MEDIUM

The School Management System – SakolaWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is …

Feb 27, 2025
CVE-2025-21797
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Add missing delayed work cancel for headset status The cancel_delayed_work_sync() call was missed, …

Feb 27, 2025
CVE-2025-21796
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfsd: clear acl_access/acl_default after releasing them If getting acl_default fails, acl_access and acl_default will be …

Feb 27, 2025
CVE-2025-21795
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfsd4_shutdown_callback If nfs4_client is in courtesy state then there is no …

Feb 27, 2025
CVE-2025-21794
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix stack-out-of-bounds read in usb_check_int_endpoints() Syzbot[1] has detected a stack-out-of-bounds read of the …

Feb 27, 2025
CVE-2025-21793
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: sn-f-ospi: Fix division by zero When there is no dummy cycle in the spi-nor …

Feb 27, 2025
CVE-2025-21792
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt If an AX25 device is bound …

Feb 27, 2025
CVE-2025-21791
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vrf: use RCU protection in l3mdev_l3_out() l3mdev_l3_out() can be called without RCU being held: raw_sendmsg() …

Feb 27, 2025
CVE-2025-21790
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vxlan: check vxlan_vnigroup_init() return value vxlan_init() must check vxlan_vnigroup_init() success otherwise a crash happens later, …

Feb 27, 2025
CVE-2025-21789
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: …

Feb 27, 2025
CVE-2025-21788
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: fix memleak in certain XDP cases If the XDP program doesn't …

Feb 27, 2025
CVE-2025-21787
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: team: better TEAM_OPTION_TYPE_STRING validation syzbot reported following splat [1] Make sure user-provided data contains one …

Feb 27, 2025
CVE-2025-21786
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: workqueue: Put the pwq after detaching the rescuer from the pool The commit 68f83057b913("workqueue: Reap …

Feb 27, 2025
CVE-2025-21785
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already …

Feb 27, 2025
CVE-2025-21784
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: bail out when failed to load fw in psp_init_cap_microcode() In function psp_init_cap_microcode(), it should …

Feb 27, 2025
CVE-2025-21783
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpiolib: Fix crash on error in gpiochip_get_ngpios() The gpiochip_get_ngpios() uses chip_*() macros to print messages. …

Feb 27, 2025
CVE-2025-21782
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: orangefs: fix a oob in orangefs_debug_write I got a syzbot report: slab-out-of-bounds Read in orangefs_debug_write... …

Feb 27, 2025
CVE-2025-21781
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix panic during interface removal Reference counting is used to ensure that batadv_hardif_neigh_node and …

Feb 27, 2025
CVE-2025-21780
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table() It malicious user provides a small pptable through …

Feb 27, 2025
CVE-2025-21779
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reject Hyper-V's SEND_IPI hypercalls if local APIC isn't in-kernel Advertise support for Hyper-V's …

Feb 27, 2025
CVE-2025-21778
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Do not allow mmap() of persistent ring buffer When trying to mmap a trace …

Feb 27, 2025
CVE-2025-21777
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Validate the persistent meta data subbuf array The meta data for a mapped ring …

Feb 27, 2025
CVE-2025-21776
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: hub: Ignore non-compliant devices with too many configs or interfaces Robert Morris created a …

Feb 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.