CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1634
7.5 HIGH

A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times …

Feb 26, 2025
CVE-2025-0941
5.8 MEDIUM

MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain text within the system. This data is not available …

Feb 26, 2025
CVE-2025-25462
5.5 MEDIUM

A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via …

Feb 26, 2025
CVE-2024-53427
8.1 HIGH

decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and …

Feb 26, 2025
CVE-2024-46226
4.8 MEDIUM

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a …

Feb 26, 2025
CVE-2025-25827
6.8 MEDIUM

A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted …

Feb 26, 2025
CVE-2025-25825
7.1 HIGH

A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Feb 26, 2025
CVE-2025-25823
7.3 HIGH

A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Feb 26, 2025
CVE-2025-25818
5.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Feb 26, 2025
CVE-2025-25813
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.

Feb 26, 2025
CVE-2025-25802
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

Feb 26, 2025
CVE-2025-25800
5.3 MEDIUM

SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.

Feb 26, 2025
CVE-2025-25799
6.0 MEDIUM

SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.

Feb 26, 2025
CVE-2025-25797
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.

Feb 26, 2025
CVE-2025-25796
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.

Feb 26, 2025
CVE-2025-25794
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.

Feb 26, 2025
CVE-2025-25793
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.

Feb 26, 2025
CVE-2025-25792
4.4 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.

Feb 26, 2025
CVE-2025-25791
4.4 MEDIUM

An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.

Feb 26, 2025
CVE-2025-25790
9.8 CRITICAL

An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.

Feb 26, 2025
CVE-2025-25789
9.8 CRITICAL

FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

Feb 26, 2025
CVE-2025-25785
9.1 CRITICAL

JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via …

Feb 26, 2025
CVE-2025-25784
9.8 CRITICAL

An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.

Feb 26, 2025
CVE-2025-25783
9.8 CRITICAL

An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.

Feb 26, 2025
CVE-2025-1716
9.8 CRITICAL

picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a …

Feb 26, 2025
CVE-2025-1249
5.3 MEDIUM

Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Events Manager: from n/a through …

Feb 26, 2025
CVE-2024-52925
6.8 MEDIUM

In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unlock Device feature for software encrypted …

Feb 26, 2025
CVE-2022-49732
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sock: redo the psock vs ULP protection check Commit 8a59f9d1e3d4 ("sock: Introduce sk->sk_prot->psock_update_sk_prot()") has moved …

Feb 26, 2025
CVE-2025-26925
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.

Feb 26, 2025
CVE-2025-0719
6.1 MEDIUM

IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript …

Feb 26, 2025
CVE-2025-26698
2.7 LOW

Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using …

Feb 26, 2025
CVE-2025-1517
6.4 MEDIUM

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to …

Feb 26, 2025
CVE-2025-0731
6.5 MEDIUM

An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed …

Feb 26, 2025
CVE-2024-6810
4.4 MEDIUM

The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.1 due to insufficient input sanitization …

Feb 26, 2025
CVE-2024-47053
7.7 HIGH

This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data. * Improper Authorization: …

Feb 26, 2025
CVE-2024-47051
9.1 CRITICAL

This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users. * Remote Code Execution …

Feb 26, 2025
CVE-2024-39441
7.1 HIGH

In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.

Feb 26, 2025
CVE-2024-13803
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in …

Feb 26, 2025
CVE-2024-13678
6.1 MEDIUM

The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13669
6.1 MEDIUM

The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13634
6.1 MEDIUM

The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13633
7.1 HIGH

The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13632
7.1 HIGH

The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 26, 2025
CVE-2024-13631
7.1 HIGH

The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13630
6.1 MEDIUM

The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13629
6.1 MEDIUM

The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13628
6.1 MEDIUM

The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 26, 2025
CVE-2024-13624
7.1 HIGH

The WPMovieLibrary WordPress plugin through 2.1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13571
7.1 HIGH

The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13560
4.3 MEDIUM

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is …

Feb 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.