CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-26751
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Alphabetic Pagination alphabetic-pagination allows Reflected XSS.This issue affects Alphabetic Pagination: from …

Feb 25, 2025
CVE-2024-54444
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows Stored XSS.This issue affects Elementor Website Builder: …

Feb 25, 2025
CVE-2024-34036
4.3 MEDIUM

An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the initial connection between a gNB and …

Feb 25, 2025
CVE-2024-34035
5.7 MEDIUM

An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with a …

Feb 25, 2025
CVE-2024-34034
5.7 MEDIUM

An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send …

Feb 25, 2025
CVE-2023-25574
10.0 CRITICAL

`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to …

Feb 25, 2025
CVE-2024-51539
2.3 LOW

The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulnerability due to improper neutralization of special elements …

Feb 25, 2025
CVE-2025-1262
5.3 MEDIUM

The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for …

Feb 25, 2025
CVE-2025-1676
6.3 MEDIUM

A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulnerability is the function pdf2swf of the file …

Feb 25, 2025
CVE-2024-13695
6.4 MEDIUM

The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' parameter. This makes …

Feb 25, 2025
CVE-2024-13693
5.3 MEDIUM

The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, …

Feb 25, 2025
CVE-2025-1675
8.2 HIGH

The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not check if the source buffer is large enough …

Feb 25, 2025
CVE-2025-1674
8.2 HIGH

A lack of input validation allows for out of bounds reads caused by malicious or malformed packets.

Feb 25, 2025
CVE-2024-13494
4.3 MEDIUM

The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to …

Feb 25, 2025
CVE-2025-1673
8.2 HIGH

A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect computation.

Feb 25, 2025
CVE-2025-1648
7.5 HIGH

The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficient …

Feb 25, 2025
CVE-2025-1128
9.8 CRITICAL

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, …

Feb 25, 2025
CVE-2025-1063
5.3 MEDIUM

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Feb 25, 2025
CVE-2025-22210
7.2 HIGH

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management …

Feb 25, 2025
CVE-2024-10545
3.5 LOW

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege …

Feb 25, 2025
CVE-2025-1646
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unknown functionality of the file …

Feb 25, 2025
CVE-2025-27145
3.6 LOW

copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a …

Feb 25, 2025
CVE-2025-1645
6.3 MEDIUM

A vulnerability classified as critical was found in Benner Connecta 1.0.5330. Affected by this vulnerability is an unknown functionality of the file /Usuarios/Usuario/EditarLogado/. The manipulation …

Feb 25, 2025
CVE-2025-1644
4.3 MEDIUM

A vulnerability classified as problematic has been found in Benner ModernaNet up to 1.2.0. Affected is an unknown function of the file /DadosPessoais/SG_Gravar. The manipulation …

Feb 25, 2025
CVE-2025-1643
4.3 MEDIUM

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Feb 25, 2025
CVE-2025-1642
4.3 MEDIUM

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been declared as critical. This vulnerability affects unknown code of the file /AGE0000700/GetImageMedico?fooId=1. …

Feb 25, 2025
CVE-2025-1641
7.3 HIGH

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been classified as critical. This affects an unknown part of the file /AGE0000700/GetHorariosDoDia?idespec=0&idproced=1103&data=2025-02-25+19%3A25&agserv=0&convenio=1&localatend=1&idplano=5&pesfis=01&idprofissional=0&target=.horarios--dia--d0&_=1739371223797. …

Feb 25, 2025
CVE-2025-1640
7.3 HIGH

A vulnerability was found in Benner ModernaNet up to 1.1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Feb 25, 2025
CVE-2025-27144

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON …

Feb 24, 2025
CVE-2025-27143
6.1 MEDIUM

Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper …

Feb 24, 2025
CVE-2025-22974
9.8 CRITICAL

SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.

Feb 24, 2025
CVE-2024-57685
5.3 MEDIUM

An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.

Feb 24, 2025
CVE-2024-56525
9.8 CRITICAL

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create …

Feb 24, 2025
CVE-2024-53544
9.8 CRITICAL

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in …

Feb 24, 2025
CVE-2024-53543
5.4 MEDIUM

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in …

Feb 24, 2025
CVE-2024-53542
6.5 MEDIUM

Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart …

Feb 24, 2025
CVE-2025-27141
6.5 MEDIUM

Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, …

Feb 24, 2025
CVE-2025-27140
9.8 CRITICAL

WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` …

Feb 24, 2025
CVE-2025-25513
9.8 CRITICAL

Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

Feb 24, 2025
CVE-2024-57608
6.5 MEDIUM

An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.

Feb 24, 2025
CVE-2025-27137
4.4 MEDIUM

Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` …

Feb 24, 2025
CVE-2025-26533
8.1 HIGH

An SQL injection risk was identified in the module list filter within course search.

Feb 24, 2025
CVE-2025-26532
3.1 LOW

Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.

Feb 24, 2025
CVE-2025-26531
3.1 LOW

Insufficient capability checks made it possible to disable badges a user does not have permission to access.

Feb 24, 2025
CVE-2025-26530
8.3 HIGH

The question bank filter required additional sanitizing to prevent a reflected XSS risk.

Feb 24, 2025
CVE-2025-26529
8.3 HIGH

Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

Feb 24, 2025
CVE-2025-26528
3.4 LOW

The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

Feb 24, 2025
CVE-2025-26527
5.3 MEDIUM

Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.

Feb 24, 2025
CVE-2025-26526
6.5 MEDIUM

Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

Feb 24, 2025
CVE-2025-26525
8.6 HIGH

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX …

Feb 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.