CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1538
8.8 HIGH

A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function set_ws_action of the file /dws/api/. The manipulation …

Feb 21, 2025
CVE-2025-1537
6.3 MEDIUM

A vulnerability was found in Harpia DiagSystem 12. It has been rated as critical. This issue affects some unknown processing of the file /diagsystem/PACS/atualatendimento_jpeg.php. The …

Feb 21, 2025
CVE-2025-1536
7.3 HIGH

A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the …

Feb 21, 2025
CVE-2025-0838
9.8 CRITICAL

There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on …

Feb 21, 2025
CVE-2024-10222
6.4 MEDIUM

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due …

Feb 21, 2025
CVE-2020-6158
4.7 MEDIUM

Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser …

Feb 21, 2025
CVE-2025-26794
7.5 HIGH

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in …

Feb 21, 2025
CVE-2025-1535
7.3 HIGH

A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This affects an unknown part of the file …

Feb 21, 2025
CVE-2025-1489
6.4 MEDIUM

The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due …

Feb 21, 2025
CVE-2025-1402
5.3 MEDIUM

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function …

Feb 21, 2025
CVE-2024-9150

Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a …

Feb 21, 2025
CVE-2024-13900
4.1 MEDIUM

The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes …

Feb 21, 2025
CVE-2024-13846
4.9 MEDIUM

The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, …

Feb 21, 2025
CVE-2024-13713
6.5 MEDIUM

The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 …

Feb 21, 2025
CVE-2024-13455
6.4 MEDIUM

The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_calendar' shortcode in all versions up to, and including, …

Feb 21, 2025
CVE-2025-1471
7.8 HIGH

In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input …

Feb 21, 2025
CVE-2025-1470
5.5 MEDIUM

In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check …

Feb 21, 2025
CVE-2024-13648
6.4 MEDIUM

The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortcode in all versions up to, and including, …

Feb 21, 2025
CVE-2024-13461
6.4 MEDIUM

The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up …

Feb 21, 2025
CVE-2024-13353
8.8 HIGH

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions …

Feb 21, 2025
CVE-2024-12452
6.4 MEDIUM

The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode in all versions up to, and including, 3.1 due …

Feb 21, 2025
CVE-2024-12276
5.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via …

Feb 21, 2025
CVE-2025-1410
6.4 MEDIUM

The Events Calendar Made Simple – Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's piecal shortcode in all versions …

Feb 21, 2025
CVE-2025-0728
7.5 HIGH

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of …

Feb 21, 2025
CVE-2025-0727
7.5 HIGH

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of …

Feb 21, 2025
CVE-2025-0726
7.5 HIGH

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. …

Feb 21, 2025
CVE-2024-13585
3.5 LOW

The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Feb 21, 2025
CVE-2024-13314
3.5 LOW

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege …

Feb 21, 2025
CVE-2024-11260
7.5 HIGH

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions …

Feb 21, 2025
CVE-2025-1407
6.4 MEDIUM

The AMO Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's amoteam_skills shortcode in all versions up to, and including, …

Feb 21, 2025
CVE-2025-1406
6.4 MEDIUM

The Newpost Catch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's npc shortcode in all versions up to, and including, 1.3.19 …

Feb 21, 2025
CVE-2024-13883
4.3 MEDIUM

The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. This is due to …

Feb 21, 2025
CVE-2024-13818
5.3 MEDIUM

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information …

Feb 21, 2025
CVE-2024-13751
6.4 MEDIUM

The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all versions up to, and including, 1.3 …

Feb 21, 2025
CVE-2024-13672
6.4 MEDIUM

The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mcg' shortcode in …

Feb 21, 2025
CVE-2024-13537
5.3 MEDIUM

The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin …

Feb 21, 2025
CVE-2024-13388
6.4 MEDIUM

The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' shortcode in all versions up to, and including, 1.0 …

Feb 21, 2025
CVE-2024-13379
6.4 MEDIUM

The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 …

Feb 21, 2025
CVE-2024-13235
6.5 MEDIUM

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up …

Feb 21, 2025
CVE-2024-38657
4.9 MEDIUM

External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker …

Feb 21, 2025
CVE-2025-1001
5.7 MEDIUM

Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to …

Feb 21, 2025
CVE-2025-27100
6.5 MEDIUM

lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting …

Feb 21, 2025
CVE-2025-27088
8.2 HIGH

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, …

Feb 20, 2025
CVE-2025-25957
6.1 MEDIUM

Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.

Feb 20, 2025
CVE-2025-25679
8.0 HIGH

Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.

Feb 20, 2025
CVE-2025-25678
9.8 CRITICAL

Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

Feb 20, 2025
CVE-2025-25676
9.8 CRITICAL

Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.

Feb 20, 2025
CVE-2025-25675
9.8 CRITICAL

Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request …

Feb 20, 2025
CVE-2025-25674
9.8 CRITICAL

Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.

Feb 20, 2025
CVE-2025-25668
9.8 CRITICAL

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.

Feb 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.