CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1118
4.4 MEDIUM

A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any …

Feb 19, 2025
CVE-2025-0893
7.8 HIGH

Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.

Feb 19, 2025
CVE-2024-53974
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Feb 19, 2025
CVE-2024-45777
6.7 MEDIUM

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a …

Feb 19, 2025
CVE-2020-10095
8.1 HIGH

Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.

Feb 19, 2025
CVE-2025-27089
5.4 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping policies for the `update` …

Feb 19, 2025
CVE-2025-24965

crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into …

Feb 19, 2025
CVE-2025-1426
8.8 HIGH

Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Feb 19, 2025
CVE-2025-1006
8.8 HIGH

Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. …

Feb 19, 2025
CVE-2025-0999
8.8 HIGH

Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 19, 2025
CVE-2024-52541
8.2 HIGH

Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of …

Feb 19, 2025
CVE-2023-47160
8.2 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. …

Feb 19, 2025
CVE-2025-20211
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack …

Feb 19, 2025
CVE-2025-20158
4.4 MEDIUM

A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access …

Feb 19, 2025
CVE-2025-20153
5.8 MEDIUM

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow …

Feb 19, 2025
CVE-2025-1465
4.1 MEDIUM

A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. …

Feb 19, 2025
CVE-2024-45084
8.0 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary …

Feb 19, 2025
CVE-2024-45081
6.5 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks.

Feb 19, 2025
CVE-2024-28780
5.9 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to …

Feb 19, 2025
CVE-2024-28777
8.8 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate …

Feb 19, 2025
CVE-2024-28776
5.4 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Feb 19, 2025
CVE-2024-52902
8.8 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used …

Feb 19, 2025
CVE-2022-46283

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

Feb 19, 2025
CVE-2025-1464
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. This issue affects some unknown processing …

Feb 19, 2025
CVE-2025-0968
5.3 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing …

Feb 19, 2025
CVE-2025-0916
7.2 HIGH

The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Feb 19, 2025
CVE-2024-13534
7.5 HIGH

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions …

Feb 19, 2025
CVE-2024-13533
7.5 HIGH

The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and …

Feb 19, 2025
CVE-2024-13491
7.5 HIGH

The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all …

Feb 19, 2025
CVE-2024-13485
7.5 HIGH

The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions …

Feb 19, 2025
CVE-2024-13483
7.5 HIGH

The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up …

Feb 19, 2025
CVE-2024-13481
7.5 HIGH

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions …

Feb 19, 2025
CVE-2024-13479
7.5 HIGH

The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up …

Feb 19, 2025
CVE-2024-13478
7.5 HIGH

The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up …

Feb 19, 2025
CVE-2025-1075
7.5 HIGH

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache …

Feb 19, 2025
CVE-2024-13489
7.5 HIGH

The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions …

Feb 19, 2025
CVE-2025-1135
7.2 HIGH

A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL …

Feb 19, 2025
CVE-2025-1134
7.2 HIGH

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL …

Feb 19, 2025
CVE-2025-1133
7.2 HIGH

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability …

Feb 19, 2025
CVE-2025-1132
8.8 HIGH

A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an …

Feb 19, 2025
CVE-2025-1024
4.8 MEDIUM

A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the …

Feb 19, 2025
CVE-2025-1007
5.3 MEDIUM

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace …

Feb 19, 2025
CVE-2024-13364
5.3 MEDIUM

The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all …

Feb 19, 2025
CVE-2024-13363
6.1 MEDIUM

The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all versions up to, and including, 3.6.3 due …

Feb 19, 2025
CVE-2024-13339
6.1 MEDIUM

The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.8.0. This is due to …

Feb 19, 2025
CVE-2024-13336
4.3 MEDIUM

The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to …

Feb 19, 2025
CVE-2024-13231
5.3 MEDIUM

The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 19, 2025
CVE-2025-0865
6.5 MEDIUM

The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or …

Feb 19, 2025
CVE-2024-13854
4.3 MEDIUM

The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the …

Feb 19, 2025
CVE-2024-13736
6.1 MEDIUM

The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWidgetName’ parameter in all versions up …

Feb 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.