CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13719
5.3 MEDIUM

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing …

Feb 19, 2025
CVE-2024-13712
4.9 MEDIUM

The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient …

Feb 19, 2025
CVE-2024-13711
6.1 MEDIUM

The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all versions up to, and including, 1.01.1 due to …

Feb 19, 2025
CVE-2024-13679
6.4 MEDIUM

The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' shortcode in all versions up to, and including, 3.1.5 …

Feb 19, 2025
CVE-2024-13676
6.5 MEDIUM

The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all versions up to, …

Feb 19, 2025
CVE-2024-13674
6.4 MEDIUM

The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cwp_social_share' shortcode in all versions …

Feb 19, 2025
CVE-2024-13663
6.4 MEDIUM

The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.5.1 …

Feb 19, 2025
CVE-2024-13660
6.4 MEDIUM

The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fshow' shortcode in all versions up to, and including, …

Feb 19, 2025
CVE-2024-13657
6.4 MEDIUM

The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including, …

Feb 19, 2025
CVE-2024-13592
7.5 HIGH

The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Feb 19, 2025
CVE-2024-13591
6.4 MEDIUM

The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'team-builder-vc' shortcode in all …

Feb 19, 2025
CVE-2024-13589
6.4 MEDIUM

The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and …

Feb 19, 2025
CVE-2024-13468
7.5 HIGH

The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' …

Feb 19, 2025
CVE-2024-13462
6.4 MEDIUM

The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, …

Feb 19, 2025
CVE-2024-13405
4.3 MEDIUM

The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due …

Feb 19, 2025
CVE-2024-13390
6.4 MEDIUM

The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions …

Feb 19, 2025
CVE-2024-12522
6.4 MEDIUM

The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode …

Feb 19, 2025
CVE-2024-12339
6.1 MEDIUM

The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' parameter in all versions up to, and including, 3.1.1 …

Feb 19, 2025
CVE-2024-12069
6.1 MEDIUM

The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Feb 19, 2025
CVE-2024-11778
6.4 MEDIUM

The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedcdn' shortcode in all versions up to, and …

Feb 19, 2025
CVE-2024-11753
6.4 MEDIUM

The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_button' shortcode in all versions up to, and including, …

Feb 19, 2025
CVE-2024-11335
6.4 MEDIUM

The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframe' …

Feb 19, 2025
CVE-2025-0633

Heap-based Buffer Overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows attacker to read out of bound memory

Feb 19, 2025
CVE-2025-25054
6.1 MEDIUM

Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a …

Feb 19, 2025
CVE-2025-24841
5.4 MEDIUM

Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as …

Feb 19, 2025
CVE-2025-22888
5.4 MEDIUM

Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be …

Feb 19, 2025
CVE-2025-1065
6.4 MEDIUM

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature …

Feb 19, 2025
CVE-2024-13799
6.4 MEDIUM

The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 19, 2025
CVE-2024-12173
3.5 LOW

The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor …

Feb 19, 2025
CVE-2025-1441
6.1 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is …

Feb 19, 2025
CVE-2025-22622
4.3 MEDIUM

Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web application dynamically generates web content without validating …

Feb 19, 2025
CVE-2024-13443
6.4 MEDIUM

The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shortcode in all versions up to, and including, 1.3.8 …

Feb 19, 2025
CVE-2024-11582
7.2 HIGH

The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up …

Feb 19, 2025
CVE-2025-1448
7.3 HIGH

A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This issue affects some unknown processing …

Feb 19, 2025
CVE-2024-57262
7.1 HIGH

In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode …

Feb 19, 2025
CVE-2024-57261
7.1 HIGH

In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-57258.

Feb 19, 2025
CVE-2025-1447
4.3 MEDIUM

A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects unknown code of the file /pigeon/imgproxy/index.php. The manipulation …

Feb 19, 2025
CVE-2024-13508
6.1 MEDIUM

The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due …

Feb 19, 2025
CVE-2025-27113
2.9 LOW

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.

Feb 18, 2025
CVE-2025-26624

Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an …

Feb 18, 2025
CVE-2025-25475
7.5 HIGH

A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM …

Feb 18, 2025
CVE-2025-25474
6.5 MEDIUM

DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.

Feb 18, 2025
CVE-2025-25473
5.3 MEDIUM

FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.

Feb 18, 2025
CVE-2025-25472
5.3 MEDIUM

A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.

Feb 18, 2025
CVE-2025-25471
4.3 MEDIUM

FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.

Feb 18, 2025
CVE-2025-24928
7.8 HIGH

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an …

Feb 18, 2025
CVE-2025-22920
5.3 MEDIUM

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat …

Feb 18, 2025
CVE-2025-22919
6.5 MEDIUM

A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.

Feb 18, 2025
CVE-2024-57259
7.1 HIGH

sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not …

Feb 18, 2025
CVE-2024-57258
7.1 HIGH

Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled …

Feb 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.