CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0814
5.3 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to …

Feb 13, 2025
CVE-2025-0661
4.3 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due …

Feb 13, 2025
CVE-2025-0327
7.8 HIGH

CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) …

Feb 13, 2025
CVE-2024-47266
2.7 LOW

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, …

Feb 13, 2025
CVE-2024-47265
6.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, …

Feb 13, 2025
CVE-2024-47264
4.9 MEDIUM

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and …

Feb 13, 2025
CVE-2024-13346
7.3 HIGH

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Feb 13, 2025
CVE-2024-13345
7.3 HIGH

The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the …

Feb 13, 2025
CVE-2025-1070
8.1 HIGH

CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downloaded.

Feb 13, 2025
CVE-2025-1060
7.5 HIGH

CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.

Feb 13, 2025
CVE-2025-1059
7.5 HIGH

CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious packets are sent to the webserver of …

Feb 13, 2025
CVE-2025-1058
8.1 HIGH

CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is downloaded.

Feb 13, 2025
CVE-2025-0692
3.5 LOW

The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Feb 13, 2025
CVE-2024-13125
3.5 LOW

The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 13, 2025
CVE-2024-13121
3.5 LOW

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some …

Feb 13, 2025
CVE-2024-13120
4.8 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some …

Feb 13, 2025
CVE-2024-13119
4.8 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some …

Feb 13, 2025
CVE-2024-12586
6.1 MEDIUM

The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 13, 2025
CVE-2024-10083
5.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated …

Feb 13, 2025
CVE-2025-0837
6.4 MEDIUM

The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.6 due to insufficient input sanitization …

Feb 13, 2025
CVE-2024-13770
8.1 HIGH

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions …

Feb 13, 2025
CVE-2024-13229
4.3 MEDIUM

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a …

Feb 13, 2025
CVE-2024-13227
6.4 MEDIUM

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank …

Feb 13, 2025
CVE-2024-10763
9.8 CRITICAL

The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes …

Feb 13, 2025
CVE-2025-1198
4.2 MEDIUM

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that …

Feb 13, 2025
CVE-2025-0896
9.8 CRITICAL

Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by …

Feb 13, 2025
CVE-2024-13644
6.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and …

Feb 13, 2025
CVE-2025-25286
9.8 CRITICAL

Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution …

Feb 13, 2025
CVE-2024-8266
4.4 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger …

Feb 13, 2025
CVE-2024-7102
9.6 CRITICAL

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as …

Feb 13, 2025
CVE-2024-51376
7.5 HIGH

Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via the file/downloadFile.action?path= component.

Feb 12, 2025
CVE-2024-34521
3.5 LOW

A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an administrative user to access system files with the …

Feb 12, 2025
CVE-2024-34520
8.8 HIGH

An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, …

Feb 12, 2025
CVE-2025-20097
4.3 MEDIUM

Uncaught exception in OpenBMC Firmware for the Intel(R) Server M50FCP Family and Intel(R) Server D50DNP Family before version R01.02.0002 may allow an authenticated user to …

Feb 12, 2025
CVE-2025-1229
6.3 MEDIUM

A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected by this vulnerability is an unknown functionality of the file /read/?page=1&logfile=eee&match=. …

Feb 12, 2025
CVE-2025-1228
4.3 MEDIUM

A vulnerability classified as problematic has been found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected is an unknown function of the file /read/?page=1&logfile=LOG_Monitor of the …

Feb 12, 2025
CVE-2024-57605
5.4 MEDIUM

Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components.

Feb 12, 2025
CVE-2024-57604
9.8 CRITICAL

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

Feb 12, 2025
CVE-2024-57603
6.3 MEDIUM

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.

Feb 12, 2025
CVE-2024-57602
9.8 CRITICAL

An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.

Feb 12, 2025
CVE-2024-57601
6.1 MEDIUM

Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.

Feb 12, 2025
CVE-2024-56940
7.5 HIGH

An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads.

Feb 12, 2025
CVE-2024-56939
5.4 MEDIUM

LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.

Feb 12, 2025
CVE-2024-56938
5.4 MEDIUM

LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content class.

Feb 12, 2025
CVE-2024-51440
7.8 HIGH

An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.

Feb 12, 2025
CVE-2024-51123
7.5 HIGH

An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensitive information via the /compose-pdf.xhtml?convid=[id] component.

Feb 12, 2025
CVE-2024-51122
6.1 MEDIUM

Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote attacker to execute arbitrary code via the ST, L, O, OU, …

Feb 12, 2025
CVE-2024-47006
6.7 MEDIUM

Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may allow an authenticated user to …

Feb 12, 2025
CVE-2024-46923
7.5 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service …

Feb 12, 2025
CVE-2024-46922
7.5 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial of Service at …

Feb 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.