CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12213
9.8 CRITICAL

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin …

Feb 12, 2025
CVE-2025-1188
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of …

Feb 12, 2025
CVE-2025-1187
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Police FIR Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Feb 12, 2025
CVE-2024-13814
5.4 MEDIUM

The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 9.1.5. …

Feb 12, 2025
CVE-2024-12315
7.5 HIGH

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Feb 12, 2025
CVE-2025-1186
6.3 MEDIUM

A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects unknown code of the file /Control/Api/Api.php. …

Feb 12, 2025
CVE-2025-1185
6.3 MEDIUM

A vulnerability was found in pihome-shc PiHome 2.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?Ajax=GetModal_Sensor_Graph. The manipulation …

Feb 12, 2025
CVE-2024-13821
5.3 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due …

Feb 12, 2025
CVE-2024-13794
5.3 MEDIUM

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, …

Feb 12, 2025
CVE-2023-49780
6.1 MEDIUM

Cross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on the web browser of the user who accessed …

Feb 12, 2025
CVE-2025-26520
7.6 HIGH

Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix …

Feb 12, 2025
CVE-2025-1184
6.3 MEDIUM

A vulnerability was found in pihome-shc PiHome 1.77 and classified as critical. Affected by this issue is some unknown functionality of the file /ajax.php?Ajax=GetModal_MQTTEdit. The …

Feb 12, 2025
CVE-2025-1183
6.3 MEDIUM

A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 12, 2025
CVE-2024-13714
8.8 HIGH

The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Feb 12, 2025
CVE-2024-13601
4.3 MEDIUM

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Feb 12, 2025
CVE-2024-13600
7.5 HIGH

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Feb 12, 2025
CVE-2024-13374
4.3 MEDIUM

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions …

Feb 12, 2025
CVE-2024-13800
8.1 HIGH

The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability …

Feb 12, 2025
CVE-2024-13769
6.4 MEDIUM

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a …

Feb 12, 2025
CVE-2024-13665
6.4 MEDIUM

The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 …

Feb 12, 2025
CVE-2024-13658
6.4 MEDIUM

The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and …

Feb 12, 2025
CVE-2024-13656
8.1 HIGH

The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial …

Feb 12, 2025
CVE-2024-13654
8.1 HIGH

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of …

Feb 12, 2025
CVE-2024-13653
8.8 HIGH

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Feb 12, 2025
CVE-2024-13421
9.8 CRITICAL

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to …

Feb 12, 2025
CVE-2024-12164
4.3 MEDIUM

The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Feb 12, 2025
CVE-2024-11746
6.4 MEDIUM

The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 12, 2025
CVE-2025-0808
4.3 MEDIUM

The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to …

Feb 12, 2025
CVE-2024-13749
6.1 MEDIUM

The StaffList plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing or …

Feb 12, 2025
CVE-2024-13701
6.4 MEDIUM

The Liveticker (by stklcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'liveticker' shortcode in all versions up to, and including, …

Feb 12, 2025
CVE-2024-13554
5.3 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Feb 12, 2025
CVE-2024-13541
4.3 MEDIUM

The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Feb 12, 2025
CVE-2024-13539
5.3 MEDIUM

The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. This is due the /vendor/aura/payload-interface/phpunit.php …

Feb 12, 2025
CVE-2024-29172
5.9 MEDIUM

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading …

Feb 12, 2025
CVE-2024-29171
5.9 MEDIUM

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this …

Feb 12, 2025
CVE-2025-23359
8.3 HIGH

NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to …

Feb 12, 2025
CVE-2025-1243

The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module …

Feb 12, 2025
CVE-2024-53880
4.9 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability in the model loading API, where a user could cause an integer overflow or wraparound error by loading …

Feb 12, 2025
CVE-2024-0145
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPEG2000 file. A …

Feb 12, 2025
CVE-2024-0144
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a buffer overflow issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2024-0143
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2024-21971
5.5 MEDIUM

Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, resulting in an …

Feb 12, 2025
CVE-2024-0142
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2024-0112
7.5 HIGH

NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper input validation issue by escalating certain …

Feb 12, 2025
CVE-2023-31345
7.5 HIGH

Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.

Feb 12, 2025
CVE-2023-20508
5.0 MEDIUM

Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, …

Feb 12, 2025
CVE-2020-3432
5.6 MEDIUM

A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content …

Feb 12, 2025
CVE-2025-25203
8.1 HIGH

CtrlPanel is open-source billing software for hosting providers. Prior to version 1.0, a Cross-Site Scripting (XSS) vulnerability exists in the `TicketsController` and `Moderation/TicketsController` due to …

Feb 11, 2025
CVE-2024-57000

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-48022. Reason: This candidate is a duplicate of CVE-2023-48022. Notes: All CVE users should reference CVE-2023-48022 …

Feb 11, 2025
CVE-2024-54916
6.8 MEDIUM

An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the …

Feb 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.