CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22693
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows SQL Injection.This …

Feb 3, 2025
CVE-2025-22691
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows SQL Injection.This issue affects WP …

Feb 3, 2025
CVE-2025-22690
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration digitimber-cpanel-integration allows Stored XSS.This issue affects DigiTimber cPanel Integration: from n/a through <= 1.4.6.

Feb 3, 2025
CVE-2025-22688
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ederson Peka Unlimited Page Sidebars unlimited-page-sidebars allows Stored XSS.This issue affects Unlimited Page Sidebars: from n/a through <= 0.2.6.

Feb 3, 2025
CVE-2025-22686
5.3 MEDIUM

Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Google Sheets Connector: from …

Feb 3, 2025
CVE-2025-22685
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in CheGevara29 Tags to Keywords tags-to-meta-keywords allows Stored XSS.This issue affects Tags to Keywords: from n/a through <= 1.0.1.

Feb 3, 2025
CVE-2025-22684
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hakan Ozevin WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Stored XSS.This issue affects WP BASE …

Feb 3, 2025
CVE-2025-22683
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper NotificationX notificationx allows Stored XSS.This issue affects NotificationX: from n/a through <= …

Feb 3, 2025
CVE-2025-22682
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saeed Sattar Beglou Hesabfa Accounting hesabfa-accounting allows Reflected XSS.This issue affects Hesabfa Accounting: …

Feb 3, 2025
CVE-2025-22681
4.3 MEDIUM

Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Cloner: from n/a through <= 1.0.1.

Feb 3, 2025
CVE-2025-22679
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows Reflected XSS.This issue affects Job Board Manager: …

Feb 3, 2025
CVE-2025-22677
4.8 MEDIUM

Missing Authorization vulnerability in UIUX Lab Uix Shortcodes uix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uix Shortcodes: from n/a through <= …

Feb 3, 2025
CVE-2025-22292
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Felipe Peixoto Powerful Auto Chat powers-triggers-of-woo-to-chat allows Stored XSS.This issue affects Powerful Auto …

Feb 3, 2025
CVE-2025-22260
4.3 MEDIUM

Missing Authorization vulnerability in Marcus (aka @msykes) Meta Tag Manager meta-tag-manager.This issue affects Meta Tag Manager: from n/a through <= 3.1.

Feb 3, 2025
CVE-2024-50500
4.3 MEDIUM

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and …

Feb 3, 2025
CVE-2024-43333
7.5 HIGH

Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from …

Feb 3, 2025
CVE-2024-57522
6.4 MEDIUM

SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the …

Feb 3, 2025
CVE-2025-0015
7.8 HIGH

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user …

Feb 3, 2025
CVE-2024-6790
6.1 MEDIUM

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th …

Feb 3, 2025
CVE-2024-10395
8.6 HIGH

No proper validation of the length of user input in http_server_get_content_type_from_extension.

Feb 3, 2025
CVE-2025-25066
8.1 HIGH

nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.

Feb 3, 2025
CVE-2024-13347
6.8 MEDIUM

The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

Feb 3, 2025
CVE-2024-57966
5.0 MEDIUM

libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

Feb 3, 2025
CVE-2025-25063
4.4 MEDIUM

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure …

Feb 3, 2025
CVE-2025-25062
4.4 MEDIUM

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor …

Feb 3, 2025
CVE-2025-20643
3.9 LOW

In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an …

Feb 3, 2025
CVE-2025-20642
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20641
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20640
4.3 MEDIUM

In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an …

Feb 3, 2025
CVE-2025-20639
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20638
4.3 MEDIUM

In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker …

Feb 3, 2025
CVE-2025-20637
7.5 HIGH

In network HW, there is a possible system hang due to an uncaught exception. This could lead to remote denial of service with no additional …

Feb 3, 2025
CVE-2025-20636
6.7 MEDIUM

In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Feb 3, 2025
CVE-2025-20635
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2025-20634
9.8 CRITICAL

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a …

Feb 3, 2025
CVE-2025-20633
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code …

Feb 3, 2025
CVE-2025-20632
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Feb 3, 2025
CVE-2025-20631
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Feb 3, 2025
CVE-2024-20147
5.3 MEDIUM

In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional …

Feb 3, 2025
CVE-2024-20142
6.6 MEDIUM

In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2024-20141
6.6 MEDIUM

In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2025-0974
5.0 MEDIUM

A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can …

Feb 3, 2025
CVE-2025-0973
5.4 MEDIUM

A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The …

Feb 3, 2025
CVE-2025-0972
3.5 LOW

A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part of the component New Ticket Handler. …

Feb 3, 2025
CVE-2025-0971
3.5 LOW

A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Feb 3, 2025
CVE-2025-0970
4.3 MEDIUM

A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 2, 2025
CVE-2025-0967
6.3 MEDIUM

A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/add_chatroom.php. The manipulation …

Feb 2, 2025
CVE-2024-0131
4.4 MEDIUM

NVIDIA GPU kernel driver for Windows and Linux contains a vulnerability where a potential user-mode attacker could read a buffer with an incorrect length. A …

Feb 2, 2025
CVE-2025-0961
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Job Recruitment 1.0. Affected by this issue is some unknown functionality of the …

Feb 1, 2025
CVE-2025-0950
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file staffview.php. The …

Feb 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.