CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24376
6.5 MEDIUM

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can evaluate only namespaced resources. The …

Jan 30, 2025
CVE-2025-23216
6.8 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages …

Jan 30, 2025
CVE-2025-22222
7.7 HIGH

VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin …

Jan 30, 2025
CVE-2025-22221
5.2 MEDIUM

VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be …

Jan 30, 2025
CVE-2025-22220
4.3 MEDIUM

VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API …

Jan 30, 2025
CVE-2025-22219
6.8 MEDIUM

VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script …

Jan 30, 2025
CVE-2025-0872
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file /addpayment.php. The manipulation …

Jan 30, 2025
CVE-2025-23367
6.5 MEDIUM

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role …

Jan 30, 2025
CVE-2025-22218
8.5 HIGH

VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials …

Jan 30, 2025
CVE-2025-0871
3.5 LOW

A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/admin/index.php?u=article-edit of the component Add Article. …

Jan 30, 2025
CVE-2024-55417
4.3 MEDIUM

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user …

Jan 30, 2025
CVE-2024-55416
3.5 LOW

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can …

Jan 30, 2025
CVE-2024-55415
5.7 MEDIUM

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

Jan 30, 2025
CVE-2024-53615
6.5 MEDIUM

A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via …

Jan 30, 2025
CVE-2024-8494
4.3 MEDIUM

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 via the 'elementor-template' …

Jan 30, 2025
CVE-2024-13742
9.8 CRITICAL

The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via …

Jan 30, 2025
CVE-2024-13720
8.8 HIGH

The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all …

Jan 30, 2025
CVE-2024-13715
4.3 MEDIUM

The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in …

Jan 30, 2025
CVE-2024-13707
8.8 HIGH

The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to …

Jan 30, 2025
CVE-2024-13705
6.1 MEDIUM

The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all …

Jan 30, 2025
CVE-2024-13700
6.4 MEDIUM

The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, …

Jan 30, 2025
CVE-2024-13671
7.5 HIGH

The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.1 via the read_score_file() function. …

Jan 30, 2025
CVE-2024-13670
6.4 MEDIUM

The Music Sheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pn_msv' shortcode in all versions up to, and including, …

Jan 30, 2025
CVE-2024-13664
6.4 MEDIUM

The WP Post List Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpb_post_list_table' shortcode in all versions up to, and …

Jan 30, 2025
CVE-2024-13661
6.4 MEDIUM

The Table Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wptableeditor_vtabs' shortcode in all versions up to, and including, 1.5.1 …

Jan 30, 2025
CVE-2024-13652
4.3 MEDIUM

The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX …

Jan 30, 2025
CVE-2024-13646
8.1 HIGH

The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on …

Jan 30, 2025
CVE-2024-13596
6.5 MEDIUM

The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute …

Jan 30, 2025
CVE-2024-13549
6.4 MEDIUM

The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in all versions up to, and including, 1.3.26 …

Jan 30, 2025
CVE-2024-13512
6.1 MEDIUM

The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing …

Jan 30, 2025
CVE-2024-13460
6.4 MEDIUM

The WE – Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Testimonial Author Names in all versions up to, and including, …

Jan 30, 2025
CVE-2024-13400
6.4 MEDIUM

The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gutenberg" Block, specifically in the "align" attribute, …

Jan 30, 2025
CVE-2024-13349
6.4 MEDIUM

The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockdio-historical-chart' shortcode in all versions up to, and including, …

Jan 30, 2025
CVE-2024-12861
6.5 MEDIUM

The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via …

Jan 30, 2025
CVE-2024-12822
9.8 CRITICAL

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing …

Jan 30, 2025
CVE-2024-12821
8.8 HIGH

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing …

Jan 30, 2025
CVE-2024-12451
6.4 MEDIUM

The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode in all versions up to, and including, 1.07 …

Jan 30, 2025
CVE-2024-12444
6.4 MEDIUM

The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcode in all versions up to, and including, 4.5.0 …

Jan 30, 2025
CVE-2024-12320
6.1 MEDIUM

The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due …

Jan 30, 2025
CVE-2024-12299
6.1 MEDIUM

The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due …

Jan 30, 2025
CVE-2024-12269
7.5 HIGH

The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Jan 30, 2025
CVE-2024-12177
6.1 MEDIUM

The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up …

Jan 30, 2025
CVE-2024-12129
8.8 HIGH

The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check …

Jan 30, 2025
CVE-2024-12102
4.3 MEDIUM

The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 via the 'elementor-template' shortcode due to …

Jan 30, 2025
CVE-2024-11600
7.2 HIGH

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Remote Code Execution in all versions up …

Jan 30, 2025
CVE-2024-11583
4.3 MEDIUM

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a …

Jan 30, 2025
CVE-2024-10847
6.4 MEDIUM

The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 18 due …

Jan 30, 2025
CVE-2024-10591
8.8 HIGH

The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauthorized modification of data …

Jan 30, 2025
CVE-2025-0870
5.6 MEDIUM

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in …

Jan 30, 2025
CVE-2025-0869
4.3 MEDIUM

A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Jan 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.