CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13466
6.4 MEDIUM

The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, …

Jan 30, 2025
CVE-2024-13380
6.4 MEDIUM

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, …

Jan 30, 2025
CVE-2025-0747
8.6 HIGH

A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message …

Jan 30, 2025
CVE-2025-0746
6.1 MEDIUM

A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging …

Jan 30, 2025
CVE-2025-0745
7.5 HIGH

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the …

Jan 30, 2025
CVE-2025-0744
7.5 HIGH

an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying …

Jan 30, 2025
CVE-2025-0743
5.3 MEDIUM

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to …

Jan 30, 2025
CVE-2025-0742
5.8 MEDIUM

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others …

Jan 30, 2025
CVE-2022-43916
6.8 MEDIUM

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, …

Jan 30, 2025
CVE-2025-0741
5.8 MEDIUM

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users …

Jan 30, 2025
CVE-2025-0740
8.6 HIGH

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to …

Jan 30, 2025
CVE-2025-0739
8.6 HIGH

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others …

Jan 30, 2025
CVE-2024-13706
6.1 MEDIUM

The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in all versions up to, and including, 1.0.1 …

Jan 30, 2025
CVE-2024-13453
7.3 HIGH

The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Jan 30, 2025
CVE-2024-12524
6.4 MEDIUM

The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-login-button' shortcode in all versions up to, and including, …

Jan 30, 2025
CVE-2024-12409
6.1 MEDIUM

The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due …

Jan 30, 2025
CVE-2025-23007
5.5 MEDIUM

A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.

Jan 30, 2025
CVE-2025-21107
7.8 HIGH

Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker …

Jan 30, 2025
CVE-2025-0861
4.9 MEDIUM

The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 3.0.1 …

Jan 30, 2025
CVE-2025-0860
6.1 MEDIUM

The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in all versions up to, and including, …

Jan 30, 2025
CVE-2025-0834
7.8 HIGH

Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\ProgramData\Wondershare\wsServices\ElevationService.exe’ …

Jan 30, 2025
CVE-2024-13758
6.5 MEDIUM

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is …

Jan 30, 2025
CVE-2024-13732
6.4 MEDIUM

The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, …

Jan 30, 2025
CVE-2024-13694
7.5 HIGH

The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up …

Jan 30, 2025
CVE-2024-13470
6.4 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode …

Jan 30, 2025
CVE-2024-13642
6.4 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hotspot widget in all versions up to, …

Jan 30, 2025
CVE-2024-13457
5.3 MEDIUM

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the …

Jan 30, 2025
CVE-2024-12921
6.4 MEDIUM

The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcode in all versions up to, and including, 2.4.6 due …

Jan 30, 2025
CVE-2024-12709
4.3 MEDIUM

The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Jan 30, 2025
CVE-2024-12708
7.1 HIGH

The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jan 30, 2025
CVE-2024-12638
7.1 HIGH

The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 30, 2025
CVE-2024-12400
7.1 HIGH

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

Jan 30, 2025
CVE-2024-12163
6.5 MEDIUM

The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.

Jan 30, 2025
CVE-2024-10309
5.9 MEDIUM

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which …

Jan 30, 2025
CVE-2025-23374
8.0 HIGH

Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high …

Jan 30, 2025
CVE-2025-0662
4.9 MEDIUM

In some cases, the ktrace facility will log the contents of kernel structures to userspace. In one such case, ktrace dumps a variable-sized sockaddr to …

Jan 30, 2025
CVE-2025-0374
6.5 MEDIUM

When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the …

Jan 30, 2025
CVE-2025-0373
6.0 MEDIUM

On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destination FID buffer by 4 bytes, a stack buffer …

Jan 30, 2025
CVE-2025-0849
6.3 MEDIUM

A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the …

Jan 30, 2025
CVE-2025-0848
6.5 MEDIUM

A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file …

Jan 30, 2025
CVE-2025-0847
7.3 HIGH

A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jan 30, 2025
CVE-2025-0846
7.3 HIGH

A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the …

Jan 30, 2025
CVE-2025-0844
4.3 MEDIUM

A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jan 30, 2025
CVE-2025-21415
9.9 CRITICAL

Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

Jan 29, 2025
CVE-2025-21396
8.2 HIGH

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

Jan 29, 2025
CVE-2025-0843
7.3 HIGH

A vulnerability was found in needyamin Library Card System 1.0. It has been classified as critical. Affected is an unknown function of the file admindashboard.php …

Jan 29, 2025
CVE-2024-57665
9.8 CRITICAL

JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly …

Jan 29, 2025
CVE-2025-0851
9.8 CRITICAL

A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary …

Jan 29, 2025
CVE-2025-0842
7.3 HIGH

A vulnerability was found in needyamin Library Card System 1.0 and classified as critical. This issue affects some unknown processing of the file admin.php of …

Jan 29, 2025
CVE-2024-57513
6.5 MEDIUM

A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.

Jan 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.