CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13422
6.1 MEDIUM

The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions …

Jan 23, 2025
CVE-2024-13389
6.4 MEDIUM

The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email' shortcode in all versions up to, and including, 1.3.4 due …

Jan 23, 2025
CVE-2024-13340
6.4 MEDIUM

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdf_results_by_ajax' shortcode in all versions …

Jan 23, 2025
CVE-2024-13236
6.5 MEDIUM

The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient …

Jan 23, 2025
CVE-2024-12504
6.4 MEDIUM

The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Jan 23, 2025
CVE-2024-12118
6.4 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all …

Jan 23, 2025
CVE-2025-0648
4.9 MEDIUM

Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of …

Jan 23, 2025
CVE-2025-0635
7.5 HIGH

Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions.

Jan 23, 2025
CVE-2025-0619
4.9 MEDIUM

Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords

Jan 23, 2025
CVE-2024-43708
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of …

Jan 23, 2025
CVE-2024-13234
7.5 HIGH

The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in all versions up to, and including, 2.1.2 …

Jan 23, 2025
CVE-2024-12043
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored …

Jan 23, 2025
CVE-2024-13593
7.5 HIGH

The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.0 via the 'bmlt_meeting_map' shortcode. …

Jan 23, 2025
CVE-2024-13511
4.3 MEDIUM

The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its …

Jan 23, 2025
CVE-2024-12957

A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 Security Update for Armoury …

Jan 23, 2025
CVE-2024-53299
6.5 MEDIUM

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server …

Jan 23, 2025
CVE-2024-52975
9.0 CRITICAL

An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature …

Jan 23, 2025
CVE-2024-52972
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot. This can …

Jan 23, 2025
CVE-2025-24530
6.4 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database …

Jan 23, 2025
CVE-2025-24529
6.4 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.

Jan 23, 2025
CVE-2024-43710
4.3 MEDIUM

A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to …

Jan 23, 2025
CVE-2024-43707
7.7 HIGH

An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature …

Jan 23, 2025
CVE-2025-24030
7.1 HIGH

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes …

Jan 23, 2025
CVE-2024-42187
5.3 MEDIUM

BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local repository which is vulnerable …

Jan 23, 2025
CVE-2024-42186
2.8 LOW

BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handling of SSL certificates validation.

Jan 23, 2025
CVE-2024-42185
2.5 LOW

BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability …

Jan 23, 2025
CVE-2024-42184
2.5 LOW

BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using …

Jan 23, 2025
CVE-2023-50309
6.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Jan 23, 2025
CVE-2023-32340
4.6 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Jan 23, 2025
CVE-2024-42183
2.5 LOW

BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without …

Jan 23, 2025
CVE-2024-57724
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.

Jan 23, 2025
CVE-2024-57723
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.

Jan 23, 2025
CVE-2024-57722
7.5 HIGH

lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.

Jan 23, 2025
CVE-2024-57721
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.

Jan 23, 2025
CVE-2024-57720
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.

Jan 23, 2025
CVE-2024-57719
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.

Jan 23, 2025
CVE-2024-42182
2.5 LOW

BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the application to download files from an internally hosted server …

Jan 23, 2025
CVE-2024-12477
6.4 MEDIUM

The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due …

Jan 22, 2025
CVE-2024-56924
7.3 HIGH

A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page …

Jan 22, 2025
CVE-2024-56923
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute …

Jan 22, 2025
CVE-2025-0612
7.5 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Jan 22, 2025
CVE-2025-0611
8.2 HIGH

Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Jan 22, 2025
CVE-2024-56914
5.7 MEDIUM

D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.

Jan 22, 2025
CVE-2024-9310

By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data can be transmitted to aircraft targets. This can lead …

Jan 22, 2025
CVE-2024-11166

For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a ground station and issue a Comm-A Identity …

Jan 22, 2025
CVE-2025-23047
6.5 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure for …

Jan 22, 2025
CVE-2025-0651
7.1 HIGH

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges can create a set of symlinks inside …

Jan 22, 2025
CVE-2024-55957
7.8 HIGH

In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege …

Jan 22, 2025
CVE-2025-24403
4.3 MEDIUM

A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials …

Jan 22, 2025
CVE-2025-24402
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using …

Jan 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.