CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0107
9.8 CRITICAL

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, …

Jan 11, 2025
CVE-2025-0106
5.3 MEDIUM

A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.

Jan 11, 2025
CVE-2025-0105
9.1 CRITICAL

An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the …

Jan 11, 2025
CVE-2025-0104
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition …

Jan 11, 2025
CVE-2025-0103
8.8 HIGH

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, …

Jan 11, 2025
CVE-2024-42169
7.1 HIGH

HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user should …

Jan 11, 2025
CVE-2024-42168
8.9 HIGH

HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the …

Jan 11, 2025
CVE-2024-12627
7.5 HIGH

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to PHP Object Injection in …

Jan 11, 2025
CVE-2024-12505
6.4 MEDIUM

The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in all versions up to, and including, 5.0.2 due …

Jan 11, 2025
CVE-2024-12472
4.3 MEDIUM

The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to …

Jan 11, 2025
CVE-2024-12404
7.5 HIGH

The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.1.0 …

Jan 11, 2025
CVE-2024-12204
5.4 MEDIUM

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access due to …

Jan 11, 2025
CVE-2024-11327
6.1 MEDIUM

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Jan 11, 2025
CVE-2025-23113
3.4 LOW

An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containing …

Jan 10, 2025
CVE-2025-23112
6.1 MEDIUM

An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name …

Jan 10, 2025
CVE-2025-23111
4.7 MEDIUM

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. …

Jan 10, 2025
CVE-2025-23110
6.1 MEDIUM

An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an upload of a CSV …

Jan 10, 2025
CVE-2024-9188
8.8 HIGH

Specially constructed queries cause cross platform scripting leaking administrator tokens

Jan 10, 2025
CVE-2024-9134
8.3 HIGH

Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to …

Jan 10, 2025
CVE-2024-9133
6.6 MEDIUM

A user with administrator privileges is able to retrieve authentication tokens

Jan 10, 2025
CVE-2024-9132
8.1 HIGH

The administrator is able to configure an insecure captive portal script

Jan 10, 2025
CVE-2024-9131
7.2 HIGH

A user with administrator privileges can perform command injection

Jan 10, 2025
CVE-2024-7142
4.6 MEDIUM

On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. …

Jan 10, 2025
CVE-2024-47520
7.6 HIGH

A user with advanced report application access rights can perform actions for which they are not authorized

Jan 10, 2025
CVE-2024-47519
8.3 HIGH

Backup uploads to ETM subject to man-in-the-middle interception

Jan 10, 2025
CVE-2024-47518
6.4 MEDIUM

Specially constructed queries targeting ETM could discover active remote access sessions

Jan 10, 2025
CVE-2024-47517
6.8 MEDIUM

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

Jan 10, 2025
CVE-2024-7095
4.3 MEDIUM

On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the …

Jan 10, 2025
CVE-2024-5872
6.5 MEDIUM

On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane …

Jan 10, 2025
CVE-2024-54998
5.4 MEDIUM

MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.

Jan 10, 2025
CVE-2024-54997
5.4 MEDIUM

MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.

Jan 10, 2025
CVE-2024-54996
8.8 HIGH

MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create.

Jan 10, 2025
CVE-2024-54994
6.5 MEDIUM

MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.

Jan 10, 2025
CVE-2024-6437
5.8 MEDIUM

On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP …

Jan 10, 2025
CVE-2024-33299
4.7 MEDIUM

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the …

Jan 10, 2025
CVE-2024-33298
6.1 MEDIUM

Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint …

Jan 10, 2025
CVE-2024-33297
4.7 MEDIUM

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add …

Jan 10, 2025
CVE-2024-12847
9.8 CRITICAL

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by …

Jan 10, 2025
CVE-2025-23079
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - ArticleFeedbackv5 extension allows Cross-Site Scripting (XSS).This issue …

Jan 10, 2025
CVE-2024-54910
4.7 MEDIUM

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

Jan 10, 2025
CVE-2025-23078
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue …

Jan 10, 2025
CVE-2024-6880

During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author …

Jan 10, 2025
CVE-2024-6662

Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php?id=7,7,0" lacks protection mechanisms. A …

Jan 10, 2025
CVE-2024-57228
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

Jan 10, 2025
CVE-2024-57227
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

Jan 10, 2025
CVE-2024-57226
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.

Jan 10, 2025
CVE-2024-57225
9.8 CRITICAL

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

Jan 10, 2025
CVE-2024-57224
9.8 CRITICAL

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

Jan 10, 2025
CVE-2024-57223
9.8 CRITICAL

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

Jan 10, 2025
CVE-2024-57222
6.3 MEDIUM

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

Jan 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.