CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-35685
7.8 HIGH

In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation …

Jan 8, 2025
CVE-2025-20168
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2025-20167
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2025-20166
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2024-56770
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: netem: account for backlog updates from child qdisc In general, 'qlen' of any classful …

Jan 8, 2025
CVE-2024-55459
6.5 MEDIUM

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

Jan 8, 2025
CVE-2024-13187
5.3 MEDIUM

A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 8, 2025
CVE-2025-22137
9.8 CRITICAL

Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) …

Jan 8, 2025
CVE-2025-22136

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These …

Jan 8, 2025
CVE-2025-22130
8.8 HIGH

Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access …

Jan 8, 2025
CVE-2025-20126
4.8 MEDIUM

A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate …

Jan 8, 2025
CVE-2025-20123
4.8 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against …

Jan 8, 2025
CVE-2024-55656
8.8 HIGH

RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis. …

Jan 8, 2025
CVE-2024-55517
8.8 HIGH

An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is …

Jan 8, 2025
CVE-2024-51737
7.0 HIGH

RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a …

Jan 8, 2025
CVE-2024-51480
7.0 HIGH

RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using …

Jan 8, 2025
CVE-2025-21102
7.5 HIGH

Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this …

Jan 8, 2025
CVE-2024-12337
6.1 MEDIUM

The Shipping via Planzer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘processed-ids’ parameter in all versions up to, and …

Jan 8, 2025
CVE-2024-11830
6.4 MEDIUM

The PDF Flipbook, 3D Flipbook—DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to 2.3.52 due to …

Jan 8, 2025
CVE-2024-11423
7.5 HIGH

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, …

Jan 8, 2025
CVE-2024-12854
8.8 HIGH

The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the functionality that automatically extracts …

Jan 8, 2025
CVE-2024-12853
8.8 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in …

Jan 8, 2025
CVE-2024-12712
5.3 MEDIUM

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook …

Jan 8, 2025
CVE-2024-9939
7.5 HIGH

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it …

Jan 8, 2025
CVE-2024-54676
9.8 CRITICAL

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA …

Jan 8, 2025
CVE-2024-45033
8.1 HIGH

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with …

Jan 8, 2025
CVE-2024-13186
7.5 HIGH

The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-13185
7.5 HIGH

The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-12855
4.3 MEDIUM

The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in …

Jan 8, 2025
CVE-2024-12328
6.4 MEDIUM

The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.7 due …

Jan 8, 2025
CVE-2024-11939
7.5 HIGH

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, and …

Jan 8, 2025
CVE-2024-11350
9.8 CRITICAL

The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to …

Jan 8, 2025
CVE-2024-13173
7.5 HIGH

The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-12045
4.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value …

Jan 8, 2025
CVE-2024-11635
9.8 CRITICAL

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie …

Jan 8, 2025
CVE-2025-22215
4.3 MEDIUM

VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate …

Jan 8, 2025
CVE-2024-8002
4.3 MEDIUM

A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File …

Jan 8, 2025
CVE-2024-12852
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all …

Jan 8, 2025
CVE-2024-12851
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 8, 2025
CVE-2024-12584
4.3 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Jan 8, 2025
CVE-2024-11613
9.8 CRITICAL

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, …

Jan 8, 2025
CVE-2024-12585
6.1 MEDIUM

The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 8, 2025
CVE-2024-10585
5.3 MEDIUM

The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the …

Jan 8, 2025
CVE-2024-10151
5.4 MEDIUM

The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 8, 2025
CVE-2024-54731
4.0 MEDIUM

cpdf through 2.8 allows stack consumption via a crafted PDF document.

Jan 8, 2025
CVE-2024-12205
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, …

Jan 8, 2025
CVE-2024-12030
6.5 MEDIUM

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute of the 'mdf_value' shortcode in …

Jan 8, 2025
CVE-2024-11271
8.8 HIGH

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in …

Jan 8, 2025
CVE-2024-11270
8.8 HIGH

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function …

Jan 8, 2025
CVE-2025-21603
4.8 MEDIUM

Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, …

Jan 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.