CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22241
5.6 MEDIUM

File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. …

Jun 13, 2025
CVE-2025-22240
6.3 MEDIUM

Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the …

Jun 13, 2025
CVE-2025-22238
4.2 MEDIUM

Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write …

Jun 13, 2025
CVE-2025-22237
6.7 MEDIUM

An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and …

Jun 13, 2025
CVE-2024-38825
6.4 MEDIUM

The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. …

Jun 13, 2025
CVE-2025-5815
5.3 MEDIUM

The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all …

Jun 13, 2025
CVE-2025-5950
6.4 MEDIUM

The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versions up to, and including, 0.13.2 due to …

Jun 13, 2025
CVE-2025-5939
4.4 MEDIUM

The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.1 due …

Jun 13, 2025
CVE-2025-5938
5.3 MEDIUM

The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 13, 2025
CVE-2025-5930
4.3 MEDIUM

The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or …

Jun 13, 2025
CVE-2025-5928
4.3 MEDIUM

The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due …

Jun 13, 2025
CVE-2025-5926
6.1 MEDIUM

The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.4. This is due to missing …

Jun 13, 2025
CVE-2025-5841
6.4 MEDIUM

The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.9 …

Jun 13, 2025
CVE-2025-5233
6.4 MEDIUM

The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versions up to, and including, 4.3.2 due …

Jun 13, 2025
CVE-2025-5123
6.4 MEDIUM

The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, …

Jun 13, 2025
CVE-2025-4586
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-4585
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-4584
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-41234
6.5 MEDIUM

Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when …

Jun 12, 2025
CVE-2025-41233
6.8 MEDIUM

Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate …

Jun 12, 2025
CVE-2025-44091
5.4 MEDIUM

yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function.

Jun 12, 2025
CVE-2025-4418
4.4 MEDIUM

An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a …

Jun 12, 2025
CVE-2025-4417
5.5 MEDIUM

A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local …

Jun 12, 2025
CVE-2025-36539
6.5 MEDIUM

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI …

Jun 12, 2025
CVE-2025-2745
6.5 MEDIUM

A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges …

Jun 12, 2025
CVE-2025-49579
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted …

Jun 12, 2025
CVE-2025-49578
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing …

Jun 12, 2025
CVE-2025-49577
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can …

Jun 12, 2025
CVE-2025-49576
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing …

Jun 12, 2025
CVE-2025-49575
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing …

Jun 12, 2025
CVE-2025-49081
4.9 MEDIUM

There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions …

Jun 12, 2025
CVE-2023-45256
5.4 MEDIUM

Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, …

Jun 12, 2025
CVE-2025-29744
5.4 MEDIUM

pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.

Jun 12, 2025
CVE-2024-44906
6.5 MEDIUM

uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is …

Jun 12, 2025
CVE-2024-44905
6.5 MEDIUM

go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.

Jun 12, 2025
CVE-2025-49200
6.5 MEDIUM

The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.

Jun 12, 2025
CVE-2025-49197
6.5 MEDIUM

The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.

Jun 12, 2025
CVE-2025-49196
6.5 MEDIUM

A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways …

Jun 12, 2025
CVE-2025-49195
5.3 MEDIUM

The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.

Jun 12, 2025
CVE-2025-49193
4.2 MEDIUM

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application …

Jun 12, 2025
CVE-2025-49192
4.3 MEDIUM

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking …

Jun 12, 2025
CVE-2025-49191
4.8 MEDIUM

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible …

Jun 12, 2025
CVE-2025-49190
4.3 MEDIUM

The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.

Jun 12, 2025
CVE-2025-49189
5.3 MEDIUM

The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag …

Jun 12, 2025
CVE-2025-49188
5.3 MEDIUM

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

Jun 12, 2025
CVE-2025-49187
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Jun 12, 2025
CVE-2025-49186
5.3 MEDIUM

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

Jun 12, 2025
CVE-2025-49185
5.5 MEDIUM

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function …

Jun 12, 2025
CVE-2024-9512
5.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may …

Jun 12, 2025
CVE-2025-5195
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible …

Jun 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.