CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43924
6.1 MEDIUM

Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in FriendsController (for …

Jun 3, 2025
CVE-2025-43923
6.5 MEDIUM

An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via …

Jun 3, 2025
CVE-2024-45655
5.5 MEDIUM

IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.

Jun 3, 2025
CVE-2025-5502
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this issue is the function formMapReboot of the file …

Jun 3, 2025
CVE-2025-5501
5.3 MEDIUM

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_request_transfer of the file src/smf/ngap-handler.c of …

Jun 3, 2025
CVE-2025-5498
5.5 MEDIUM

A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/is_file of the file …

Jun 3, 2025
CVE-2025-45855
5.4 MEDIUM

An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.

Jun 3, 2025
CVE-2025-5497
6.3 MEDIUM

A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_feedimport/inc/processing.inc.php of the component Feedimport …

Jun 3, 2025
CVE-2024-12718
5.3 MEDIUM

Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected …

Jun 3, 2025
CVE-2025-5340
6.4 MEDIUM

The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’ parameter in all versions up to, and including, …

Jun 3, 2025
CVE-2025-4671
6.4 MEDIUM

The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and …

Jun 3, 2025
CVE-2025-4205
6.4 MEDIUM

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all versions up to, and including, 1.20.4 due …

Jun 3, 2025
CVE-2025-5493
6.3 MEDIUM

A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 3, 2025
CVE-2025-5492
6.3 MEDIUM

A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnerability is the function sub_456DE8 of the …

Jun 3, 2025
CVE-2025-5116
6.4 MEDIUM

The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ parameter in all versions up to, and including, …

Jun 3, 2025
CVE-2025-5103
4.9 MEDIUM

The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'default_price' and 'product_id' parameters in all versions up …

Jun 3, 2025
CVE-2025-4420
6.4 MEDIUM

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all …

Jun 3, 2025
CVE-2025-1725
6.4 MEDIUM

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site …

Jun 3, 2025
CVE-2025-41428
5.3 MEDIUM

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the …

Jun 3, 2025
CVE-2025-4567
4.8 MEDIUM

The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options …

Jun 3, 2025
CVE-2025-3662
6.1 MEDIUM

The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was …

Jun 3, 2025
CVE-2025-3584
4.8 MEDIUM

The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin …

Jun 3, 2025
CVE-2025-31712
5.1 MEDIUM

In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jun 3, 2025
CVE-2025-31711
5.1 MEDIUM

In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional …

Jun 3, 2025
CVE-2025-31710
5.9 MEDIUM

In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional …

Jun 3, 2025
CVE-2024-53018
6.6 MEDIUM

Memory corruption may occur while processing the OIS packet parser.

Jun 3, 2025
CVE-2024-53017
6.6 MEDIUM

Memory corruption while handling test pattern generator IOCTL command.

Jun 3, 2025
CVE-2024-53016
6.6 MEDIUM

Memory corruption while processing I2C settings in Camera driver.

Jun 3, 2025
CVE-2024-53015
6.6 MEDIUM

Memory corruption while processing IOCTL command to handle buffers associated with a session.

Jun 3, 2025
CVE-2024-53013
6.6 MEDIUM

Memory corruption may occur while processing voice call registration with user.

Jun 3, 2025
CVE-2025-4047
4.3 MEDIUM

The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions …

Jun 3, 2025
CVE-2025-2939
5.6 MEDIUM

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 …

Jun 3, 2025
CVE-2025-49164
4.3 MEDIUM

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a485f49a8a7d0c8b0fdc9f51ced50f2530668a.

Jun 3, 2025
CVE-2025-49163
6.7 MEDIUM

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

Jun 3, 2025
CVE-2025-49162
6.4 MEDIUM

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an attacker to …

Jun 3, 2025
CVE-2025-3919
6.4 MEDIUM

The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings …

Jun 2, 2025
CVE-2025-48996
5.3 MEDIUM

HAX open-apis provides microservice apis for HAX webcomponents repo that are shared infrastructure calls. An unauthenticated information disclosure vulnerability exists in the Penn State University …

Jun 2, 2025
CVE-2025-47585
6.5 MEDIUM

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from …

Jun 2, 2025
CVE-2025-49069
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Request Forgery.This issue affects Contact Forms by Cimatti: from n/a …

Jun 2, 2025
CVE-2025-45387
5.4 MEDIUM

osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

Jun 2, 2025
CVE-2025-27955
6.5 MEDIUM

Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive …

Jun 2, 2025
CVE-2025-27954
6.5 MEDIUM

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.

Jun 2, 2025
CVE-2025-27953
6.5 MEDIUM

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.

Jun 2, 2025
CVE-2025-23104
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privilege escalation.

Jun 2, 2025
CVE-2025-20297
4.3 MEDIUM

In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not …

Jun 2, 2025
CVE-2024-8008
5.2 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store …

Jun 2, 2025
CVE-2024-7074
6.8 MEDIUM

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with …

Jun 2, 2025
CVE-2024-7073
6.5 MEDIUM

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers …

Jun 2, 2025
CVE-2024-3509
4.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor …

Jun 2, 2025
CVE-2024-1440
5.4 MEDIUM

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is …

Jun 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.