CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52875
8.8 HIGH

An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is …

Jan 31, 2025
CVE-2025-0809
7.2 HIGH

The Link Fixer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via broken links in all versions up to, and including, 3.4 due to …

Jan 31, 2025
CVE-2024-13504
7.2 HIGH

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads …

Jan 31, 2025
CVE-2024-47900
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.

Jan 31, 2025
CVE-2024-47899
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Jan 31, 2025
CVE-2024-47898
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Jan 31, 2025
CVE-2024-47891
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Jan 31, 2025
CVE-2024-46974
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA buffers.

Jan 31, 2025
CVE-2024-13767
8.1 HIGH

The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up …

Jan 31, 2025
CVE-2024-23929
7.3 HIGH

This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the …

Jan 31, 2025
CVE-2024-23921
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23920
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2022-28653
7.5 HIGH

Users can consume unlimited disk space in /var/crash

Jan 31, 2025
CVE-2024-24731
7.5 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. …

Jan 31, 2025
CVE-2024-23973
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. …

Jan 31, 2025
CVE-2024-23971
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23969
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23968
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23963
8.0 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair …

Jan 31, 2025
CVE-2025-24886
7.7 HIGH

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows …

Jan 30, 2025
CVE-2025-24885
7.6 HIGH

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rendering custom (unprivileged) dojo …

Jan 30, 2025
CVE-2025-0574
7.5 HIGH

Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS …

Jan 30, 2025
CVE-2025-0569
7.5 HIGH

Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante …

Jan 30, 2025
CVE-2025-0568
7.5 HIGH

Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante …

Jan 30, 2025
CVE-2024-11611
7.8 HIGH

AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jan 30, 2025
CVE-2024-11610
7.8 HIGH

AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jan 30, 2025
CVE-2024-11609
7.8 HIGH

AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Jan 30, 2025
CVE-2025-24802
8.6 HIGH

Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not divisible by 26 = floor(num_routed_wires / 3) …

Jan 30, 2025
CVE-2025-0147
8.8 HIGH

Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.

Jan 30, 2025
CVE-2025-0626
7.5 HIGH

The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to …

Jan 30, 2025
CVE-2024-44142
7.8 HIGH

The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code …

Jan 30, 2025
CVE-2025-22222
7.7 HIGH

VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin …

Jan 30, 2025
CVE-2025-22218
8.5 HIGH

VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials …

Jan 30, 2025
CVE-2024-13720
8.8 HIGH

The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all …

Jan 30, 2025
CVE-2024-13707
8.8 HIGH

The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to …

Jan 30, 2025
CVE-2024-13671
7.5 HIGH

The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.1 via the read_score_file() function. …

Jan 30, 2025
CVE-2024-13646
8.1 HIGH

The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on …

Jan 30, 2025
CVE-2024-12821
8.8 HIGH

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing …

Jan 30, 2025
CVE-2024-12269
7.5 HIGH

The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Jan 30, 2025
CVE-2024-12129
8.8 HIGH

The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check …

Jan 30, 2025
CVE-2024-11600
7.2 HIGH

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Remote Code Execution in all versions up …

Jan 30, 2025
CVE-2024-10591
8.8 HIGH

The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauthorized modification of data …

Jan 30, 2025
CVE-2025-0747
8.6 HIGH

A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message …

Jan 30, 2025
CVE-2025-0745
7.5 HIGH

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the …

Jan 30, 2025
CVE-2025-0744
7.5 HIGH

an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying …

Jan 30, 2025
CVE-2025-0740
8.6 HIGH

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to …

Jan 30, 2025
CVE-2025-0739
8.6 HIGH

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others …

Jan 30, 2025
CVE-2024-13453
7.3 HIGH

The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Jan 30, 2025
CVE-2025-21107
7.8 HIGH

Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker …

Jan 30, 2025
CVE-2025-0834
7.8 HIGH

Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\ProgramData\Wondershare\wsServices\ElevationService.exe’ …

Jan 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.