CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-55517
8.8 HIGH

An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is …

Jan 8, 2025
CVE-2024-51737
7.0 HIGH

RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a …

Jan 8, 2025
CVE-2024-51480
7.0 HIGH

RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using …

Jan 8, 2025
CVE-2025-21102
7.5 HIGH

Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this …

Jan 8, 2025
CVE-2024-11423
7.5 HIGH

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, …

Jan 8, 2025
CVE-2024-12854
8.8 HIGH

The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the functionality that automatically extracts …

Jan 8, 2025
CVE-2024-12853
8.8 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in …

Jan 8, 2025
CVE-2024-9939
7.5 HIGH

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it …

Jan 8, 2025
CVE-2024-45033
8.1 HIGH

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with …

Jan 8, 2025
CVE-2024-13186
7.5 HIGH

The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-13185
7.5 HIGH

The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-11939
7.5 HIGH

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, and …

Jan 8, 2025
CVE-2024-13173
7.5 HIGH

The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-11271
8.8 HIGH

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in …

Jan 8, 2025
CVE-2024-11270
8.8 HIGH

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function …

Jan 8, 2025
CVE-2024-56451
7.3 HIGH

Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-11916
7.4 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability …

Jan 8, 2025
CVE-2024-11816
8.8 HIGH

The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing …

Jan 8, 2025
CVE-2024-56447
7.8 HIGH

Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56444
7.5 HIGH

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56439
7.5 HIGH

Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2025-22132
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By …

Jan 7, 2025
CVE-2024-53522
7.5 HIGH

Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to …

Jan 7, 2025
CVE-2022-45186
8.1 HIGH

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

Jan 7, 2025
CVE-2022-45185
8.8 HIGH

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code …

Jan 7, 2025
CVE-2024-40427
7.9 HIGH

Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute

Jan 7, 2025
CVE-2024-55413
7.8 HIGH

A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via …

Jan 7, 2025
CVE-2024-55412
7.8 HIGH

A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via …

Jan 7, 2025
CVE-2024-55411
8.8 HIGH

An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL …

Jan 7, 2025
CVE-2024-54007
7.2 HIGH

Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation …

Jan 7, 2025
CVE-2024-54006
7.2 HIGH

Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation …

Jan 7, 2025
CVE-2025-22350
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injection.This issue affects Ultimate Learning …

Jan 7, 2025
CVE-2024-8361
7.5 HIGH

In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which …

Jan 7, 2025
CVE-2024-55555
8.8 HIGH

Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available …

Jan 7, 2025
CVE-2024-40749
7.5 HIGH

Improper Access Controls allows access to protected views.

Jan 7, 2025
CVE-2024-40748
7.5 HIGH

Lack of output escaping in the id attribute of menu lists.

Jan 7, 2025
CVE-2024-12430
7.0 HIGH

An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 …

Jan 7, 2025
CVE-2025-22593
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burria Laika Pedigree Tree laika-pedigree-tree allows Stored XSS.This issue affects Laika Pedigree Tree: …

Jan 7, 2025
CVE-2025-22592
7.5 HIGH

Missing Authorization vulnerability in 8blocks 1003 Mortgage Application 1003-mortgage-application allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 1003 Mortgage Application: from n/a through …

Jan 7, 2025
CVE-2025-22590
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in mmrs151 Prayer Times Anywhere prayer-times-anywhere allows Stored XSS.This issue affects Prayer Times Anywhere: from n/a through <= 2.0.1.

Jan 7, 2025
CVE-2025-22589
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in bozdoz Quote Tweet quote-tweet allows Stored XSS.This issue affects Quote Tweet: from n/a through <= 0.7.

Jan 7, 2025
CVE-2025-22582
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Scott Nelle Uptime Robot uptime-robot allows Stored XSS.This issue affects Uptime Robot: from n/a through <= 0.1.3.

Jan 7, 2025
CVE-2025-22571
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in instabot Instabot instabot allows Cross Site Request Forgery.This issue affects Instabot: from n/a through <= 1.10.

Jan 7, 2025
CVE-2025-22559
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in tubepress TubePress.NET tubepressnet allows Cross Site Request Forgery.This issue affects TubePress.NET: from n/a through <= 4.0.1.

Jan 7, 2025
CVE-2025-22557
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in cdowp News Publisher Autopilot wpm-news-api allows Cross Site Request Forgery.This issue affects News Publisher Autopilot: from n/a through <= …

Jan 7, 2025
CVE-2025-22556
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Norse Rune Oracle Plugin norse-runes-oracle allows Cross Site Request Forgery.This issue affects Norse Rune Oracle Plugin: …

Jan 7, 2025
CVE-2025-22555
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in njshofe Smoothness Slider Shortcode smoothness-slider-shortcode allows Cross Site Request Forgery.This issue affects Smoothness Slider Shortcode: from n/a through <= …

Jan 7, 2025
CVE-2025-22552
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in bnielsen Affiliate Disclosure Statement affiliate-disclosure-statement allows Cross Site Request Forgery.This issue affects Affiliate Disclosure Statement: from n/a through <= …

Jan 7, 2025
CVE-2025-22548
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in frankkoenen ldap_login_password_and_role_manager ldap-login-password-and-role-manager allows Stored XSS.This issue affects ldap_login_password_and_role_manager: from n/a through <= …

Jan 7, 2025
CVE-2025-22547
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jaykrishnang JK Html To Pdf jk-html-to-pdf allows Stored XSS.This issue affects JK Html …

Jan 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.