CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3956
6.3 MEDIUM

A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the function RestResp of the file novel-cloud-master/novel-book/novel-book-service/src/main/resources/mapper/BookInfoMapper.xml. The manipulation …

Apr 27, 2025
CVE-2025-46578
6.5 MEDIUM

There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database …

Apr 27, 2025
CVE-2025-46577
6.5 MEDIUM

There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.

Apr 27, 2025
CVE-2025-46576
5.4 MEDIUM

There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.

Apr 27, 2025
CVE-2025-46575
4.9 MEDIUM

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

Apr 27, 2025
CVE-2025-46574
4.1 MEDIUM

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

Apr 27, 2025
CVE-2025-46673
4.9 MEDIUM

NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space …

Apr 27, 2025
CVE-2025-3955
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This affects an unknown part of the file /edit_rpatient.php.php. …

Apr 27, 2025
CVE-2025-46655
4.9 MEDIUM

CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of …

Apr 26, 2025
CVE-2025-46654
4.9 MEDIUM

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that …

Apr 26, 2025
CVE-2025-46652
6.1 MEDIUM

In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is …

Apr 26, 2025
CVE-2025-46646
4.5 MEDIUM

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

Apr 26, 2025
CVE-2024-53636
6.4 MEDIUM

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the …

Apr 26, 2025
CVE-2024-13812
6.5 MEDIUM

The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.1.1. This is due …

Apr 26, 2025
CVE-2025-2811
5.7 MEDIUM

A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 …

Apr 26, 2025
CVE-2025-3915
4.3 MEDIUM

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function …

Apr 26, 2025
CVE-2025-1458
6.4 MEDIUM

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 26, 2025
CVE-2025-32984
6.1 MEDIUM

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.

Apr 25, 2025
CVE-2025-32979
6.5 MEDIUM

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

Apr 25, 2025
CVE-2024-30152
6.5 MEDIUM

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify …

Apr 25, 2025
CVE-2025-2070
5.0 MEDIUM

An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is …

Apr 25, 2025
CVE-2025-2069
5.0 MEDIUM

A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local …

Apr 25, 2025
CVE-2025-2068
5.0 MEDIUM

An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.

Apr 25, 2025
CVE-2025-46433
4.9 MEDIUM

In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

Apr 25, 2025
CVE-2025-46432
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs

Apr 25, 2025
CVE-2025-43016
5.4 MEDIUM

In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

Apr 25, 2025
CVE-2025-3647
4.3 MEDIUM

A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.

Apr 25, 2025
CVE-2025-3645
4.3 MEDIUM

A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

Apr 25, 2025
CVE-2025-3644
4.3 MEDIUM

A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

Apr 25, 2025
CVE-2025-3643
5.4 MEDIUM

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

Apr 25, 2025
CVE-2025-3640
4.3 MEDIUM

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as …

Apr 25, 2025
CVE-2025-3636
4.3 MEDIUM

A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.

Apr 25, 2025
CVE-2025-3628
4.3 MEDIUM

A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.

Apr 25, 2025
CVE-2025-3627
4.3 MEDIUM

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using …

Apr 25, 2025
CVE-2025-32045
5.3 MEDIUM

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

Apr 25, 2025
CVE-2025-28076
6.5 MEDIUM

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) …

Apr 25, 2025
CVE-2025-3634
4.3 MEDIUM

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can …

Apr 25, 2025
CVE-2025-28354
6.5 MEDIUM

An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted …

Apr 25, 2025
CVE-2025-3912
5.3 MEDIUM

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to …

Apr 25, 2025
CVE-2025-2986
5.5 MEDIUM

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web …

Apr 25, 2025
CVE-2025-3870
6.1 MEDIUM

The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.dec.2012. This is due to …

Apr 25, 2025
CVE-2025-46535
5.4 MEDIUM

Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a …

Apr 25, 2025
CVE-2025-46482
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz wp-quiz allows Stored XSS.This issue affects WP Quiz: from n/a …

Apr 25, 2025
CVE-2025-3868
6.1 MEDIUM

The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 …

Apr 25, 2025
CVE-2025-3867
6.1 MEDIUM

The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due …

Apr 25, 2025
CVE-2025-3866
6.1 MEDIUM

The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Apr 25, 2025
CVE-2025-3743
5.3 MEDIUM

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due …

Apr 25, 2025
CVE-2025-3923
5.3 MEDIUM

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 …

Apr 25, 2025
CVE-2025-3861
5.4 MEDIUM

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability …

Apr 25, 2025
CVE-2025-2580
4.9 MEDIUM

The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Apr 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.