CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27283
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator allows Path Traversal.This issue affects Theme File …

Apr 17, 2025
CVE-2025-24737
6.5 MEDIUM

Missing Authorization vulnerability in Mat Bao Corporation WP Helper Premium wp-helper-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Helper Premium: from …

Apr 17, 2025
CVE-2025-24651
5.9 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & …

Apr 17, 2025
CVE-2025-24583
6.5 MEDIUM

Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting …

Apr 17, 2025
CVE-2025-24581
6.5 MEDIUM

Missing Authorization vulnerability in Themefic Instantio instantio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Instantio: from n/a through <= 3.3.7.

Apr 17, 2025
CVE-2025-24577
6.5 MEDIUM

Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through <= …

Apr 17, 2025
CVE-2025-24550
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JobScore Job Manager job-manager-by-jobscore allows Stored XSS.This issue affects Job Manager: from n/a …

Apr 17, 2025
CVE-2025-23958
6.5 MEDIUM

Missing Authorization vulnerability in FADI MED Editor Wysiwyg Background Color editor-wysiwyg-background-color allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Editor Wysiwyg Background Color: …

Apr 17, 2025
CVE-2025-23906
6.5 MEDIUM

Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through …

Apr 17, 2025
CVE-2025-23773
6.5 MEDIUM

Missing Authorization vulnerability in mingocommerce Delete All Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Delete All Posts: through 1.1.1.

Apr 17, 2025
CVE-2025-22771
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studio Hyperset The Great Firewords of China sensitive-chinese-words-scanner allows Stored XSS.This issue affects …

Apr 17, 2025
CVE-2025-22340
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Data Dash data-dash allows Stored XSS.This issue affects Data Dash: from n/a …

Apr 17, 2025
CVE-2025-29015
6.1 MEDIUM

Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.

Apr 17, 2025
CVE-2025-3760
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, …

Apr 17, 2025
CVE-2025-3487
6.4 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter …

Apr 17, 2025
CVE-2025-3479
5.3 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, …

Apr 17, 2025
CVE-2025-3453
5.3 MEDIUM

The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is …

Apr 17, 2025
CVE-2025-26477
4.3 MEDIUM

Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading …

Apr 17, 2025
CVE-2025-2197
4.3 MEDIUM

Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.

Apr 17, 2025
CVE-2025-3615
6.4 MEDIUM

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due …

Apr 17, 2025
CVE-2025-3295
4.9 MEDIUM

The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for …

Apr 17, 2025
CVE-2025-43717
5.4 MEDIUM

In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.

Apr 17, 2025
CVE-2025-43704
4.7 MEDIUM

Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.

Apr 16, 2025
CVE-2025-24911
4.9 MEDIUM

Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define …

Apr 16, 2025
CVE-2025-24910
4.9 MEDIUM

Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define …

Apr 16, 2025
CVE-2025-24909
4.4 MEDIUM

Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that …

Apr 16, 2025
CVE-2025-24908
6.8 MEDIUM

Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled …

Apr 16, 2025
CVE-2025-24907
6.8 MEDIUM

Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled …

Apr 16, 2025
CVE-2025-1704
6.5 MEDIUM

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via …

Apr 16, 2025
CVE-2025-0758
6.1 MEDIUM

Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) …

Apr 16, 2025
CVE-2025-0757
4.4 MEDIUM

Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that …

Apr 16, 2025
CVE-2025-43703
6.1 MEDIUM

An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the …

Apr 16, 2025
CVE-2025-32791
4.3 MEDIUM

The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some …

Apr 16, 2025
CVE-2025-32783
4.7 MEDIUM

XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured …

Apr 16, 2025
CVE-2025-3728
5.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability affects the function Login. The manipulation of the argument …

Apr 16, 2025
CVE-2025-29710
6.1 MEDIUM

SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.

Apr 16, 2025
CVE-2025-26153
5.4 MEDIUM

A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, …

Apr 16, 2025
CVE-2025-32817
6.1 MEDIUM

A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this results in unauthorized file overwrite, potentially leading …

Apr 16, 2025
CVE-2025-39472
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through < …

Apr 16, 2025
CVE-2025-22872
6.5 MEDIUM

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result …

Apr 16, 2025
CVE-2024-53304
6.5 MEDIUM

An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands via posing as …

Apr 16, 2025
CVE-2025-3739
5.9 MEDIUM

Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.

Apr 16, 2025
CVE-2025-3738
5.9 MEDIUM

Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.

Apr 16, 2025
CVE-2025-3737
5.9 MEDIUM

Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.

Apr 16, 2025
CVE-2025-3736
5.9 MEDIUM

Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.

Apr 16, 2025
CVE-2025-3735
5.9 MEDIUM

Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.

Apr 16, 2025
CVE-2025-3734
5.9 MEDIUM

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue affects Stage File Proxy: from 0.0.0 before 3.1.5.

Apr 16, 2025
CVE-2025-3733
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, …

Apr 16, 2025
CVE-2025-2564
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, …

Apr 16, 2025
CVE-2024-40074
4.8 MEDIUM

Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the …

Apr 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.