CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27565
5.3 MEDIUM

An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

Apr 15, 2025
CVE-2025-27561
5.3 MEDIUM

Unauthenticated attackers can rename "rooms" of arbitrary users.

Apr 15, 2025
CVE-2025-26998
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a …

Apr 15, 2025
CVE-2025-26996
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through …

Apr 15, 2025
CVE-2025-26951
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in covertnine C9 Blocks c9-blocks allows DOM-Based XSS.This issue affects C9 Blocks: from n/a …

Apr 15, 2025
CVE-2025-26950
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonsPress Nepali Date Converter nepali-date-converter allows Stored XSS.This issue affects Nepali Date Converter: …

Apr 15, 2025
CVE-2025-26934
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphthemes Glossy Blog glossy-blog allows Stored XSS.This issue affects Glossy Blog: from n/a …

Apr 15, 2025
CVE-2025-26930
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Home Services home-services allows DOM-Based XSS.This issue affects Home Services: from n/a …

Apr 15, 2025
CVE-2025-26919
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainá taina allows Stored XSS.This issue affects Tainá: from n/a through < …

Apr 15, 2025
CVE-2025-26906
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows DOM-Based XSS.This issue affects WP …

Apr 15, 2025
CVE-2025-26903
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery inpost-gallery allows Cross Site Request Forgery.This issue affects InPost Gallery: from n/a through <= 2.1.4.3.

Apr 15, 2025
CVE-2025-26880
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar skt-skill-bar allows Stored XSS.This issue affects SKT Skill Bar: …

Apr 15, 2025
CVE-2025-26870
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows DOM-Based XSS.This issue affects JetEngine: from n/a through <= …

Apr 15, 2025
CVE-2025-26857
5.3 MEDIUM

Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

Apr 15, 2025
CVE-2025-26749
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects …

Apr 15, 2025
CVE-2025-26740
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware SpaBiz spabiz allows DOM-Based XSS.This issue affects SpaBiz: from n/a through <= …

Apr 15, 2025
CVE-2025-25276
5.3 MEDIUM

An unauthenticated attacker can hijack other users' devices and potentially control them.

Apr 15, 2025
CVE-2025-24850
5.3 MEDIUM

An attacker can export other users' plant information.

Apr 15, 2025
CVE-2025-24315
5.3 MEDIUM

Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

Apr 15, 2025
CVE-2025-22269
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from …

Apr 15, 2025
CVE-2025-22268
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny …

Apr 15, 2025
CVE-2024-49200
6.4 MEDIUM

An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. …

Apr 15, 2025
CVE-2025-31949
5.3 MEDIUM

An authenticated attacker can obtain any plant name by knowing the plant ID.

Apr 15, 2025
CVE-2025-31941
5.3 MEDIUM

An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.

Apr 15, 2025
CVE-2025-31933
5.3 MEDIUM

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

Apr 15, 2025
CVE-2025-31357
5.3 MEDIUM

An unauthenticated attacker can obtain a user's plant list by knowing the username.

Apr 15, 2025
CVE-2025-30740
6.5 MEDIUM

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable …

Apr 15, 2025
CVE-2025-30737
5.7 MEDIUM

Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). The supported version that is affected is 24.200. Difficult …

Apr 15, 2025
CVE-2025-30733
6.5 MEDIUM

Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows unauthenticated …

Apr 15, 2025
CVE-2025-30732
6.1 MEDIUM

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows …

Apr 15, 2025
CVE-2025-30729
5.5 MEDIUM

Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and …

Apr 15, 2025
CVE-2025-30726
5.3 MEDIUM

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows …

Apr 15, 2025
CVE-2025-30725
6.7 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Difficult to exploit vulnerability allows …

Apr 15, 2025
CVE-2025-30723
5.4 MEDIUM

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30722
5.3 MEDIUM

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit …

Apr 15, 2025
CVE-2025-30721
4.0 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit …

Apr 15, 2025
CVE-2025-30720
6.1 MEDIUM

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Orders). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker …

Apr 15, 2025
CVE-2025-30719
6.1 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploitable vulnerability allows low …

Apr 15, 2025
CVE-2025-30718
5.4 MEDIUM

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30717
6.5 MEDIUM

Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows …

Apr 15, 2025
CVE-2025-30715
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable …

Apr 15, 2025
CVE-2025-30714
4.8 MEDIUM

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged …

Apr 15, 2025
CVE-2025-30713
5.4 MEDIUM

Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily …

Apr 15, 2025
CVE-2025-30711
5.4 MEDIUM

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30710
4.9 MEDIUM

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable …

Apr 15, 2025
CVE-2025-30709
6.1 MEDIUM

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable …

Apr 15, 2025
CVE-2025-30705
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability …

Apr 15, 2025
CVE-2025-30704
4.4 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to …

Apr 15, 2025
CVE-2025-30702
5.3 MEDIUM

Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.3-19.26. Easily exploitable vulnerability allows unauthenticated …

Apr 15, 2025
CVE-2025-30699
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable …

Apr 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.