CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31729
6.5 MEDIUM

Missing Authorization vulnerability in jeffikus WooTumblog woo-tumblog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooTumblog: from n/a through <= 2.1.4.

Apr 3, 2025
CVE-2025-31622
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Utkarsh Kukreti Advanced Typekit advanced-typekit allows Stored XSS.This issue affects Advanced Typekit: from …

Apr 3, 2025
CVE-2025-31581
6.5 MEDIUM

Missing Authorization vulnerability in Sandeep Kumar WP Video Playlist wp-video-playlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Video Playlist: from n/a …

Apr 3, 2025
CVE-2025-31558
5.8 MEDIUM

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Greg TailPress tailpress allows Retrieve Embedded Sensitive Data.This issue affects TailPress: from n/a through …

Apr 3, 2025
CVE-2025-31554
5.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in docxpresso Docxpresso docxpresso allows Absolute Path Traversal.This issue affects Docxpresso: from n/a …

Apr 3, 2025
CVE-2025-31541
6.5 MEDIUM

Missing Authorization vulnerability in TuriTop TuriTop Booking System turitop-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TuriTop Booking System: from n/a through …

Apr 3, 2025
CVE-2025-31091
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Header and Footer cm-header-footer-script-loader allows Stored XSS.This issue affects CM Header …

Apr 3, 2025
CVE-2025-30916
6.5 MEDIUM

Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Residential Address Detection: from n/a through …

Apr 3, 2025
CVE-2025-30915
6.5 MEDIUM

Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Small Package …

Apr 3, 2025
CVE-2025-30596
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file include-file allows Path Traversal.This issue affects include-file: from n/a through …

Apr 3, 2025
CVE-2024-9416
6.4 MEDIUM

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to …

Apr 3, 2025
CVE-2025-2299
6.1 MEDIUM

The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. This is due …

Apr 3, 2025
CVE-2025-3150
4.3 MEDIUM

A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been declared as problematic. Affected by this vulnerability is an …

Apr 3, 2025
CVE-2025-2874
4.4 MEDIUM

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin …

Apr 3, 2025
CVE-2025-22007
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix error code in chan_alloc_skb_cb() The chan_alloc_skb_cb() function is supposed to return error pointers …

Apr 3, 2025
CVE-2025-22006
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: Fix NAPI registration sequence Registering the interrupts for TX or RX …

Apr 3, 2025
CVE-2025-22005
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw(). fib_check_nh_v6_gw() expects that fib6_nh_init() cleans up everything when …

Apr 3, 2025
CVE-2025-22003
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix out of bound read in strscpy() source Commit 7fdaf8966aae ("can: ucan: use …

Apr 3, 2025
CVE-2025-22002
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Call `invalidate_cache` only if implemented Many filesystems such as NFS and Ceph do not …

Apr 3, 2025
CVE-2025-22001
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix integer overflow in qaic_validate_req() These are u64 variables that come from the user …

Apr 3, 2025
CVE-2025-22000
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: drop beyond-EOF folios with the right number of refs When an after-split folio is …

Apr 3, 2025
CVE-2025-21998
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the TZ allocator, …

Apr 3, 2025
CVE-2025-21997
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xsk: fix an integer overflow in xp_create_and_assign_umem() Since the i and pool->chunk_size variables are of …

Apr 3, 2025
CVE-2025-21996
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse() On the off chance that command stream passed …

Apr 3, 2025
CVE-2025-21995
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix fence reference count leak The last_scheduled fence leaks when an entity is being …

Apr 3, 2025
CVE-2025-1663
6.4 MEDIUM

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 …

Apr 3, 2025
CVE-2024-13673
6.4 MEDIUM

The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' shortcode in all versions up to, and including, …

Apr 3, 2025
CVE-2025-30485
6.2 MEDIUM

UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attaching to the affected product an external storage …

Apr 3, 2025
CVE-2025-3143
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The …

Apr 3, 2025
CVE-2025-3142
6.3 MEDIUM

A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 3, 2025
CVE-2025-31334
6.8 MEDIUM

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists …

Apr 3, 2025
CVE-2025-2055
6.8 MEDIUM

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users …

Apr 3, 2025
CVE-2025-3141
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 3, 2025
CVE-2025-3140
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 3, 2025
CVE-2025-3139
5.3 MEDIUM

A vulnerability was found in code-projects Bus Reservation System 1.0 and classified as critical. Affected by this issue is the function Login of the component …

Apr 3, 2025
CVE-2025-3153
6.5 MEDIUM

Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are …

Apr 3, 2025
CVE-2025-3135
6.3 MEDIUM

A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The …

Apr 3, 2025
CVE-2025-3134
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation …

Apr 3, 2025
CVE-2025-3123
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme …

Apr 2, 2025
CVE-2025-3130
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1.

Apr 2, 2025
CVE-2025-3129
4.8 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.

Apr 2, 2025
CVE-2025-3120
6.3 MEDIUM

A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 2, 2025
CVE-2025-3119
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /tutor/courses/manage_course.php. …

Apr 2, 2025
CVE-2025-30218
5.9 MEDIUM

Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this …

Apr 2, 2025
CVE-2025-0257
6.3 MEDIUM

HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its …

Apr 2, 2025
CVE-2025-3118
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. …

Apr 2, 2025
CVE-2025-29719
6.1 MEDIUM

SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.

Apr 2, 2025
CVE-2025-31286
4.6 MEDIUM

An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has …

Apr 2, 2025
CVE-2025-31285
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could …

Apr 2, 2025
CVE-2025-31284
4.6 MEDIUM

A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then …

Apr 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.