CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2995
5.3 MEDIUM

A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects unknown code of the file /goform/SysToolChangePwd of the component …

Mar 31, 2025
CVE-2024-55093
5.4 MEDIUM

phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.

Mar 31, 2025
CVE-2025-2994
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component …

Mar 31, 2025
CVE-2025-2993
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality of the file …

Mar 31, 2025
CVE-2025-3027
6.1 MEDIUM

The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, …

Mar 31, 2025
CVE-2025-3026
6.1 MEDIUM

The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it …

Mar 31, 2025
CVE-2025-31419
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeix Churel allows DOM-Based XSS.This issue affects Churel: from n/a through 1.0.8.

Mar 31, 2025
CVE-2025-30963
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSmartFilters jet-smart-filters allows DOM-Based XSS.This issue affects JetSmartFilters: from n/a through <= …

Mar 31, 2025
CVE-2025-2992
5.3 MEDIUM

A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is an unknown functionality of the file /goform/AdvSetWrlsafeset of the …

Mar 31, 2025
CVE-2025-2991
5.3 MEDIUM

A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of the file /goform/AdvSetWrlmacfilter of the component Web …

Mar 31, 2025
CVE-2025-31386
5.3 MEDIUM

Missing Authorization vulnerability in simplepress Simple:Press simplepress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple:Press: from n/a through <= 6.11.5.

Mar 31, 2025
CVE-2025-31376
4.3 MEDIUM

Missing Authorization vulnerability in Mayeenul Islam NanoSupport nanosupport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NanoSupport: from n/a through <= 0.6.0.

Mar 31, 2025
CVE-2025-2990
5.3 MEDIUM

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/AdvSetWrlGstset of …

Mar 31, 2025
CVE-2025-2989
5.3 MEDIUM

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/AdvSetWrl of the …

Mar 31, 2025
CVE-2025-31410
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Church Donation wp-church-donation allows Cross Site Request Forgery.This issue affects WP Church Donation: from n/a through …

Mar 31, 2025
CVE-2025-31406
4.3 MEDIUM

Missing Authorization vulnerability in ELEXtensions ELEX WooCommerce Request a Quote elex-request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WooCommerce Request a …

Mar 31, 2025
CVE-2025-30961
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tinuzz Trackserver trackserver allows DOM-Based XSS.This issue affects Trackserver: from n/a through <= …

Mar 31, 2025
CVE-2025-2985
6.3 MEDIUM

A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affects an unknown part of the file update_account.php. …

Mar 31, 2025
CVE-2025-2984
6.3 MEDIUM

A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Mar 31, 2025
CVE-2025-2983
5.5 MEDIUM

A vulnerability has been found in Legrand SMS PowerView 1.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of …

Mar 31, 2025
CVE-2025-2982
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown function. The manipulation of the argument redirect …

Mar 31, 2025
CVE-2025-31417
4.3 MEDIUM

Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through < …

Mar 31, 2025
CVE-2025-31414
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder allows Stored XSS.This issue affects Cost Calculator Builder: …

Mar 31, 2025
CVE-2025-31412
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetProductGallery jet-woo-product-gallery allows DOM-Based XSS.This issue affects JetProductGallery: from n/a through <= …

Mar 31, 2025
CVE-2025-31043
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= …

Mar 31, 2025
CVE-2025-30987
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: …

Mar 31, 2025
CVE-2025-2978
6.3 MEDIUM

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=container&CKEditorFuncNum=1 …

Mar 31, 2025
CVE-2025-0613
6.1 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated …

Mar 31, 2025
CVE-2025-24852
4.6 MEDIUM

Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an attacker who can …

Mar 31, 2025
CVE-2025-2973
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file /Admin/student.php. The …

Mar 31, 2025
CVE-2025-2961
4.3 MEDIUM

A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function render_mav of the file /aa of the component …

Mar 30, 2025
CVE-2025-2960
6.5 MEDIUM

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the …

Mar 30, 2025
CVE-2025-2959
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is the function sub_4019A0 of the file …

Mar 30, 2025
CVE-2025-2958
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Mar 30, 2025
CVE-2025-2957
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function sub_401DB0 of the file /usr/sbin/httpd of the …

Mar 30, 2025
CVE-2025-2956
6.5 MEDIUM

A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the …

Mar 30, 2025
CVE-2025-2955
5.3 MEDIUM

A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/ExportIbmsConfig.sh of …

Mar 30, 2025
CVE-2025-2952
6.3 MEDIUM

A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /api/api.php?mod=upload&type=1. The …

Mar 30, 2025
CVE-2025-2951
6.3 MEDIUM

A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the file /api/data.php. The manipulation of …

Mar 30, 2025
CVE-2025-1734
5.3 MEDIUM

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the …

Mar 30, 2025
CVE-2025-1219
5.3 MEDIUM

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the …

Mar 30, 2025
CVE-2024-11180
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, …

Mar 29, 2025
CVE-2025-2840
5.3 MEDIUM

The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the …

Mar 29, 2025
CVE-2024-13557
6.5 MEDIUM

The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6. This is due …

Mar 29, 2025
CVE-2024-7577
4.4 MEDIUM

IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.

Mar 29, 2025
CVE-2024-51477
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.

Mar 29, 2025
CVE-2024-43186
5.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.

Mar 29, 2025
CVE-2025-28097
5.5 MEDIUM

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

Mar 28, 2025
CVE-2025-28096
5.4 MEDIUM

OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

Mar 28, 2025
CVE-2025-28094
6.5 MEDIUM

shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

Mar 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.