CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-49747
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: erofs/zmap.c: Fix incorrect offset calculation Effective offset to add to length was being incorrectly calculated, …

Mar 27, 2025
CVE-2022-49746
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: imx-sdma: Fix a possible memory leak in sdma_transfer_init If the function sdma_load_context() fails, the …

Mar 27, 2025
CVE-2022-49745
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: m10bmc-sec: Fix probe rollback Handle probe error rollbacks properly to avoid leaks.

Mar 27, 2025
CVE-2022-49744
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/uffd: fix pte marker when fork() without fork event Patch series "mm: Fixes on pte …

Mar 27, 2025
CVE-2022-49743
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ovl: Use "buf" flexible array for memcpy() destination The "buf" flexible array needs to be …

Mar 27, 2025
CVE-2022-49742
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: initialize locks earlier in f2fs_fill_super() syzbot is reporting lockdep warning at f2fs_handle_error() [1], for …

Mar 27, 2025
CVE-2022-49741
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: fix error handling code in ufx_usb_probe The current error handling code in ufx_usb_probe …

Mar 27, 2025
CVE-2022-49739
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed …

Mar 27, 2025
CVE-2021-4454
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: j1939: fix errant WARN_ON_ONCE in j1939_session_deactivate The conclusion "j1939_session_deactivate() should be called with a …

Mar 27, 2025
CVE-2025-2855
4.7 MEDIUM

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of …

Mar 27, 2025
CVE-2025-26762
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= …

Mar 27, 2025
CVE-2025-26265
6.5 MEDIUM

A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification response.

Mar 27, 2025
CVE-2025-22640
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in integrationdevpaytm Paytm Payment Donation paytm-donation allows Stored XSS.This issue affects Paytm Payment Donation: …

Mar 27, 2025
CVE-2025-22638
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce allows Stored XSS.This issue affects Product Table …

Mar 27, 2025
CVE-2025-22637
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in verkkovaraani Print PDF Generator and Publisher nopeamedia allows Cross Site Request Forgery.This issue affects Print PDF Generator and Publisher: …

Mar 27, 2025
CVE-2025-22634
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MD Abu Jubayer Hossain Easy Booked – Appointment Booking and Scheduling Management System for WordPress easy-booked allows Cross Site …

Mar 27, 2025
CVE-2025-22629
5.3 MEDIUM

Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iNET Webkit: from n/a through <= 1.2.2.

Mar 27, 2025
CVE-2025-22497
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bramwaas Simple Google Calendar Outlook Events Block Widget simple-google-icalendar-widget allows Stored XSS.This issue …

Mar 27, 2025
CVE-2025-22496
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MarMar8x Notif Bell notif-bell allows Stored XSS.This issue affects Notif Bell: from n/a …

Mar 27, 2025
CVE-2025-22278
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes Whitish Lite allows Stored XSS.This issue affects Whitish Lite: from n/a through …

Mar 27, 2025
CVE-2025-31181
6.2 MEDIUM

A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-31180
6.2 MEDIUM

A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-31179
6.2 MEDIUM

A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

Mar 27, 2025
CVE-2025-31178
6.2 MEDIUM

A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-31176
6.2 MEDIUM

A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-30221
4.3 MEDIUM

Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with …

Mar 27, 2025
CVE-2025-2854
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file update_employee.php. …

Mar 27, 2025
CVE-2025-29497
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.

Mar 27, 2025
CVE-2025-29496
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29494
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29493
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29492
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.

Mar 27, 2025
CVE-2025-29491
6.5 MEDIUM

An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.

Mar 27, 2025
CVE-2025-29490
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29489
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.

Mar 27, 2025
CVE-2025-29488
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.

Mar 27, 2025
CVE-2025-29486
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.

Mar 27, 2025
CVE-2025-29485
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29483
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.

Mar 27, 2025
CVE-2025-22671
4.3 MEDIUM

Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation disable-elementor-editor-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from …

Mar 27, 2025
CVE-2025-22670
6.5 MEDIUM

Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VikBooking Hotel Booking …

Mar 27, 2025
CVE-2025-22669
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Cross Site Request Forgery.This issue affects Awesome Event Booking: from n/a through <= …

Mar 27, 2025
CVE-2025-22668
6.5 MEDIUM

Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Event Booking: from n/a through …

Mar 27, 2025
CVE-2025-22667
4.3 MEDIUM

Missing Authorization vulnerability in Creative Werk Designs Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets wpsyncsheets-woocommerce.This issue affects Export Order, Product, Customer …

Mar 27, 2025
CVE-2025-22665
4.3 MEDIUM

Missing Authorization vulnerability in Shakeeb Sadikeen RapidLoad unusedcss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RapidLoad: from n/a through <= 2.4.4.

Mar 27, 2025
CVE-2025-22660
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wolfgang Include Mastodon Feed include-mastodon-feed allows DOM-Based XSS.This issue affects Include Mastodon Feed: …

Mar 27, 2025
CVE-2025-22659
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle themeisle-companion allows Stored XSS.This issue affects Orbit Fox …

Mar 27, 2025
CVE-2025-22649
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: …

Mar 27, 2025
CVE-2025-22648
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Blog, Posts and Category Filter for Elementor blog-posts-and-category-for-elementor allows Stored XSS.This …

Mar 27, 2025
CVE-2025-22647
4.3 MEDIUM

Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …

Mar 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.