CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2276
4.3 MEDIUM

The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Mar 26, 2025
CVE-2025-30219
6.1 MEDIUM

RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk …

Mar 25, 2025
CVE-2025-30741
4.3 MEDIUM

Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if …

Mar 25, 2025
CVE-2024-55029
6.1 MEDIUM

NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

Mar 25, 2025
CVE-2024-31896
5.9 MEDIUM

IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Mar 25, 2025
CVE-2025-2312
5.9 MEDIUM

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong …

Mar 25, 2025
CVE-2025-26742
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for …

Mar 25, 2025
CVE-2024-55604
4.3 MEDIUM

Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of …

Mar 25, 2025
CVE-2025-29932
4.1 MEDIUM

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

Mar 25, 2025
CVE-2025-27633
6.1 MEDIUM

The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-side code injection that might be used to compromise the confidentiality …

Mar 25, 2025
CVE-2025-27632
6.1 MEDIUM

A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple …

Mar 25, 2025
CVE-2025-27631
6.5 MEDIUM

The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that …

Mar 25, 2025
CVE-2024-12169
6.5 MEDIUM

A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart …

Mar 25, 2025
CVE-2024-11499
4.9 MEDIUM

A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can …

Mar 25, 2025
CVE-2024-10037
4.4 MEDIUM

A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted …

Mar 25, 2025
CVE-2022-1804
5.5 MEDIUM

accountsservice no longer drops permissions when writting .pam_environment

Mar 25, 2025
CVE-2025-2109
5.8 MEDIUM

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, …

Mar 25, 2025
CVE-2025-2757
6.3 MEDIUM

A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of …

Mar 25, 2025
CVE-2025-2756
6.3 MEDIUM

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of …

Mar 25, 2025
CVE-2025-2635
6.1 MEDIUM

The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg() function without appropriate escaping on the …

Mar 25, 2025
CVE-2025-2542
6.4 MEDIUM

The Your Simple SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Mar 25, 2025
CVE-2024-53679
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to …

Mar 25, 2025
CVE-2025-2755
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection …

Mar 25, 2025
CVE-2025-2754
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection …

Mar 25, 2025
CVE-2025-2753
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file …

Mar 25, 2025
CVE-2025-2559
4.9 MEDIUM

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT …

Mar 25, 2025
CVE-2025-2510
5.5 MEDIUM

The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter in all versions up to, and including, 1.0 …

Mar 25, 2025
CVE-2024-13731
6.4 MEDIUM

The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert Box …

Mar 25, 2025
CVE-2024-13710
4.3 MEDIUM

The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is …

Mar 25, 2025
CVE-2025-2752
4.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h …

Mar 25, 2025
CVE-2025-2751
4.3 MEDIUM

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file …

Mar 25, 2025
CVE-2025-2750
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp …

Mar 25, 2025
CVE-2025-2744
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component …

Mar 25, 2025
CVE-2025-2743
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the file /admin-api/mp/material/upload-temporary of …

Mar 25, 2025
CVE-2025-2742
5.4 MEDIUM

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload …

Mar 25, 2025
CVE-2025-2252
5.3 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Mar 25, 2025
CVE-2025-1320
4.3 MEDIUM

The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or …

Mar 25, 2025
CVE-2024-12623
6.4 MEDIUM

The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in all versions up to, and including, 0.10.6 …

Mar 25, 2025
CVE-2025-2224
5.3 MEDIUM

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a …

Mar 25, 2025
CVE-2025-27810
5.4 MEDIUM

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the …

Mar 25, 2025
CVE-2025-27809
5.4 MEDIUM

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client …

Mar 25, 2025
CVE-2025-1798
6.1 MEDIUM

The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting …

Mar 25, 2025
CVE-2025-0845
6.4 MEDIUM

The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient …

Mar 25, 2025
CVE-2024-9770
4.7 MEDIUM

The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL …

Mar 25, 2025
CVE-2024-13118
4.3 MEDIUM

The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Mar 25, 2025
CVE-2024-12682
6.1 MEDIUM

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-12109
4.1 MEDIUM

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, …

Mar 25, 2025
CVE-2024-11503
6.1 MEDIUM

The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 25, 2025
CVE-2024-11273
6.1 MEDIUM

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could …

Mar 25, 2025
CVE-2024-11272
6.1 MEDIUM

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could …

Mar 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.