CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2626
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This vulnerability affects unknown code of the file edit_case.php. …

Mar 22, 2025
CVE-2025-2625
6.3 MEDIUM

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /system/cms/content/page. The manipulation of the …

Mar 22, 2025
CVE-2025-2624
6.3 MEDIUM

A vulnerability was found in westboy CicadasCMS 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Mar 22, 2025
CVE-2025-2622
6.3 MEDIUM

A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the …

Mar 22, 2025
CVE-2025-26796
5.4 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all …

Mar 22, 2025
CVE-2025-2577
6.4 MEDIUM

The Bitspecter Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due …

Mar 22, 2025
CVE-2025-2331
5.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 …

Mar 22, 2025
CVE-2025-1973
4.9 MEDIUM

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the …

Mar 22, 2025
CVE-2024-13666
5.3 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions …

Mar 22, 2025
CVE-2025-2484
6.1 MEDIUM

The Multi Video Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'video_id' and 'group_id' parameters in all versions up to, and …

Mar 22, 2025
CVE-2025-2482
6.1 MEDIUM

The Gotcha | Gesture-based Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menu' parameter in all versions up to, and including, …

Mar 22, 2025
CVE-2025-2479
6.1 MEDIUM

The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, …

Mar 22, 2025
CVE-2025-2478
4.9 MEDIUM

The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due …

Mar 22, 2025
CVE-2025-2477
4.7 MEDIUM

The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ckemail’ parameter in all versions up to, and including, 2.4 due to …

Mar 22, 2025
CVE-2025-1311
6.5 MEDIUM

The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in the update_delivery_status() function in all …

Mar 22, 2025
CVE-2025-0807
4.3 MEDIUM

The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Mar 22, 2025
CVE-2024-13856
6.4 MEDIUM

The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, …

Mar 22, 2025
CVE-2024-13768
4.3 MEDIUM

The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Mar 22, 2025
CVE-2025-1408
4.3 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 22, 2025
CVE-2025-0723
6.5 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters …

Mar 22, 2025
CVE-2024-13739
6.1 MEDIUM

The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9.9.7 due to …

Mar 22, 2025
CVE-2024-13737
4.3 MEDIUM

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on …

Mar 22, 2025
CVE-2025-26500
4.6 MEDIUM

: Uncontrolled Resource Consumption vulnerability in Wind River Systems VxWorks 7 on VxWorks allows Excessive Allocation. Specifically crafted USB packets may lead to the system …

Mar 21, 2025
CVE-2025-2608
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown part of the file /admin/view-user-queries.php. The manipulation …

Mar 21, 2025
CVE-2025-2607
6.3 MEDIUM

A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mar 21, 2025
CVE-2025-2606
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 21, 2025
CVE-2025-2604
6.3 MEDIUM

A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 21, 2025
CVE-2025-2603
6.3 MEDIUM

A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the …

Mar 21, 2025
CVE-2025-2602
6.3 MEDIUM

A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Mar 21, 2025
CVE-2025-2601
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the …

Mar 21, 2025
CVE-2025-25036
6.8 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8).

Mar 21, 2025
CVE-2025-29227
6.3 MEDIUM

In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.

Mar 21, 2025
CVE-2025-29226
6.3 MEDIUM

In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.

Mar 21, 2025
CVE-2025-29223
6.3 MEDIUM

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.

Mar 21, 2025
CVE-2023-43029
6.8 MEDIUM

IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment.

Mar 21, 2025
CVE-2019-16151
4.7 MEDIUM

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker …

Mar 21, 2025
CVE-2025-30168
6.9 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd …

Mar 21, 2025
CVE-2025-30157
6.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a …

Mar 21, 2025
CVE-2025-2598
5.5 MEDIUM

When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property …

Mar 21, 2025
CVE-2025-2593
6.3 MEDIUM

A vulnerability has been found in FastCMS up to 0.1.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Mar 21, 2025
CVE-2025-29640
5.4 MEDIUM

Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-report.php via the parameter searchdata..

Mar 21, 2025
CVE-2025-27612
5.9 MEDIUM

libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of capabilities to …

Mar 21, 2025
CVE-2021-25635
5.5 MEDIUM

An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify …

Mar 21, 2025
CVE-2025-2592
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the …

Mar 21, 2025
CVE-2025-2591
4.3 MEDIUM

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The …

Mar 21, 2025
CVE-2025-2589
5.5 MEDIUM

A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. …

Mar 21, 2025
CVE-2025-2597
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability could allow an attacker to execute malicious Javascript code via GET …

Mar 21, 2025
CVE-2025-2587
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Jinher OA C6 1.0. This affects an unknown part of the file IncentivePlanFulfillAppprove.aspx. The manipulation …

Mar 21, 2025
CVE-2025-30179
4.3 MEDIUM

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass …

Mar 21, 2025
CVE-2025-27933
5.4 MEDIUM

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to …

Mar 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.