CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2342
5.3 MEDIUM

A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the …

Mar 16, 2025
CVE-2025-2339
5.3 MEDIUM

A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs. The …

Mar 16, 2025
CVE-2025-2338
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulation leads …

Mar 16, 2025
CVE-2025-2337
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in tbeu matio 1.5.28. This issue affects the function Mat_VarPrint of the file src/mat.c. The …

Mar 16, 2025
CVE-2025-1621
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1620
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1619
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2024-13602
4.8 MEDIUM

The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 16, 2025
CVE-2024-13126
4.6 MEDIUM

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

Mar 16, 2025
CVE-2025-24856
4.2 MEDIUM

An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading …

Mar 16, 2025
CVE-2024-58103
5.8 MEDIUM

Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.

Mar 16, 2025
CVE-2025-30077
6.2 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits.

Mar 16, 2025
CVE-2025-2334
5.4 MEDIUM

A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat …

Mar 15, 2025
CVE-2025-26940
6.3 MEDIUM

Path Traversal vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.

Mar 15, 2025
CVE-2025-26924
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Ohio Extra: from n/a through <= …

Mar 15, 2025
CVE-2025-26899
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce recapture-for-woocommerce allows Cross Site Request Forgery.This issue affects Recapture for …

Mar 15, 2025
CVE-2025-26895
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maennchen1.de m1.DownloadList m1downloadlist allows DOM-Based XSS.This issue affects m1.DownloadList: from n/a through <= …

Mar 15, 2025
CVE-2025-25225
6.5 MEDIUM

A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions.

Mar 15, 2025
CVE-2025-2323
4.3 MEDIUM

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of …

Mar 15, 2025
CVE-2025-2321
6.3 MEDIUM

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this issue is some unknown functionality of the file /api/mjkj-chat/cgform-api/addData/. The …

Mar 15, 2025
CVE-2025-2025
6.5 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Mar 15, 2025
CVE-2025-1530
4.3 MEDIUM

The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9. This is due to missing nonce …

Mar 15, 2025
CVE-2025-1057
4.3 MEDIUM

A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries …

Mar 15, 2025
CVE-2019-25222
4.9 MEDIUM

The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due …

Mar 15, 2025
CVE-2025-1773
6.1 MEDIUM

The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient …

Mar 15, 2025
CVE-2025-2267
6.5 MEDIUM

The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check …

Mar 15, 2025
CVE-2025-2164
6.1 MEDIUM

The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' parameters in all versions up to, and including, 0.8.2 …

Mar 15, 2025
CVE-2025-2163
6.1 MEDIUM

The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missing …

Mar 15, 2025
CVE-2025-1670
6.5 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, …

Mar 15, 2025
CVE-2025-1669
6.5 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, and including, …

Mar 15, 2025
CVE-2025-1668
4.3 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the wpsp_DeleteUser() function …

Mar 15, 2025
CVE-2024-12336
6.5 MEDIUM

The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Mar 15, 2025
CVE-2025-2310
5.3 MEDIUM

A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation …

Mar 14, 2025
CVE-2025-2309
5.3 MEDIUM

A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__bit_copy of the component Type Conversion Logic. The …

Mar 14, 2025
CVE-2025-2308
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_decompress_one_byte of the component Scale-Offset Filter. The manipulation leads …

Mar 14, 2025
CVE-2025-29782
5.4 MEDIUM

WeGIA is Web manager for charitable institutions A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_tipo_docs_atendido.php` endpoint in versions of the WeGIA application …

Mar 14, 2025
CVE-2024-29409
5.5 MEDIUM

File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.

Mar 14, 2025
CVE-2024-12020
6.1 MEDIUM

There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a …

Mar 14, 2025
CVE-2025-27606
5.1 MEDIUM

Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user …

Mar 14, 2025
CVE-2025-1888
4.6 MEDIUM

The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within …

Mar 14, 2025
CVE-2024-55594
5.6 MEDIUM

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows …

Mar 14, 2025
CVE-2025-25873
5.5 MEDIUM

Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function

Mar 14, 2025
CVE-2025-25872
5.5 MEDIUM

An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

Mar 14, 2025
CVE-2024-40585
6.5 MEDIUM

An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and …

Mar 14, 2025
CVE-2023-48785
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on …

Mar 14, 2025
CVE-2023-33300
5.3 MEDIUM

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, …

Mar 14, 2025
CVE-2024-47573
6.5 MEDIUM

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 …

Mar 14, 2025
CVE-2024-45643
5.9 MEDIUM

IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.

Mar 14, 2025
CVE-2024-45638
4.1 MEDIUM

IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.

Mar 14, 2025
CVE-2024-40590
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to …

Mar 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.