CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29032
5.9 MEDIUM

Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.

Mar 14, 2025
CVE-2025-26626
6.5 MEDIUM

The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software package. Versions prior to 1.5.0 …

Mar 14, 2025
CVE-2024-13772
5.6 MEDIUM

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, …

Mar 14, 2025
CVE-2025-1507
5.3 MEDIUM

The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() …

Mar 14, 2025
CVE-2025-1526
6.4 MEDIUM

The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Display Widget (countdown feature) in all versions up …

Mar 14, 2025
CVE-2024-13407
4.3 MEDIUM

The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to insufficient …

Mar 14, 2025
CVE-2025-2289
4.3 MEDIUM

The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoints in …

Mar 14, 2025
CVE-2025-2166
6.1 MEDIUM

The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use …

Mar 14, 2025
CVE-2025-1528
4.3 MEDIUM

The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_meta_values' function …

Mar 14, 2025
CVE-2025-1285
5.3 MEDIUM

The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and …

Mar 14, 2025
CVE-2025-0955
5.3 MEDIUM

The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'vidorev_import_single_video' AJAX action in all versions …

Mar 14, 2025
CVE-2025-30022
6.8 MEDIUM

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.

Mar 14, 2025
CVE-2024-55060
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a …

Mar 13, 2025
CVE-2025-25363
6.5 MEDIUM

An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator …

Mar 13, 2025
CVE-2024-30143
4.3 MEDIUM

HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. …

Mar 13, 2025
CVE-2025-29773
5.8 MEDIUM

Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the …

Mar 13, 2025
CVE-2025-29768
4.4 MEDIUM

Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is …

Mar 13, 2025
CVE-2025-28011
6.1 MEDIUM

A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code …

Mar 13, 2025
CVE-2025-27103
6.5 MEDIUM

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users …

Mar 13, 2025
CVE-2025-24974
6.5 MEDIUM

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the …

Mar 13, 2025
CVE-2025-1767
6.5 MEDIUM

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the …

Mar 13, 2025
CVE-2024-9042
5.9 MEDIUM

This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed …

Mar 13, 2025
CVE-2025-28015
5.3 MEDIUM

A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers …

Mar 13, 2025
CVE-2025-28010
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript …

Mar 13, 2025
CVE-2024-57062
6.7 MEDIUM

An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component.

Mar 13, 2025
CVE-2025-25625
5.4 MEDIUM

A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2, which allows an authenticated web interface user …

Mar 13, 2025
CVE-2024-55198
5.3 MEDIUM

User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users …

Mar 13, 2025
CVE-2024-57348
6.1 MEDIUM

Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary code via the crafted payload to the hostname, sitegroupid, …

Mar 13, 2025
CVE-2024-28803
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter

Mar 13, 2025
CVE-2024-22880
4.7 MEDIUM

Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary code via a crafted script to the webchat …

Mar 13, 2025
CVE-2025-2278
6.5 MEDIUM

Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about …

Mar 13, 2025
CVE-2025-1636
6.5 MEDIUM

Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user …

Mar 13, 2025
CVE-2025-1635
6.5 MEDIUM

Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows a user exporting a …

Mar 13, 2025
CVE-2025-21104
4.3 MEDIUM

Dell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redirect') Vulnerability in NetWorker Management Console. An unauthenticated …

Mar 13, 2025
CVE-2025-1785
5.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes …

Mar 13, 2025
CVE-2025-1257
6.5 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A …

Mar 13, 2025
CVE-2025-0652
4.3 MEDIUM

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions …

Mar 13, 2025
CVE-2024-13054
6.5 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of …

Mar 13, 2025
CVE-2024-12380
4.4 MEDIUM

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting …

Mar 13, 2025
CVE-2020-36843
4.3 MEDIUM

The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message …

Mar 13, 2025
CVE-2025-2104
4.3 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the …

Mar 13, 2025
CVE-2025-1503
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Roundup Recipe Name field in all versions up to, and …

Mar 13, 2025
CVE-2025-2250
4.9 MEDIUM

The WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all …

Mar 13, 2025
CVE-2024-13887
5.3 MEDIUM

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Mar 13, 2025
CVE-2025-1559
6.4 MEDIUM

The CC-IMG-Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'img' shortcode in all versions up to, and including, 1.1.0 due …

Mar 13, 2025
CVE-2024-13703
4.3 MEDIUM

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Mar 13, 2025
CVE-2025-22870
4.4 MEDIUM

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is …

Mar 12, 2025
CVE-2025-27017
6.5 MEDIUM

Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during …

Mar 12, 2025
CVE-2025-25774
6.5 MEDIUM

An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may …

Mar 12, 2025
CVE-2025-25683
5.6 MEDIUM

AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects AlekSIS-Core 3.0, 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, …

Mar 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.