CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13825
6.1 MEDIUM

The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 8, 2025
CVE-2024-12119
6.4 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter …

Mar 8, 2025
CVE-2024-12114
4.3 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Mar 8, 2025
CVE-2024-13640
5.9 MEDIUM

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 …

Mar 8, 2025
CVE-2025-1504
4.3 MEDIUM

The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2 via the 'pl_autocomplete' AJAX action due …

Mar 8, 2025
CVE-2025-1481
6.5 MEDIUM

The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in …

Mar 8, 2025
CVE-2024-13895
4.3 MEDIUM

The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due …

Mar 8, 2025
CVE-2024-13774
6.1 MEDIUM

The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. …

Mar 8, 2025
CVE-2024-12460
6.4 MEDIUM

The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'years-since' shortcode in all versions up to, …

Mar 8, 2025
CVE-2025-1261
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all …

Mar 8, 2025
CVE-2025-2096
6.3 MEDIUM

A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Mar 7, 2025
CVE-2025-2095
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Mar 7, 2025
CVE-2025-2094
6.3 MEDIUM

A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file …

Mar 7, 2025
CVE-2025-27826
6.4 MEDIUM

An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.

Mar 7, 2025
CVE-2025-27825
6.4 MEDIUM

An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.

Mar 7, 2025
CVE-2025-27824
6.4 MEDIUM

An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficiently sanitize input before displaying results to …

Mar 7, 2025
CVE-2025-27823
6.4 MEDIUM

An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdrop CMS. It enables a website to obfuscate email addresses, and should prevent …

Mar 7, 2025
CVE-2025-26643
5.4 MEDIUM

The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Mar 7, 2025
CVE-2024-53698
4.9 MEDIUM

A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Mar 7, 2025
CVE-2024-53696
4.9 MEDIUM

A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator …

Mar 7, 2025
CVE-2024-53692
4.7 MEDIUM

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Mar 7, 2025
CVE-2024-50405
5.5 MEDIUM

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Mar 7, 2025
CVE-2024-13086
5.3 MEDIUM

An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of …

Mar 7, 2025
CVE-2023-43052
5.3 MEDIUM

IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could …

Mar 7, 2025
CVE-2023-35894
5.4 MEDIUM

IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow …

Mar 7, 2025
CVE-2025-27152
5.3 MEDIUM

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. …

Mar 7, 2025
CVE-2025-25617
4.3 MEDIUM

Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.

Mar 7, 2025
CVE-2025-2090
4.7 MEDIUM

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Mar 7, 2025
CVE-2025-2089
5.4 MEDIUM

A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUserInfo of the file /personal/updateInfo …

Mar 7, 2025
CVE-2025-1768
6.5 MEDIUM

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to, and …

Mar 7, 2025
CVE-2024-12634
6.1 MEDIUM

The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Mar 7, 2025
CVE-2024-9458
4.8 MEDIUM

The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 7, 2025
CVE-2024-13857
5.5 MEDIUM

The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Mar 7, 2025
CVE-2024-13805
6.4 MEDIUM

The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File …

Mar 7, 2025
CVE-2024-13635
4.3 MEDIUM

The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. …

Mar 7, 2025
CVE-2024-13552
4.3 MEDIUM

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Mar 7, 2025
CVE-2025-21843
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_dev_query() 'priorities_info' is uninitialized, and the uninitialized value is copied …

Mar 7, 2025
CVE-2025-21842
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to init user queue The destructor of a gtt …

Mar 7, 2025
CVE-2025-21841
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting amd_pstate_update_limits() takes a cpufreq_policy reference but doesn't decrement the refcount …

Mar 7, 2025
CVE-2025-21840
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/netlink: Prevent userspace segmentation fault by adjusting UAPI header The intel-lpmd tool [1], which uses …

Mar 7, 2025
CVE-2025-21839
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop Move the conditional …

Mar 7, 2025
CVE-2025-21838
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: flush gadget workqueue after device removal device_del() can lead to new work …

Mar 7, 2025
CVE-2025-21836
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it …

Mar 7, 2025
CVE-2025-21835
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, …

Mar 7, 2025
CVE-2024-13904
5.3 MEDIUM

The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' …

Mar 7, 2025
CVE-2024-13781
6.5 MEDIUM

The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due …

Mar 7, 2025
CVE-2024-13431
6.1 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter …

Mar 7, 2025
CVE-2024-12611
5.3 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and …

Mar 7, 2025
CVE-2024-12610
5.3 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' …

Mar 7, 2025
CVE-2024-12609
6.5 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, …

Mar 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.