CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12607
6.5 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all …

Mar 7, 2025
CVE-2025-0863
6.4 MEDIUM

The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, …

Mar 7, 2025
CVE-2024-12576
5.5 MEDIUM

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU …

Mar 7, 2025
CVE-2024-12809
6.4 MEDIUM

The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due …

Mar 7, 2025
CVE-2025-27796
4.5 MEDIUM

ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.

Mar 7, 2025
CVE-2025-27795
4.3 MEDIUM

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

Mar 7, 2025
CVE-2025-2061
4.3 MEDIUM

A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Mar 7, 2025
CVE-2025-26708
4.2 MEDIUM

There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the …

Mar 7, 2025
CVE-2025-2054
4.7 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 7, 2025
CVE-2025-0748
4.3 MEDIUM

The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect …

Mar 7, 2025
CVE-2024-13526
4.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on …

Mar 7, 2025
CVE-2025-2053
6.3 MEDIUM

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Mar 7, 2025
CVE-2025-2052
6.3 MEDIUM

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /forgot-password.php. …

Mar 7, 2025
CVE-2025-2051
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-visitor.php. …

Mar 7, 2025
CVE-2025-1121
6.8 MEDIUM

Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code …

Mar 7, 2025
CVE-2025-2046
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 6, 2025
CVE-2025-2044
4.7 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 6, 2025
CVE-2025-2043
4.7 MEDIUM

A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component …

Mar 6, 2025
CVE-2025-2042
4.3 MEDIUM

A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. …

Mar 6, 2025
CVE-2025-2041
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file …

Mar 6, 2025
CVE-2024-57972
6.5 MEDIUM

The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause …

Mar 6, 2025
CVE-2025-2040
6.3 MEDIUM

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation …

Mar 6, 2025
CVE-2025-2039
4.7 MEDIUM

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/delete_members.php. The …

Mar 6, 2025
CVE-2025-2037
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Mar 6, 2025
CVE-2025-2036
6.3 MEDIUM

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation …

Mar 6, 2025
CVE-2025-27600
6.5 MEDIUM

FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP verification, an attacker can initiate an …

Mar 6, 2025
CVE-2025-27506
5.4 MEDIUM

NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId …

Mar 6, 2025
CVE-2025-26699
5.0 MEDIUM

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject …

Mar 6, 2025
CVE-2025-25294
5.3 MEDIUM

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to …

Mar 6, 2025
CVE-2025-25191
5.4 MEDIUM

Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before …

Mar 6, 2025
CVE-2025-2035
6.3 MEDIUM

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /customer_register.php. The …

Mar 6, 2025
CVE-2025-2033
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /user_dashboard/view_donor.php. …

Mar 6, 2025
CVE-2025-21834
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: seccomp: passthrough uretprobe systemcall without filtering When attaching uretprobes to processes running inside docker, the …

Mar 6, 2025
CVE-2025-21833
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE There is a WARN_ON_ONCE to catch an unlikely …

Mar 6, 2025
CVE-2025-21832
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: don't revert iter for -EIOCBQUEUED blkdev_read_iter() has a few odd checks, like gating the …

Mar 6, 2025
CVE-2025-21831
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1 commit 9d26d3a8f1b0 ("PCI: …

Mar 6, 2025
CVE-2025-21830
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: landlock: Handle weird files A corrupted filesystem (e.g. bcachefs) might return weird files. Instead of …

Mar 6, 2025
CVE-2025-21829
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix the warning "__rxe_cleanup+0x12c/0x170 [rdma_rxe]" The Call Trace is as below: " <TASK> ? …

Mar 6, 2025
CVE-2025-0337
6.5 MEDIUM

ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability, if exploited, potentially could enable …

Mar 6, 2025
CVE-2024-58086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Stop active perfmon if it is being destroyed If the active performance monitor (`v3d->active_perfmon`) …

Mar 6, 2025
CVE-2024-58085
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tomoyo: don't emit warning in tomoyo_write_control() syzbot is reporting too large allocation warning at tomoyo_write_control(), …

Mar 6, 2025
CVE-2024-58084
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qcom_scm_get_tzmem_pool() Commit 2e4955167ec5 ("firmware: qcom: scm: Fix …

Mar 6, 2025
CVE-2024-58082
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: nuvoton: Fix an error check in npcm_video_ece_init() When function of_find_device_by_node() fails, it returns NULL …

Mar 6, 2025
CVE-2024-58081
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: mmp2: call pm_genpd_init() only after genpd.name is set Setting the genpd's struct device's name …

Mar 6, 2025
CVE-2024-58080
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: qcom: dispcc-sm6350: Add missing parent_map for a clock If a clk_rcg2 has a parent, …

Mar 6, 2025
CVE-2024-58079
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix crash during unbind if gpio unit is in use We used the …

Mar 6, 2025
CVE-2024-58078
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: misc: misc_minor_alloc to use ida for all dynamic/misc dynamic minors misc_minor_alloc was allocating id using …

Mar 6, 2025
CVE-2024-58077
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-pcm: don't use soc_pcm_ret() on .prepare callback commit 1f5664351410 ("ASoC: lower "no backend DAIs …

Mar 6, 2025
CVE-2024-58076
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gcc-sm6350: Add missing parent_map for two clocks If a clk_rcg2 has a parent, …

Mar 6, 2025
CVE-2025-2031
6.3 MEDIUM

A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/upload. The manipulation of …

Mar 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.