CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20920
5.5 MEDIUM

Out-of-bounds read in action link data in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20919
5.5 MEDIUM

Out-of-bounds read in applying binary of video content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20918
5.5 MEDIUM

Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20917
5.5 MEDIUM

Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20916
5.5 MEDIUM

Out-of-bounds read in reading string of SPen in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20915
5.5 MEDIUM

Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20914
5.5 MEDIUM

Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20913
5.5 MEDIUM

Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20912
6.2 MEDIUM

Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.

Mar 6, 2025
CVE-2025-20911
4.4 MEDIUM

Improper access control in sem_wifi service prior to SMR Mar-2025 Release 1 allows privileged local attackers to update MAC address of Galaxy Watch.

Mar 6, 2025
CVE-2025-20910
6.2 MEDIUM

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

Mar 6, 2025
CVE-2025-20909
4.0 MEDIUM

Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.

Mar 6, 2025
CVE-2025-20908
6.5 MEDIUM

Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.

Mar 6, 2025
CVE-2025-1979
6.4 MEDIUM

Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in …

Mar 6, 2025
CVE-2025-27625
4.3 MEDIUM

In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by …

Mar 5, 2025
CVE-2025-27624
5.4 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of …

Mar 5, 2025
CVE-2025-27623
4.3 MEDIUM

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, …

Mar 5, 2025
CVE-2025-27622
4.3 MEDIUM

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, …

Mar 5, 2025
CVE-2025-25634
6.5 MEDIUM

A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to …

Mar 5, 2025
CVE-2024-48246
5.4 MEDIUM

Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.

Mar 5, 2025
CVE-2025-20208
4.6 MEDIUM

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) …

Mar 5, 2025
CVE-2025-27412
6.1 MEDIUM

REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected cross-site scripting (XSS) on the page of …

Mar 5, 2025
CVE-2025-27411
5.4 MEDIUM

REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5.18.3.

Mar 5, 2025
CVE-2025-24521
4.9 MEDIUM

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues …

Mar 5, 2025
CVE-2025-23416
4.9 MEDIUM

Path traversal may lead to arbitrary file deletion. The score without least privilege principle violation is as calculated below. In combination with other issues it …

Mar 5, 2025
CVE-2025-21095
4.9 MEDIUM

Path traversal may lead to arbitrary file download. The score without least privilege principle violation is as calculated below. In combination with other issues it …

Mar 5, 2025
CVE-2025-1463
4.3 MEDIUM

The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. This is due to improper …

Mar 5, 2025
CVE-2024-13423
5.3 MEDIUM

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions …

Mar 5, 2025
CVE-2024-12650
5.4 MEDIUM

An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a …

Mar 5, 2025
CVE-2024-11153
5.3 MEDIUM

The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure …

Mar 5, 2025
CVE-2025-0954
6.5 MEDIUM

The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the json_import() and json_export() functions in …

Mar 5, 2025
CVE-2024-5667
6.4 MEDIUM

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js JavaScript library (versions 1.7.13 to 1.7.14) in various versions due …

Mar 5, 2025
CVE-2024-13839
6.1 MEDIUM

The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Mar 5, 2025
CVE-2024-13815
6.5 MEDIUM

The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the …

Mar 5, 2025
CVE-2024-13811
4.3 MEDIUM

The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing …

Mar 5, 2025
CVE-2024-13810
4.3 MEDIUM

The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Mar 5, 2025
CVE-2024-13809
6.5 MEDIUM

The Hero Slider - WordPress Slider Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, …

Mar 5, 2025
CVE-2024-13780
6.5 MEDIUM

The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in …

Mar 5, 2025
CVE-2024-13779
6.1 MEDIUM

The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'index' parameter in all versions …

Mar 5, 2025
CVE-2024-13778
6.5 MEDIUM

The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection via several functions in all versions up to, …

Mar 5, 2025
CVE-2024-13757
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_layer shortcode in all versions up …

Mar 5, 2025
CVE-2024-13747
4.3 MEDIUM

The WooMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'template_delete_saved' …

Mar 5, 2025
CVE-2024-12815
6.4 MEDIUM

The Point Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'point_maker' shortcode in all versions up to, and including, 0.1.6 …

Mar 5, 2025
CVE-2024-11731
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slider shortcode in all versions up …

Mar 5, 2025
CVE-2025-22493
5.6 MEDIUM

Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the …

Mar 5, 2025
CVE-2025-1435
6.3 MEDIUM

The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. This is due to missing or …

Mar 5, 2025
CVE-2025-1008
6.4 MEDIUM

The Recently Purchased Products For Woo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘view’ parameter in all versions up to, and …

Mar 5, 2025
CVE-2025-0990
4.3 MEDIUM

The I Am Gloria plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.4. This is due to …

Mar 5, 2025
CVE-2024-8682
5.3 MEDIUM

The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, …

Mar 5, 2025
CVE-2024-13866
6.4 MEDIUM

The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3 due to insufficient input sanitization …

Mar 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.