CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13827
6.1 MEDIUM

The Razorpay Subscription Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg() and remove_query_arg() functions without …

Mar 5, 2025
CVE-2024-13350
6.4 MEDIUM

The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, …

Mar 5, 2025
CVE-2025-27679
6.1 MEDIUM

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scripting in Badge Registration V-2023-005.

Mar 5, 2025
CVE-2025-27676
6.1 MEDIUM

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scripting in Reports V-2023-002.

Mar 5, 2025
CVE-2025-27660
5.4 MEDIUM

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross Site Scripting OVE-20230524-0003.

Mar 5, 2025
CVE-2025-27654
6.1 MEDIUM

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Cross Site Scripting (XSS) V-2023-017.

Mar 5, 2025
CVE-2025-27653
6.1 MEDIUM

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Preauthenticated Cross Site Scripting (XSS): Badge Registration V-2023-012.

Mar 5, 2025
CVE-2025-27637
6.1 MEDIUM

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016.

Mar 5, 2025
CVE-2025-1923
4.3 MEDIUM

Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform …

Mar 5, 2025
CVE-2025-1922
4.3 MEDIUM

Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI …

Mar 5, 2025
CVE-2025-1921
6.5 MEDIUM

Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML …

Mar 5, 2025
CVE-2025-1917
4.3 MEDIUM

Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML …

Mar 5, 2025
CVE-2024-0141
6.8 MEDIUM

NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to write …

Mar 5, 2025
CVE-2025-21092
6.5 MEDIUM

GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in an attacker being able to escalate …

Mar 5, 2025
CVE-2025-20002
5.3 MEDIUM

After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information disclosure

Mar 5, 2025
CVE-2025-1961
6.3 MEDIUM

A vulnerability has been found in SourceCodester Best Church Management Software 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 4, 2025
CVE-2025-1958
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The …

Mar 4, 2025
CVE-2025-26318
5.8 MEDIUM

hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.

Mar 4, 2025
CVE-2024-9135
5.3 MEDIUM

On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result …

Mar 4, 2025
CVE-2024-8000
5.3 MEDIUM

On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in …

Mar 4, 2025
CVE-2025-26202
4.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An …

Mar 4, 2025
CVE-2025-1969
4.3 MEDIUM

Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof …

Mar 4, 2025
CVE-2025-1949
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the …

Mar 4, 2025
CVE-2025-1947
6.3 MEDIUM

A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The …

Mar 4, 2025
CVE-2025-1946
6.3 MEDIUM

A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function exportPDF …

Mar 4, 2025
CVE-2020-3122
5.3 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain …

Mar 4, 2025
CVE-2019-1815
5.3 MEDIUM

A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals …

Mar 4, 2025
CVE-2025-27402
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An …

Mar 4, 2025
CVE-2025-27401
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited …

Mar 4, 2025
CVE-2025-27156
4.1 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the …

Mar 4, 2025
CVE-2025-27155
6.1 MEDIUM

Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone …

Mar 4, 2025
CVE-2025-27150
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from …

Mar 4, 2025
CVE-2025-26182
6.5 MEDIUM

An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file

Mar 4, 2025
CVE-2025-26091
4.6 MEDIUM

A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web …

Mar 4, 2025
CVE-2025-26320
6.5 MEDIUM

t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.

Mar 4, 2025
CVE-2025-27426
5.4 MEDIUM

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for …

Mar 4, 2025
CVE-2025-27425
4.3 MEDIUM

Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation …

Mar 4, 2025
CVE-2025-27424
4.3 MEDIUM

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox …

Mar 4, 2025
CVE-2025-1938
6.5 MEDIUM

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and …

Mar 4, 2025
CVE-2025-1935
4.3 MEDIUM

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in …

Mar 4, 2025
CVE-2025-1934
6.5 MEDIUM

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting …

Mar 4, 2025
CVE-2025-1925
5.3 MEDIUM

A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of …

Mar 4, 2025
CVE-2025-0958
5.4 MEDIUM

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9. This makes …

Mar 4, 2025
CVE-2025-0370
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, …

Mar 4, 2025
CVE-2025-26849
4.3 MEDIUM

There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain …

Mar 4, 2025
CVE-2025-0512
6.4 MEDIUM

The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and …

Mar 4, 2025
CVE-2025-0433
6.4 MEDIUM

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Mar 4, 2025
CVE-2024-9618
6.4 MEDIUM

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Mar 4, 2025
CVE-2024-13724
4.3 MEDIUM

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in …

Mar 4, 2025
CVE-2024-13682
4.3 MEDIUM

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.