CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13546
4.3 MEDIUM

The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.1 via the 'get_image_description' function. This makes …

Mar 1, 2025
CVE-2025-1291
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icon’ parameter …

Mar 1, 2025
CVE-2024-13697
4.8 MEDIUM

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions …

Mar 1, 2025
CVE-2024-13806
6.5 MEDIUM

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to …

Mar 1, 2025
CVE-2025-1730
6.5 MEDIUM

The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This …

Mar 1, 2025
CVE-2025-1502
5.3 MEDIUM

The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'download_ip2location_redirection_backup' AJAX action in …

Mar 1, 2025
CVE-2025-1459
6.4 MEDIUM

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and …

Mar 1, 2025
CVE-2024-13901
4.4 MEDIUM

The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the …

Mar 1, 2025
CVE-2025-0820
6.4 MEDIUM

The Clicface Trombi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nom’ parameter in all versions up to, and including, 2.08 due …

Mar 1, 2025
CVE-2024-9217
6.1 MEDIUM

The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Mar 1, 2025
CVE-2024-9212
6.1 MEDIUM

The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Mar 1, 2025
CVE-2024-13750
6.5 MEDIUM

The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and …

Mar 1, 2025
CVE-2024-13746
6.5 MEDIUM

The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on the …

Mar 1, 2025
CVE-2024-13559
6.4 MEDIUM

The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wishlist_table' shortcode in all versions up to, and including, 3.2.9 …

Mar 1, 2025
CVE-2024-13518
4.3 MEDIUM

The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.12. This is due to missing …

Mar 1, 2025
CVE-2025-1780
4.3 MEDIUM

The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Mar 1, 2025
CVE-2024-13358
4.3 MEDIUM

The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Mar 1, 2025
CVE-2025-23118
6.4 MEDIUM

An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the …

Mar 1, 2025
CVE-2025-23117
6.8 MEDIUM

An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to …

Mar 1, 2025
CVE-2025-25478
6.5 MEDIUM

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web …

Feb 28, 2025
CVE-2025-25476
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious …

Feb 28, 2025
CVE-2025-26466
5.9 MEDIUM

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer …

Feb 28, 2025
CVE-2025-27413
6.5 MEDIUM

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an administrator to import raw data into the database, …

Feb 28, 2025
CVE-2025-27410
6.5 MEDIUM

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, …

Feb 28, 2025
CVE-2025-25429
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.

Feb 28, 2025
CVE-2025-27408
4.8 MEDIUM

Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifest employs a weak password hashing implementation that uses SHA3 without a salt. …

Feb 28, 2025
CVE-2025-25431
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.

Feb 28, 2025
CVE-2025-25430
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.

Feb 28, 2025
CVE-2025-24843
5.1 MEDIUM

Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.

Feb 28, 2025
CVE-2025-24318
6.8 MEDIUM

Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.

Feb 28, 2025
CVE-2025-24316
5.3 MEDIUM

The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality.

Feb 28, 2025
CVE-2025-23405
5.3 MEDIUM

Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).

Feb 28, 2025
CVE-2025-20049
5.8 MEDIUM

The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.

Feb 28, 2025
CVE-2025-0985
5.5 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local …

Feb 28, 2025
CVE-2024-54175
5.5 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an …

Feb 28, 2025
CVE-2025-26263
5.1 MEDIUM

GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to improper memory handling in …

Feb 28, 2025
CVE-2025-26047
5.1 MEDIUM

Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.

Feb 28, 2025
CVE-2025-25461
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a malicious XSS …

Feb 28, 2025
CVE-2024-44754
6.8 MEDIUM

Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut …

Feb 28, 2025
CVE-2025-25916
5.4 MEDIUM

wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.

Feb 28, 2025
CVE-2025-1776
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to execute arbitrary code via the ‘query’ parameter in /app-google-custom-search/searchResults. …

Feb 28, 2025
CVE-2025-1749
4.7 MEDIUM

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending …

Feb 28, 2025
CVE-2025-1748
4.7 MEDIUM

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending …

Feb 28, 2025
CVE-2025-1747
4.7 MEDIUM

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending …

Feb 28, 2025
CVE-2025-1746
6.1 MEDIUM

Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the …

Feb 28, 2025
CVE-2025-1300
6.1 MEDIUM

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open …

Feb 28, 2025
CVE-2024-10860
4.3 MEDIUM

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data due to a missing capability check …

Feb 28, 2025
CVE-2025-22492
6.3 MEDIUM

The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative …

Feb 28, 2025
CVE-2025-22491
6.7 MEDIUM

The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript …

Feb 28, 2025
CVE-2025-1662
6.4 MEDIUM

The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.0 via the 'url_media_uploader_url_upload' action. …

Feb 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.