CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1560
6.4 MEDIUM

The WOW Entrance Effects (WEE!) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wee' shortcode in all versions up to, and …

Feb 28, 2025
CVE-2024-9019
6.4 MEDIUM

The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's secupress_check_ban_ips_form shortcode in all versions up to, …

Feb 28, 2025
CVE-2024-13851
5.5 MEDIUM

The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.7.4.2 due to insufficient input sanitization …

Feb 28, 2025
CVE-2024-13832
4.3 MEDIUM

The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' …

Feb 28, 2025
CVE-2024-13716
4.3 MEDIUM

The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_settings_callback() function in all …

Feb 28, 2025
CVE-2024-13638
5.9 MEDIUM

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' …

Feb 28, 2025
CVE-2024-13469
6.4 MEDIUM

The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and including, …

Feb 28, 2025
CVE-2025-1572
6.5 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up …

Feb 28, 2025
CVE-2025-1571
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all …

Feb 28, 2025
CVE-2025-1405
6.4 MEDIUM

The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_products shortcode in all versions up to, and including, …

Feb 28, 2025
CVE-2025-0764
6.5 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class …

Feb 28, 2025
CVE-2025-1511
6.1 MEDIUM

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the …

Feb 28, 2025
CVE-2025-1506
4.3 MEDIUM

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. …

Feb 28, 2025
CVE-2024-12820
6.4 MEDIUM

The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' shortcode in all versions up to, and including, …

Feb 28, 2025
CVE-2025-1757
6.4 MEDIUM

The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pfhub_portfolio' and 'pfhub_portfolio_portfolio' shortcodes in all …

Feb 28, 2025
CVE-2025-1505
6.1 MEDIUM

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, …

Feb 28, 2025
CVE-2025-0801
4.3 MEDIUM

The RateMyAgent Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing …

Feb 28, 2025
CVE-2024-13796
5.3 MEDIUM

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 …

Feb 28, 2025
CVE-2025-23225
6.5 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the …

Feb 28, 2025
CVE-2025-0823
6.5 MEDIUM

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could …

Feb 28, 2025
CVE-2024-56340
6.5 MEDIUM

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal …

Feb 28, 2025
CVE-2024-54173
4.7 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local …

Feb 28, 2025
CVE-2025-25728
6.5 MEDIUM

Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers …

Feb 28, 2025
CVE-2025-25727
6.2 MEDIUM

Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.

Feb 28, 2025
CVE-2025-1681
5.4 MEDIUM

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename …

Feb 28, 2025
CVE-2025-24832
5.5 MEDIUM

Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM …

Feb 27, 2025
CVE-2025-25730
4.6 MEDIUM

An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control …

Feb 27, 2025
CVE-2024-38290
5.3 MEDIUM

In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.

Feb 27, 2025
CVE-2025-21824
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix a use of uninitialized mutex commit c8347f915e67 ("gpu: host1x: Fix boot regression …

Feb 27, 2025
CVE-2025-21823
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: batman-adv: Drop unmanaged ELP metric worker The ELP worker needs to calculate new metric values …

Feb 27, 2025
CVE-2025-21822
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: Set driver data before its usage If vmclock_ptp_register() fails during probing, vmclock_remove() is …

Feb 27, 2025
CVE-2025-21821
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbdev: omap: use threaded IRQ for LCD DMA When using touchscreen and framebuffer, Nokia 770 …

Feb 27, 2025
CVE-2025-21820
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tty: xilinx_uartps: split sysrq handling lockdep detects the following circular locking dependency: CPU 0 CPU …

Feb 27, 2025
CVE-2025-21819
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd/display: Use HW lock mgr for PSR1" This reverts commit a2b5a9956269 ("drm/amd/display: Use HW …

Feb 27, 2025
CVE-2025-21817
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: mark GFP_NOIO around sysfs ->store() sysfs ->store is called with queue freezed, meantime we …

Feb 27, 2025
CVE-2025-21816
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hrtimers: Force migrate away hrtimers queued after CPUHP_AP_HRTIMERS_DYING hrtimers are migrated away from the dying …

Feb 27, 2025
CVE-2025-21814
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ptp: Ensure info->enable callback is always set The ioctl and sysfs handlers unconditionally call the …

Feb 27, 2025
CVE-2025-21813
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: timers/migration: Fix off-by-one root mis-connection Before attaching a new root to the old root, the …

Feb 27, 2025
CVE-2025-21810
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: driver core: class: Fix wild pointer dereferences in API class_dev_iter_next() There are a potential wild …

Feb 27, 2025
CVE-2025-21809
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc, afs: Fix peer hash locking vs RCU callback In its address list, afs now …

Feb 27, 2025
CVE-2025-21808
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: xdp: Disallow attaching device-bound programs in generic mode Device-bound programs are used to support …

Feb 27, 2025
CVE-2025-21807
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix queue freeze vs limits lock order in sysfs store methods queue_attr_store() always freezes …

Feb 27, 2025
CVE-2025-21806
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: let net.core.dev_weight always be non-zero The following problem was encountered during stability test: (NULL …

Feb 27, 2025
CVE-2025-21805
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the …

Feb 27, 2025
CVE-2025-21804
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: rcar-ep: Fix incorrect variable used when calling devm_request_mem_region() The rcar_pcie_parse_outbound_ranges() uses the devm_request_mem_region() macro …

Feb 27, 2025
CVE-2025-21803
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix warnings during S3 suspend The enable_gpe_wakeup() function calls acpi_enable_all_wakeup_gpes(), and the later one …

Feb 27, 2025
CVE-2025-21802
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix oops when unload drivers paralleling When unload hclge driver, it tries to …

Feb 27, 2025
CVE-2025-21801
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ravb: Fix missing rtnl lock in suspend/resume path Fix the suspend/resume path by ensuring …

Feb 27, 2025
CVE-2025-21799
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: fix freeing IRQ in am65_cpsw_nuss_remove_tx_chns() When getting the IRQ we use …

Feb 27, 2025
CVE-2025-21798
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firewire: test: Fix potential null dereference in firewire kunit test kunit_kzalloc() may return a NULL …

Feb 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.