CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25797
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.

Feb 26, 2025
CVE-2025-25796
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.

Feb 26, 2025
CVE-2025-25794
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.

Feb 26, 2025
CVE-2025-25793
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.

Feb 26, 2025
CVE-2025-25792
4.4 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.

Feb 26, 2025
CVE-2025-25791
4.4 MEDIUM

An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.

Feb 26, 2025
CVE-2025-1249
5.3 MEDIUM

Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Events Manager: from n/a through …

Feb 26, 2025
CVE-2024-52925
6.8 MEDIUM

In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unlock Device feature for software encrypted …

Feb 26, 2025
CVE-2022-49732
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sock: redo the psock vs ULP protection check Commit 8a59f9d1e3d4 ("sock: Introduce sk->sk_prot->psock_update_sk_prot()") has moved …

Feb 26, 2025
CVE-2025-26925
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.

Feb 26, 2025
CVE-2025-0719
6.1 MEDIUM

IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript …

Feb 26, 2025
CVE-2025-1517
6.4 MEDIUM

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to …

Feb 26, 2025
CVE-2025-0731
6.5 MEDIUM

An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed …

Feb 26, 2025
CVE-2024-6810
4.4 MEDIUM

The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.1 due to insufficient input sanitization …

Feb 26, 2025
CVE-2024-13803
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in …

Feb 26, 2025
CVE-2024-13678
6.1 MEDIUM

The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13669
6.1 MEDIUM

The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13634
6.1 MEDIUM

The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13630
6.1 MEDIUM

The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13629
6.1 MEDIUM

The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13628
6.1 MEDIUM

The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 26, 2025
CVE-2024-13560
4.3 MEDIUM

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is …

Feb 26, 2025
CVE-2024-13113
5.9 MEDIUM

The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow …

Feb 26, 2025
CVE-2024-12737
6.1 MEDIUM

The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a parameter before outputting it back in …

Feb 26, 2025
CVE-2024-12434
5.3 MEDIUM

The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes …

Feb 26, 2025
CVE-2024-10563
5.4 MEDIUM

The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a …

Feb 26, 2025
CVE-2022-25773
4.3 MEDIUM

This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a …

Feb 26, 2025
CVE-2025-0236
5.3 MEDIUM

Out-of-bounds vulnerability in slope processing during curve rendering in Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic LIPSLX V4 …

Feb 26, 2025
CVE-2025-0235
5.3 MEDIUM

Out-of-bounds vulnerability due to improper memory release during image rendering in Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic …

Feb 26, 2025
CVE-2025-0234
5.3 MEDIUM

Out-of-bounds vulnerability in curve segmentation processing of Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic LIPSLX V4 Printer Driver.

Feb 26, 2025
CVE-2022-49731
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo() In an unlikely (and probably wrong?) case …

Feb 26, 2025
CVE-2022-49729
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfc: nfcmrvl: Fix memory leak in nfcmrvl_play_deferred Similar to the handling of play_deferred in commit …

Feb 26, 2025
CVE-2022-49728
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix signed integer overflow in __ip6_append_data Resurrect ubsan overflow checks and ubsan report this …

Feb 26, 2025
CVE-2022-49727
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg When len >= INT_MAX - transhdrlen, ulen = …

Feb 26, 2025
CVE-2022-49726
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clocksource: hyper-v: unexport __init-annotated hv_init_clocksource() EXPORT_SYMBOL and __init is a bad combination because the .init.text …

Feb 26, 2025
CVE-2022-49725
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix call trace in setup_tx_descriptors After PF reset and ethtool -t there was call …

Feb 26, 2025
CVE-2022-49723
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915/reset: Fix error_state_read ptr + offset use Fix our pointer offset usage in error_state_read when …

Feb 26, 2025
CVE-2022-49721
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: ftrace: consistently handle PLTs. Sometimes it is necessary to use a PLT entry to …

Feb 26, 2025
CVE-2022-49719
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic/realview: Fix refcount leak in realview_gic_of_init of_find_matching_node_and_match() returns a node pointer with refcount incremented, we …

Feb 26, 2025
CVE-2022-49718
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/apple-aic: Fix refcount leak in aic_of_ic_init of_get_child_by_name() returns a node pointer with refcount incremented, we …

Feb 26, 2025
CVE-2022-49717
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/apple-aic: Fix refcount leak in build_fiq_affinity of_find_node_by_phandle() returns a node pointer with refcount incremented, we …

Feb 26, 2025
CVE-2022-49716
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3: Fix error handling in gic_populate_ppi_partitions of_get_child_by_name() returns a node pointer with refcount incremented, we …

Feb 26, 2025
CVE-2022-49715
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3: Fix refcount leak in gic_populate_ppi_partitions of_find_node_by_phandle() returns a node pointer with refcount incremented, we …

Feb 26, 2025
CVE-2022-49714
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/realtek-rtl: Fix refcount leak in map_interrupts of_find_node_by_phandle() returns a node pointer with refcount incremented, we …

Feb 26, 2025
CVE-2022-49713
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: Fix memory leak in dwc2_hcd_init usb_create_hcd will alloc memory for hcd, and we …

Feb 26, 2025
CVE-2022-49712
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: lpc32xx_udc: Fix refcount leak in lpc32xx_udc_probe of_parse_phandle() returns a node pointer with refcount …

Feb 26, 2025
CVE-2022-49710
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm mirror log: round up region bitmap size to BITS_PER_LONG The code in dm-log rounds …

Feb 26, 2025
CVE-2022-49709
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cfi: Fix __cfi_slowpath_diag RCU usage with cpuidle RCU_NONIDLE usage during __cfi_slowpath_diag can result in an …

Feb 26, 2025
CVE-2022-49708
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on ext4_mb_use_inode_pa Hulk Robot reported a BUG_ON: ================================================================== kernel BUG at fs/ext4/mballoc.c:3211! [...] …

Feb 26, 2025
CVE-2022-49707
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: add reserved GDT blocks check We capture a NULL pointer issue when resizing a …

Feb 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.