CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1406
6.4 MEDIUM

The Newpost Catch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's npc shortcode in all versions up to, and including, 1.3.19 …

Feb 21, 2025
CVE-2024-13883
4.3 MEDIUM

The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. This is due to …

Feb 21, 2025
CVE-2024-13818
5.3 MEDIUM

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information …

Feb 21, 2025
CVE-2024-13751
6.4 MEDIUM

The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all versions up to, and including, 1.3 …

Feb 21, 2025
CVE-2024-13672
6.4 MEDIUM

The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mcg' shortcode in …

Feb 21, 2025
CVE-2024-13537
5.3 MEDIUM

The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin …

Feb 21, 2025
CVE-2024-13388
6.4 MEDIUM

The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' shortcode in all versions up to, and including, 1.0 …

Feb 21, 2025
CVE-2024-13379
6.4 MEDIUM

The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 …

Feb 21, 2025
CVE-2024-13235
6.5 MEDIUM

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up …

Feb 21, 2025
CVE-2024-38657
4.9 MEDIUM

External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker …

Feb 21, 2025
CVE-2025-1001
5.7 MEDIUM

Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to …

Feb 21, 2025
CVE-2025-27100
6.5 MEDIUM

lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting …

Feb 21, 2025
CVE-2025-25957
6.1 MEDIUM

Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.

Feb 20, 2025
CVE-2025-25960
6.1 MEDIUM

Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background …

Feb 20, 2025
CVE-2025-25958
5.4 MEDIUM

Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.

Feb 20, 2025
CVE-2025-27098
5.8 MEDIUM

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and …

Feb 20, 2025
CVE-2023-51339
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2023-51338
5.4 MEDIUM

PHPJabbers Meeting Room Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters of index.php page.

Feb 20, 2025
CVE-2023-51337
5.4 MEDIUM

PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.

Feb 20, 2025
CVE-2025-25973
6.5 MEDIUM

A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted …

Feb 20, 2025
CVE-2025-25968
6.0 MEDIUM

DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, …

Feb 20, 2025
CVE-2024-55457
6.5 MEDIUM

MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary …

Feb 20, 2025
CVE-2024-54961
6.5 MEDIUM

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current …

Feb 20, 2025
CVE-2024-54960
6.5 MEDIUM

A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.

Feb 20, 2025
CVE-2024-54959
6.1 MEDIUM

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

Feb 20, 2025
CVE-2024-54958
6.1 MEDIUM

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts …

Feb 20, 2025
CVE-2023-51335
6.5 MEDIUM

PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

Feb 20, 2025
CVE-2023-51334
5.3 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2025-26311
6.5 MEDIUM

Multiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in util/parser.c of libming v0.4.8, which allow attackers to cause …

Feb 20, 2025
CVE-2025-26310
6.5 MEDIUM

Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming v0.4.8, which allow attackers to cause …

Feb 20, 2025
CVE-2025-26309
6.5 MEDIUM

A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26308
6.5 MEDIUM

A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26307
6.5 MEDIUM

A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26306
6.5 MEDIUM

A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2023-51332
4.3 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of …

Feb 20, 2025
CVE-2023-51331
6.5 MEDIUM

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient …

Feb 20, 2025
CVE-2023-51330
5.4 MEDIUM

PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.

Feb 20, 2025
CVE-2023-51327
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2023-51326
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2023-51325
5.4 MEDIUM

PHPJabbers Shared Asset Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

Feb 20, 2025
CVE-2023-51324
6.5 MEDIUM

PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to …

Feb 20, 2025
CVE-2023-51323
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of …

Feb 20, 2025
CVE-2023-51321
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of …

Feb 20, 2025
CVE-2023-51320
5.3 MEDIUM

PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to …

Feb 20, 2025
CVE-2023-51318
5.4 MEDIUM

PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

Feb 20, 2025
CVE-2023-51317
6.5 MEDIUM

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

Feb 20, 2025
CVE-2023-51315
5.4 MEDIUM

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name" parameters.

Feb 20, 2025
CVE-2023-51312
5.4 MEDIUM

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter.

Feb 20, 2025
CVE-2023-51310
4.3 MEDIUM

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive …

Feb 20, 2025
CVE-2023-51309
4.3 MEDIUM

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of …

Feb 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.