CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51308
6.1 MEDIUM

PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

Feb 20, 2025
CVE-2023-51306
5.4 MEDIUM

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters.

Feb 20, 2025
CVE-2025-21106
5.5 MEDIUM

Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading …

Feb 20, 2025
CVE-2025-21105
6.6 MEDIUM

Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by …

Feb 20, 2025
CVE-2025-1043
6.4 MEDIUM

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Feb 20, 2025
CVE-2024-49779
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of …

Feb 20, 2025
CVE-2024-49344
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in …

Feb 20, 2025
CVE-2024-49337
5.4 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used …

Feb 20, 2025
CVE-2025-1483
5.3 MEDIUM

The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 20, 2025
CVE-2025-1328
6.4 MEDIUM

The Typed JS: A typewriter style animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘typespeed’ parameter in all versions up to, …

Feb 20, 2025
CVE-2025-0866
6.5 MEDIUM

The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 …

Feb 20, 2025
CVE-2024-6432
6.4 MEDIUM

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter within the plugin's shortcode Content Block …

Feb 20, 2025
CVE-2024-13855
4.3 MEDIUM

The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the …

Feb 20, 2025
CVE-2024-13849
5.5 MEDIUM

The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.0 due to insufficient input …

Feb 20, 2025
CVE-2024-13802
6.4 MEDIUM

The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_events' shortcode in all versions up to, and including, 1.3.1 …

Feb 20, 2025
CVE-2024-13748
4.4 MEDIUM

The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 …

Feb 20, 2025
CVE-2024-13520
5.3 MEDIUM

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing …

Feb 20, 2025
CVE-2025-1064
6.4 MEDIUM

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all …

Feb 20, 2025
CVE-2025-0897
6.4 MEDIUM

The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions …

Feb 20, 2025
CVE-2024-13155
6.4 MEDIUM

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up …

Feb 20, 2025
CVE-2025-27218
5.3 MEDIUM

Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

Feb 20, 2025
CVE-2024-13445
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and …

Feb 20, 2025
CVE-2024-49782
6.8 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit …

Feb 20, 2025
CVE-2024-49780
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to …

Feb 20, 2025
CVE-2024-49355
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing …

Feb 20, 2025
CVE-2024-43196
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof …

Feb 20, 2025
CVE-2025-24947
5.3 MEDIUM

A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a …

Feb 20, 2025
CVE-2025-24946
5.3 MEDIUM

The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attackers to cause a considerable CPU load …

Feb 20, 2025
CVE-2025-23020
5.3 MEDIUM

An issue was discovered in Kwik before 0.10.1. A hash collision vulnerability (in the hash table used to manage connections) allows remote attackers to cause …

Feb 20, 2025
CVE-2025-1223
6.1 MEDIUM

An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

Feb 20, 2025
CVE-2025-1222
6.1 MEDIUM

An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

Feb 20, 2025
CVE-2024-6697
6.5 MEDIUM

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may …

Feb 20, 2025
CVE-2024-6696
4.9 MEDIUM

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in …

Feb 20, 2025
CVE-2024-37363
6.5 MEDIUM

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862) Hitachi Vantara Pentaho Business …

Feb 20, 2025
CVE-2024-37362
6.3 MEDIUM

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522) Hitachi Vantara Pentaho …

Feb 20, 2025
CVE-2025-25947
5.5 MEDIUM

An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a …

Feb 19, 2025
CVE-2025-25946
5.5 MEDIUM

An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution …

Feb 19, 2025
CVE-2025-25945
6.5 MEDIUM

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.

Feb 19, 2025
CVE-2025-25942
6.5 MEDIUM

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in …

Feb 19, 2025
CVE-2024-37360
4.4 MEDIUM

Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The software does not neutralize or incorrectly neutralize …

Feb 19, 2025
CVE-2023-51305
5.4 MEDIUM

PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

Feb 19, 2025
CVE-2025-27090
5.3 MEDIUM

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse …

Feb 19, 2025
CVE-2023-51303
6.1 MEDIUM

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

Feb 19, 2025
CVE-2023-51300
6.1 MEDIUM

PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

Feb 19, 2025
CVE-2023-51299
6.1 MEDIUM

PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

Feb 19, 2025
CVE-2023-51298
4.7 MEDIUM

PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient …

Feb 19, 2025
CVE-2023-51297
6.5 MEDIUM

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email …

Feb 19, 2025
CVE-2025-0677
6.4 MEDIUM

A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer …

Feb 19, 2025
CVE-2023-51296
6.1 MEDIUM

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary …

Feb 19, 2025
CVE-2020-13481
6.1 MEDIUM

Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information.

Feb 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.