CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1118
4.4 MEDIUM

A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any …

Feb 19, 2025
CVE-2024-53974
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Feb 19, 2025
CVE-2024-45777
6.7 MEDIUM

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a …

Feb 19, 2025
CVE-2025-27089
5.4 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping policies for the `update` …

Feb 19, 2025
CVE-2025-20211
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack …

Feb 19, 2025
CVE-2025-20158
4.4 MEDIUM

A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access …

Feb 19, 2025
CVE-2025-20153
5.8 MEDIUM

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow …

Feb 19, 2025
CVE-2025-1465
4.1 MEDIUM

A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. …

Feb 19, 2025
CVE-2024-45081
6.5 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks.

Feb 19, 2025
CVE-2024-28780
5.9 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to …

Feb 19, 2025
CVE-2024-28776
5.4 MEDIUM

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code …

Feb 19, 2025
CVE-2025-0968
5.3 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing …

Feb 19, 2025
CVE-2025-1024
4.8 MEDIUM

A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the …

Feb 19, 2025
CVE-2025-1007
5.3 MEDIUM

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace …

Feb 19, 2025
CVE-2024-13364
5.3 MEDIUM

The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all …

Feb 19, 2025
CVE-2024-13363
6.1 MEDIUM

The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all versions up to, and including, 3.6.3 due …

Feb 19, 2025
CVE-2024-13339
6.1 MEDIUM

The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.8.0. This is due to …

Feb 19, 2025
CVE-2024-13336
4.3 MEDIUM

The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to …

Feb 19, 2025
CVE-2024-13231
5.3 MEDIUM

The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 19, 2025
CVE-2025-0865
6.5 MEDIUM

The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or …

Feb 19, 2025
CVE-2024-13854
4.3 MEDIUM

The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the …

Feb 19, 2025
CVE-2024-13736
6.1 MEDIUM

The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWidgetName’ parameter in all versions up …

Feb 19, 2025
CVE-2024-13719
5.3 MEDIUM

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing …

Feb 19, 2025
CVE-2024-13712
4.9 MEDIUM

The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient …

Feb 19, 2025
CVE-2024-13711
6.1 MEDIUM

The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all versions up to, and including, 1.01.1 due to …

Feb 19, 2025
CVE-2024-13679
6.4 MEDIUM

The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' shortcode in all versions up to, and including, 3.1.5 …

Feb 19, 2025
CVE-2024-13676
6.5 MEDIUM

The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all versions up to, …

Feb 19, 2025
CVE-2024-13674
6.4 MEDIUM

The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cwp_social_share' shortcode in all versions …

Feb 19, 2025
CVE-2024-13663
6.4 MEDIUM

The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.5.1 …

Feb 19, 2025
CVE-2024-13660
6.4 MEDIUM

The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fshow' shortcode in all versions up to, and including, …

Feb 19, 2025
CVE-2024-13657
6.4 MEDIUM

The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including, …

Feb 19, 2025
CVE-2024-13591
6.4 MEDIUM

The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'team-builder-vc' shortcode in all …

Feb 19, 2025
CVE-2024-13589
6.4 MEDIUM

The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and …

Feb 19, 2025
CVE-2024-13462
6.4 MEDIUM

The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, …

Feb 19, 2025
CVE-2024-13405
4.3 MEDIUM

The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due …

Feb 19, 2025
CVE-2024-13390
6.4 MEDIUM

The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions …

Feb 19, 2025
CVE-2024-12522
6.4 MEDIUM

The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode …

Feb 19, 2025
CVE-2024-12339
6.1 MEDIUM

The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' parameter in all versions up to, and including, 3.1.1 …

Feb 19, 2025
CVE-2024-12069
6.1 MEDIUM

The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Feb 19, 2025
CVE-2024-11778
6.4 MEDIUM

The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedcdn' shortcode in all versions up to, and …

Feb 19, 2025
CVE-2024-11753
6.4 MEDIUM

The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_button' shortcode in all versions up to, and including, …

Feb 19, 2025
CVE-2024-11335
6.4 MEDIUM

The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframe' …

Feb 19, 2025
CVE-2025-25054
6.1 MEDIUM

Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a …

Feb 19, 2025
CVE-2025-24841
5.4 MEDIUM

Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as …

Feb 19, 2025
CVE-2025-22888
5.4 MEDIUM

Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be …

Feb 19, 2025
CVE-2025-1065
6.4 MEDIUM

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature …

Feb 19, 2025
CVE-2024-13799
6.4 MEDIUM

The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 19, 2025
CVE-2025-1441
6.1 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is …

Feb 19, 2025
CVE-2025-22622
4.3 MEDIUM

Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web application dynamically generates web content without validating …

Feb 19, 2025
CVE-2024-13443
6.4 MEDIUM

The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shortcode in all versions up to, and including, 1.3.8 …

Feb 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.