CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1447
4.3 MEDIUM

A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects unknown code of the file /pigeon/imgproxy/index.php. The manipulation …

Feb 19, 2025
CVE-2024-13508
6.1 MEDIUM

The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due …

Feb 19, 2025
CVE-2025-25474
6.5 MEDIUM

DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.

Feb 18, 2025
CVE-2025-25473
5.3 MEDIUM

FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.

Feb 18, 2025
CVE-2025-25472
5.3 MEDIUM

A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.

Feb 18, 2025
CVE-2025-25471
4.3 MEDIUM

FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.

Feb 18, 2025
CVE-2025-22920
5.3 MEDIUM

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat …

Feb 18, 2025
CVE-2025-22919
6.5 MEDIUM

A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.

Feb 18, 2025
CVE-2024-13743
6.4 MEDIUM

The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_video shortcode in all versions up to, and including, …

Feb 18, 2025
CVE-2025-25896
5.7 MEDIUM

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the destination, netmask, and gateway parameters. This vulnerability allows attackers to cause a Denial …

Feb 18, 2025
CVE-2025-25892
5.7 MEDIUM

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip parameters. This vulnerability allows attackers to cause a …

Feb 18, 2025
CVE-2025-25891
5.7 MEDIUM

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gateway parameters. This vulnerability allows attackers to cause a …

Feb 18, 2025
CVE-2025-25469
6.5 MEDIUM

FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.

Feb 18, 2025
CVE-2025-25468
6.5 MEDIUM

FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.

Feb 18, 2025
CVE-2025-22921
6.5 MEDIUM

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

Feb 18, 2025
CVE-2025-27016
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Drivr Lite – Google Drive Plugin allows Stored XSS. This issue affects …

Feb 18, 2025
CVE-2025-27013
5.3 MEDIUM

Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MediCenter - Health Medical …

Feb 18, 2025
CVE-2025-22650
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget smartarget-contact-us allows Stored XSS.This issue affects Smartarget: from n/a through …

Feb 18, 2025
CVE-2025-22645
5.3 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Password Brute Forcing.This issue affects Real Estate Manager: from n/a …

Feb 18, 2025
CVE-2025-0622
6.4 MEDIUM

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw …

Feb 18, 2025
CVE-2024-45783
4.4 MEDIUM

A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERRNO value. This issue …

Feb 18, 2025
CVE-2024-45781
6.7 MEDIUM

A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as …

Feb 18, 2025
CVE-2024-45776
6.7 MEDIUM

When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may …

Feb 18, 2025
CVE-2024-45775
5.2 MEDIUM

A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check …

Feb 18, 2025
CVE-2025-26603
4.2 MEDIUM

Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to …

Feb 18, 2025
CVE-2025-26465
6.8 MEDIUM

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit …

Feb 18, 2025
CVE-2025-21608
5.3 MEDIUM

Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client …

Feb 18, 2025
CVE-2024-57056
5.4 MEDIUM

Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a …

Feb 18, 2025
CVE-2024-57055
5.0 MEDIUM

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue …

Feb 18, 2025
CVE-2024-45774
6.7 MEDIUM

A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its …

Feb 18, 2025
CVE-2025-26058
4.2 MEDIUM

Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication …

Feb 18, 2025
CVE-2024-56882
5.4 MEDIUM

Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the …

Feb 18, 2025
CVE-2024-49589
6.5 MEDIUM

Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied …

Feb 18, 2025
CVE-2024-39328
6.8 MEDIUM

Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment …

Feb 18, 2025
CVE-2022-41545
6.4 MEDIUM

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header …

Feb 18, 2025
CVE-2024-13689
6.3 MEDIUM

The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the …

Feb 18, 2025
CVE-2025-1414
6.5 MEDIUM

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Feb 18, 2025
CVE-2025-1269
4.8 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.

Feb 18, 2025
CVE-2025-1035
5.7 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This …

Feb 18, 2025
CVE-2024-13783
4.3 MEDIUM

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, …

Feb 18, 2025
CVE-2024-13691
6.5 MEDIUM

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, …

Feb 18, 2025
CVE-2024-13667
5.4 MEDIUM

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to …

Feb 18, 2025
CVE-2025-0981
6.1 MEDIUM

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) …

Feb 18, 2025
CVE-2024-13369
6.5 MEDIUM

The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up …

Feb 18, 2025
CVE-2024-13718
4.3 MEDIUM

The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Feb 18, 2025
CVE-2024-13395
6.4 MEDIUM

The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode in all versions up to, and including, 1.7.1 due …

Feb 18, 2025
CVE-2024-13316
5.3 MEDIUM

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access …

Feb 18, 2025
CVE-2025-0864
6.1 MEDIUM

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in …

Feb 18, 2025
CVE-2024-13795
4.3 MEDIUM

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This …

Feb 18, 2025
CVE-2024-13575
6.4 MEDIUM

The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'web_stories_enhancer' shortcode in …

Feb 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.