CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13821
5.3 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due …

Feb 12, 2025
CVE-2024-13794
5.3 MEDIUM

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, …

Feb 12, 2025
CVE-2023-49780
6.1 MEDIUM

Cross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on the web browser of the user who accessed …

Feb 12, 2025
CVE-2025-1184
6.3 MEDIUM

A vulnerability was found in pihome-shc PiHome 1.77 and classified as critical. Affected by this issue is some unknown functionality of the file /ajax.php?Ajax=GetModal_MQTTEdit. The …

Feb 12, 2025
CVE-2025-1183
6.3 MEDIUM

A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 12, 2025
CVE-2024-13601
4.3 MEDIUM

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Feb 12, 2025
CVE-2024-13374
4.3 MEDIUM

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions …

Feb 12, 2025
CVE-2024-13769
6.4 MEDIUM

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a …

Feb 12, 2025
CVE-2024-13665
6.4 MEDIUM

The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 …

Feb 12, 2025
CVE-2024-13658
6.4 MEDIUM

The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and …

Feb 12, 2025
CVE-2024-12164
4.3 MEDIUM

The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Feb 12, 2025
CVE-2024-11746
6.4 MEDIUM

The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 12, 2025
CVE-2025-0808
4.3 MEDIUM

The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to …

Feb 12, 2025
CVE-2024-13749
6.1 MEDIUM

The StaffList plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing or …

Feb 12, 2025
CVE-2024-13701
6.4 MEDIUM

The Liveticker (by stklcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'liveticker' shortcode in all versions up to, and including, …

Feb 12, 2025
CVE-2024-13554
5.3 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Feb 12, 2025
CVE-2024-13541
4.3 MEDIUM

The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Feb 12, 2025
CVE-2024-13539
5.3 MEDIUM

The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. This is due the /vendor/aura/payload-interface/phpunit.php …

Feb 12, 2025
CVE-2024-29172
5.9 MEDIUM

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading …

Feb 12, 2025
CVE-2024-29171
5.9 MEDIUM

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this …

Feb 12, 2025
CVE-2024-53880
4.9 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability in the model loading API, where a user could cause an integer overflow or wraparound error by loading …

Feb 12, 2025
CVE-2024-0145
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPEG2000 file. A …

Feb 12, 2025
CVE-2024-0144
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a buffer overflow issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2024-0143
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2024-21971
5.5 MEDIUM

Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, resulting in an …

Feb 12, 2025
CVE-2024-0142
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2023-20508
5.0 MEDIUM

Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, …

Feb 12, 2025
CVE-2020-3432
5.6 MEDIUM

A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content …

Feb 12, 2025
CVE-2024-54916
6.8 MEDIUM

An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the …

Feb 11, 2025
CVE-2024-54772
5.4 MEDIUM

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available …

Feb 11, 2025
CVE-2024-44336
5.3 MEDIUM

An issue in AnkiDroid Android Application v2.17.6 allows attackers to retrieve internal files from the /data/data/com.ichi2.anki/ directory and save it into publicly available storage.

Feb 11, 2025
CVE-2023-31352
6.0 MEDIUM

A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private data.

Feb 11, 2025
CVE-2022-37660
6.5 MEDIUM

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another …

Feb 11, 2025
CVE-2024-57777
5.1 MEDIUM

Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information

Feb 11, 2025
CVE-2024-57241
6.5 MEDIUM

Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in …

Feb 11, 2025
CVE-2024-55212
6.5 MEDIUM

DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx.

Feb 11, 2025
CVE-2023-20582
5.3 MEDIUM

Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table entry (PTE) faults to bypass …

Feb 11, 2025
CVE-2023-20515
5.7 MEDIUM

Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of …

Feb 11, 2025
CVE-2025-25529
5.1 MEDIUM

Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configuration of static NAT …

Feb 11, 2025
CVE-2025-25528
5.1 MEDIUM

Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, …

Feb 11, 2025
CVE-2025-25527
5.1 MEDIUM

Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT …

Feb 11, 2025
CVE-2025-25526
5.1 MEDIUM

Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration of the PPTP server. …

Feb 11, 2025
CVE-2025-25525
5.1 MEDIUM

Buffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the setting of firewall rules. …

Feb 11, 2025
CVE-2024-12833
6.1 MEDIUM

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network …

Feb 11, 2025
CVE-2025-25524
5.1 MEDIUM

Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. …

Feb 11, 2025
CVE-2025-25523
5.9 MEDIUM

Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point …

Feb 11, 2025
CVE-2025-25202
6.5 MEDIUM

Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have …

Feb 11, 2025
CVE-2022-35202
5.1 MEDIUM

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used …

Feb 11, 2025
CVE-2025-24437
5.4 MEDIUM

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24436
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.