CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25143
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ibasit GlobalQuran globalquran allows Cross Site Request Forgery.This issue affects GlobalQuran: from n/a through <= 1.0.

Feb 7, 2025
CVE-2025-25136
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shujahat21 Optimate Ads optimate-ads allows Stored XSS.This issue affects Optimate Ads: from n/a …

Feb 7, 2025
CVE-2025-25120
4.3 MEDIUM

Missing Authorization vulnerability in Melodic Media Slide Banners slide-banners allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slide Banners: from n/a through <= …

Feb 7, 2025
CVE-2025-25117
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Polonski Smart Countdown FX smart-countdown-fx allows Stored XSS.This issue affects Smart Countdown …

Feb 7, 2025
CVE-2025-25111
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Cross Site Request Forgery.This issue affects WP Spell Check: from n/a …

Feb 7, 2025
CVE-2025-25110
5.4 MEDIUM

Missing Authorization vulnerability in Metagauss Event Kikfyre kikfyre-events-calendar-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Kikfyre: from n/a through <= 2.1.8.

Feb 7, 2025
CVE-2025-25105
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in coffeestudios Pop Up popup-seo-optimized allows Stored XSS.This issue affects Pop Up: from n/a …

Feb 7, 2025
CVE-2025-25103
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in bnielsen Indeed API indeed-api allows Cross Site Request Forgery.This issue affects Indeed API: from n/a through <= 0.5.

Feb 7, 2025
CVE-2025-25098
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz Links in Captions links-in-captions allows Stored XSS.This issue affects Links in …

Feb 7, 2025
CVE-2025-25097
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kwiliarty External Video For Everybody external-video-for-everybody allows Stored XSS.This issue affects External Video …

Feb 7, 2025
CVE-2025-25096
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titusbicknell RSS in Page rss-in-page allows Stored XSS.This issue affects RSS in Page: …

Feb 7, 2025
CVE-2025-25095
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reverbnationdev ReverbNation Widgets reverbnation-widgets allows Stored XSS.This issue affects ReverbNation Widgets: from n/a …

Feb 7, 2025
CVE-2025-25094
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amitythemes.com Breaking News Ticker breaking-news-ticker allows Stored XSS.This issue affects Breaking News Ticker: …

Feb 7, 2025
CVE-2025-25093
6.1 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in paulswarthout Child Themes Helper child-themes-helper allows Path Traversal.This issue affects Child Themes Helper: from n/a through <= 2.2.7.

Feb 7, 2025
CVE-2025-25091
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zackdesign NextGen Cooliris Gallery nextgen-cooliris-gallery allows Stored XSS.This issue affects NextGen Cooliris Gallery: …

Feb 7, 2025
CVE-2025-25085
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matt_mcbrien WP SimpleWeather wp-simpleweather allows Stored XSS.This issue affects WP SimpleWeather: from n/a …

Feb 7, 2025
CVE-2025-25082
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Chirkov FlexIDX Home Search flexidx-home-search allows Stored XSS.This issue affects FlexIDX Home …

Feb 7, 2025
CVE-2025-25081
4.2 MEDIUM

Missing Authorization vulnerability in DeannaS Embed RSS embed-rss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Embed RSS: from n/a through <= 3.1.

Feb 7, 2025
CVE-2025-25080
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gubbigubbi Kona Gallery Block kona-instagram-feed-for-gutenberg allows Stored XSS.This issue affects Kona Gallery Block: …

Feb 7, 2025
CVE-2025-25079
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simple Select All Text Box simple-select-all-text-box allows Stored XSS.This issue affects …

Feb 7, 2025
CVE-2025-25078
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrew Norcross Google Earth Embed google-earth-tours allows Stored XSS.This issue affects Google Earth …

Feb 7, 2025
CVE-2025-25077
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugbug Easy Chart Builder for WordPress easy-chart-builder allows Stored XSS.This issue affects Easy …

Feb 7, 2025
CVE-2025-25076
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation graceful-email-obfuscation allows Stored XSS.This issue affects Graceful Email Obfuscation: …

Feb 7, 2025
CVE-2025-25073
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles easy-wp-tiles allows Stored XSS.This issue affects Easy WP …

Feb 7, 2025
CVE-2025-0302
5.5 MEDIUM

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.

Feb 7, 2025
CVE-2025-23085
5.3 MEDIUM

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected …

Feb 7, 2025
CVE-2024-13841
4.3 MEDIUM

The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to Information Exposure in all versions up to, …

Feb 7, 2025
CVE-2024-13492
6.1 MEDIUM

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 7, 2025
CVE-2025-1072
6.5 MEDIUM

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, …

Feb 7, 2025
CVE-2025-1086
5.3 MEDIUM

A vulnerability has been found in Safetytest Cloud-Master Server up to 1.1.1 and classified as critical. This vulnerability affects unknown code of the file /static/. …

Feb 7, 2025
CVE-2025-1085
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Animati PACS up to 1.24.12.09.03. This affects an unknown part of the file /login. The …

Feb 7, 2025
CVE-2025-1084
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this issue is some unknown functionality. The manipulation …

Feb 7, 2025
CVE-2025-21404
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Feb 6, 2025
CVE-2025-21283
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 6, 2025
CVE-2025-21279
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 6, 2025
CVE-2025-21267
4.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Feb 6, 2025
CVE-2025-21253
5.3 MEDIUM

Microsoft Edge for IOS and Android Spoofing Vulnerability

Feb 6, 2025
CVE-2024-53586
5.3 MEDIUM

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads …

Feb 6, 2025
CVE-2024-48589
6.3 MEDIUM

Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php

Feb 6, 2025
CVE-2024-25883
5.3 MEDIUM

The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.

Feb 6, 2025
CVE-2020-36085
6.3 MEDIUM

Stored Cross Site Scripting(XSS) vulnerability in Egavilan Media Resumes Management and Job Application Website 1.0 allows remote attackers to inject arbitrary code via First and …

Feb 6, 2025
CVE-2025-1004
5.3 MEDIUM

Certain HP LaserJet Pro printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer via IPP …

Feb 6, 2025
CVE-2025-0158
5.5 MEDIUM

IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.

Feb 6, 2025
CVE-2025-22936
5.7 MEDIUM

An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi …

Feb 6, 2025
CVE-2024-57673
5.5 MEDIUM

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

Feb 6, 2025
CVE-2024-57672
5.5 MEDIUM

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing module.

Feb 6, 2025
CVE-2024-52892
6.1 MEDIUM

IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in …

Feb 6, 2025
CVE-2024-47256
6.0 MEDIUM

Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to read hardcoded AES passphrase, which may be used …

Feb 6, 2025
CVE-2024-13417
4.6 MEDIUM

Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it gets back to fully working …

Feb 6, 2025
CVE-2024-57523
4.5 MEDIUM

Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests …

Feb 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.