CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22730
6.5 MEDIUM

Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ksher: from n/a through <= 1.1.2.

Feb 4, 2025
CVE-2025-22697
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Reflected XSS.This issue affects Responsive Blocks: from n/a …

Feb 4, 2025
CVE-2025-22696
5.4 MEDIUM

Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Document Block – Upload & Embed Docs: from n/a through …

Feb 4, 2025
CVE-2025-22675
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Alert Box Block – Display notice/alerts in the front end alert-box-block allows …

Feb 4, 2025
CVE-2025-22674
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Product Blocks for WooCommerce product-blocks-for-woocommerce allows Stored XSS.This issue affects Product …

Feb 4, 2025
CVE-2025-22664
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from …

Feb 4, 2025
CVE-2025-22662
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Stored XSS.This issue affects SendPulse Email …

Feb 4, 2025
CVE-2025-22653
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv Music Press Pro music-press-pro allows Stored XSS.This issue affects Music Press Pro: …

Feb 4, 2025
CVE-2025-22643
4.3 MEDIUM

Missing Authorization vulnerability in famethemes OnePress onepress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OnePress: from n/a through <= 2.3.11.

Feb 4, 2025
CVE-2025-22642
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites Dynamic Conditions dynamicconditions allows Stored XSS.This issue affects Dynamic Conditions: from n/a …

Feb 4, 2025
CVE-2025-22641
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prem Tiwari FM Notification Bar fm-notification-bar allows Stored XSS.This issue affects FM Notification …

Feb 4, 2025
CVE-2025-22206
4.7 MEDIUM

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' …

Feb 4, 2025
CVE-2025-0825
5.3 MEDIUM

cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF …

Feb 4, 2025
CVE-2025-1019
4.3 MEDIUM

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This …

Feb 4, 2025
CVE-2025-1018
5.3 MEDIUM

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. …

Feb 4, 2025
CVE-2025-1015
5.4 MEDIUM

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a …

Feb 4, 2025
CVE-2025-1013
6.5 MEDIUM

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. …

Feb 4, 2025
CVE-2025-0510
6.5 MEDIUM

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This …

Feb 4, 2025
CVE-2024-11623
4.8 MEDIUM

Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed …

Feb 4, 2025
CVE-2024-13699
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter in all versions up to, and including, …

Feb 4, 2025
CVE-2025-24860
5.4 MEDIUM

Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or …

Feb 4, 2025
CVE-2024-27137
5.3 MEDIUM

In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry …

Feb 4, 2025
CVE-2024-13733
6.4 MEDIUM

The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's skt-blocks/post-carousel block in all versions …

Feb 4, 2025
CVE-2024-13529
6.5 MEDIUM

The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Feb 4, 2025
CVE-2024-13510
6.1 MEDIUM

The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or …

Feb 4, 2025
CVE-2024-13356
6.5 MEDIUM

The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This …

Feb 4, 2025
CVE-2024-13403
6.4 MEDIUM

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Feb 4, 2025
CVE-2025-20907
6.0 MEDIUM

Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.

Feb 4, 2025
CVE-2025-20906
5.5 MEDIUM

Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.

Feb 4, 2025
CVE-2025-20905
6.3 MEDIUM

Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.

Feb 4, 2025
CVE-2025-20904
6.3 MEDIUM

Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.

Feb 4, 2025
CVE-2025-20902
5.1 MEDIUM

Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.

Feb 4, 2025
CVE-2025-20901
4.4 MEDIUM

Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bounds memory.

Feb 4, 2025
CVE-2025-20900
6.3 MEDIUM

Out-of-bounds write in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to write out-of-bounds memory.

Feb 4, 2025
CVE-2025-20899
4.0 MEDIUM

Improper access control in PushNotification prior to version 13.0.00.15 in Android 12, 14.0.00.7 in Android 13, and 15.1.00.5 in Android 14 allows local attackers to …

Feb 4, 2025
CVE-2025-20898
4.6 MEDIUM

Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles.

Feb 4, 2025
CVE-2025-20897
6.8 MEDIUM

Improper access control in Secure Folder prior to version 1.9.20.50 in Android 14, 1.8.11.0 in Android 13, and 1.7.04.0 in Android 12 allows local attacker …

Feb 4, 2025
CVE-2025-20896
4.0 MEDIUM

Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information.

Feb 4, 2025
CVE-2025-20894
4.6 MEDIUM

Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multiple user profiles.

Feb 4, 2025
CVE-2025-20893
5.1 MEDIUM

Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.

Feb 4, 2025
CVE-2025-20892
5.9 MEDIUM

Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for …

Feb 4, 2025
CVE-2025-20891
5.3 MEDIUM

Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User …

Feb 4, 2025
CVE-2025-20889
5.3 MEDIUM

Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction …

Feb 4, 2025
CVE-2025-20887
5.3 MEDIUM

Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction …

Feb 4, 2025
CVE-2025-20886
4.1 MEDIUM

Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.

Feb 4, 2025
CVE-2025-20885
6.4 MEDIUM

Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption.

Feb 4, 2025
CVE-2025-20884
4.6 MEDIUM

Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.

Feb 4, 2025
CVE-2025-20883
4.6 MEDIUM

Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.

Feb 4, 2025
CVE-2024-13514
4.3 MEDIUM

The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.5 via …

Feb 4, 2025
CVE-2024-12046
4.3 MEDIUM

The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.2 via the …

Feb 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.