CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23561
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robertkay MLL Audio Player MP3 Ajax music-let-loose-mp3-audio-player allows Stored XSS.This issue affects MLL …

Feb 3, 2025
CVE-2025-23527
6.5 MEDIUM

Missing Authorization vulnerability in hemnathmouli WC Wallet wc-wallet allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WC Wallet: from n/a through <= 2.2.0.

Feb 3, 2025
CVE-2025-22701
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-essential-for-elementor.This issue affects Traveler Layout Essential For Elementor: from n/a through < 1.4.

Feb 3, 2025
CVE-2025-22695
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support nirweb-support.This issue affects Nirweb support: from n/a through <= 3.0.3.

Feb 3, 2025
CVE-2025-22694
4.3 MEDIUM

Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerce.This issue affects Hide Shipping Method For WooCommerce: from n/a through <= 1.5.1.

Feb 3, 2025
CVE-2025-22686
5.3 MEDIUM

Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Google Sheets Connector: from …

Feb 3, 2025
CVE-2025-22683
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper NotificationX notificationx allows Stored XSS.This issue affects NotificationX: from n/a through <= …

Feb 3, 2025
CVE-2025-22681
4.3 MEDIUM

Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Cloner: from n/a through <= 1.0.1.

Feb 3, 2025
CVE-2025-22677
4.8 MEDIUM

Missing Authorization vulnerability in UIUX Lab Uix Shortcodes uix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uix Shortcodes: from n/a through <= …

Feb 3, 2025
CVE-2025-22292
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Felipe Peixoto Powerful Auto Chat powers-triggers-of-woo-to-chat allows Stored XSS.This issue affects Powerful Auto …

Feb 3, 2025
CVE-2025-22260
4.3 MEDIUM

Missing Authorization vulnerability in Marcus (aka @msykes) Meta Tag Manager meta-tag-manager.This issue affects Meta Tag Manager: from n/a through <= 3.1.

Feb 3, 2025
CVE-2024-50500
4.3 MEDIUM

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and …

Feb 3, 2025
CVE-2024-57522
6.4 MEDIUM

SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the …

Feb 3, 2025
CVE-2024-6790
6.1 MEDIUM

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th …

Feb 3, 2025
CVE-2024-13347
6.8 MEDIUM

The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

Feb 3, 2025
CVE-2024-57966
5.0 MEDIUM

libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

Feb 3, 2025
CVE-2025-25063
4.4 MEDIUM

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure …

Feb 3, 2025
CVE-2025-25062
4.4 MEDIUM

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor …

Feb 3, 2025
CVE-2025-20642
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20641
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20640
4.3 MEDIUM

In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an …

Feb 3, 2025
CVE-2025-20639
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20638
4.3 MEDIUM

In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker …

Feb 3, 2025
CVE-2025-20636
6.7 MEDIUM

In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Feb 3, 2025
CVE-2025-20635
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2024-20147
5.3 MEDIUM

In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional …

Feb 3, 2025
CVE-2024-20142
6.6 MEDIUM

In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2024-20141
6.6 MEDIUM

In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2025-0974
5.0 MEDIUM

A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can …

Feb 3, 2025
CVE-2025-0973
5.4 MEDIUM

A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The …

Feb 3, 2025
CVE-2025-0970
4.3 MEDIUM

A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 2, 2025
CVE-2025-0967
6.3 MEDIUM

A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/add_chatroom.php. The manipulation …

Feb 2, 2025
CVE-2024-0131
4.4 MEDIUM

NVIDIA GPU kernel driver for Windows and Linux contains a vulnerability where a potential user-mode attacker could read a buffer with an incorrect length. A …

Feb 2, 2025
CVE-2025-0950
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file staffview.php. The …

Feb 1, 2025
CVE-2025-0949
6.3 MEDIUM

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file partview.php. The …

Feb 1, 2025
CVE-2025-0948
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file incview.php. The …

Feb 1, 2025
CVE-2025-0947
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Tailoring Management System 1.0. Affected by this issue is some unknown functionality of …

Feb 1, 2025
CVE-2025-0946
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file templatedelete.php. …

Feb 1, 2025
CVE-2025-0945
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file typedelete.php. The manipulation …

Feb 1, 2025
CVE-2025-0944
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Feb 1, 2025
CVE-2024-13775
5.4 MEDIUM

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', …

Feb 1, 2025
CVE-2024-13612
6.4 MEDIUM

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Feb 1, 2025
CVE-2025-0943
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file deldoc.php. …

Feb 1, 2025
CVE-2024-13429
4.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Feb 1, 2025
CVE-2024-13428
5.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Feb 1, 2025
CVE-2024-13425
4.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Feb 1, 2025
CVE-2024-13372
5.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Feb 1, 2025
CVE-2024-13371
5.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending …

Feb 1, 2025
CVE-2024-12825
5.4 MEDIUM

The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX …

Feb 1, 2025
CVE-2025-23091
5.9 MEDIUM

An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application …

Feb 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.