CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21667
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iomap: avoid avoid truncating 64-bit offset to 32 bits on 32-bit kernels, iomap_write_delalloc_scan() was inadvertently …

Jan 31, 2025
CVE-2025-21666
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports have shown how we sometimes call vsock_*_has_data() when …

Jan 31, 2025
CVE-2025-21665
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: filemap: avoid truncating 64-bit offset to 32 bits On 32-bit kernels, folio_seek_hole_data() was inadvertently truncating …

Jan 31, 2025
CVE-2024-57948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mac802154: check local interfaces before deleting sdata list syzkaller reported a corrupted list in ieee802154_if_remove. …

Jan 31, 2025
CVE-2024-13662
6.4 MEDIUM

The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_objects_image_grid' shortcode in all versions up to, and …

Jan 31, 2025
CVE-2024-12415
6.5 MEDIUM

The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due …

Jan 31, 2025
CVE-2024-12267
5.3 MEDIUM

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file …

Jan 31, 2025
CVE-2024-12037
6.4 MEDIUM

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Jan 31, 2025
CVE-2025-24597
6.5 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Retrieve Embedded Sensitive Data.This …

Jan 31, 2025
CVE-2025-23987
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codegearthemes Designer designer allows DOM-Based XSS.This issue affects Designer: from n/a through <= …

Jan 31, 2025
CVE-2025-23985
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in brainvireinfo Dynamic URL SEO dynamic-url-seo allows Cross Site Request Forgery.This issue affects Dynamic URL SEO: from n/a through <= …

Jan 31, 2025
CVE-2025-22757
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Stored XSS.This issue affects CodeBard Help Desk: …

Jan 31, 2025
CVE-2025-22720
5.8 MEDIUM

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from …

Jan 31, 2025
CVE-2025-22265
6.5 MEDIUM

Missing Authorization vulnerability in mgplugin EMI Calculator emi-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EMI Calculator: from n/a through <= 1.1.

Jan 31, 2025
CVE-2024-44055
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshine Modules: from n/a through < 3.3.8.

Jan 31, 2025
CVE-2024-13566
6.4 MEDIUM

The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 0.2.6 due …

Jan 31, 2025
CVE-2024-13157
6.4 MEDIUM

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS …

Jan 31, 2025
CVE-2024-53007
6.4 MEDIUM

Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authenticated user via an API call.

Jan 31, 2025
CVE-2024-13530
4.3 MEDIUM

The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in …

Jan 31, 2025
CVE-2024-13623
5.9 MEDIUM

The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via the 'uploads' …

Jan 31, 2025
CVE-2025-22216
5.4 MEDIUM

A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use …

Jan 31, 2025
CVE-2024-13717
4.3 MEDIUM

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Jan 31, 2025
CVE-2024-13424
4.3 MEDIUM

The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint …

Jan 31, 2025
CVE-2024-13415
4.3 MEDIUM

The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check …

Jan 31, 2025
CVE-2024-13226
6.1 MEDIUM

The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Jan 31, 2025
CVE-2024-13225
6.1 MEDIUM

The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Jan 31, 2025
CVE-2024-13224
6.1 MEDIUM

The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading …

Jan 31, 2025
CVE-2024-13223
6.1 MEDIUM

The Tabulate WordPress plugin through 2.10.3 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site …

Jan 31, 2025
CVE-2024-13222
6.1 MEDIUM

The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13221
6.1 MEDIUM

The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13220
6.1 MEDIUM

The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in …

Jan 31, 2025
CVE-2024-13219
6.1 MEDIUM

The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 31, 2025
CVE-2024-13218
6.1 MEDIUM

The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13216
4.3 MEDIUM

The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Jan 31, 2025
CVE-2024-13112
6.1 MEDIUM

The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13101
5.4 MEDIUM

The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 31, 2025
CVE-2024-13100
6.1 MEDIUM

The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Jan 31, 2025
CVE-2024-12872
4.8 MEDIUM

The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 31, 2025
CVE-2024-12772
5.4 MEDIUM

The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, …

Jan 31, 2025
CVE-2024-12275
6.1 MEDIUM

The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-11886
6.4 MEDIUM

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in …

Jan 31, 2025
CVE-2025-0507
6.4 MEDIUM

The Ticketmeo – Sell Tickets – Event Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up …

Jan 31, 2025
CVE-2024-10867
5.4 MEDIUM

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads …

Jan 31, 2025
CVE-2025-0470
6.1 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter …

Jan 31, 2025
CVE-2024-13463
6.4 MEDIUM

The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in all versions up to, and including, 1.56.0 due …

Jan 31, 2025
CVE-2024-13399
6.4 MEDIUM

The Gosign – Posts Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'posts-slider-block' block in all versions up to, and …

Jan 31, 2025
CVE-2024-13397
6.4 MEDIUM

The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpradio_player' shortcode in all versions up …

Jan 31, 2025
CVE-2024-13396
6.4 MEDIUM

The Frictionless plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'frictionless_form' shortcode[s] in all versions up to, and including, 0.0.23 due …

Jan 31, 2025
CVE-2023-0092
4.9 MEDIUM

An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's …

Jan 31, 2025
CVE-2024-23970
6.5 MEDIUM

This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.