CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23962
5.3 MEDIUM

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The …

Jan 31, 2025
CVE-2024-23937
4.3 MEDIUM

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. …

Jan 31, 2025
CVE-2024-23930
4.3 MEDIUM

This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. …

Jan 31, 2025
CVE-2024-23928
6.5 MEDIUM

This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit …

Jan 31, 2025
CVE-2024-1211
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

Jan 31, 2025
CVE-2025-0882
6.3 MEDIUM

A vulnerability was found in code-projects Chat System up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 30, 2025
CVE-2025-0881
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/saveroutine.php. …

Jan 30, 2025
CVE-2025-0880
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/updateplan.php. The …

Jan 30, 2025
CVE-2025-0573
5.3 MEDIUM

Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of …

Jan 30, 2025
CVE-2025-0572
4.3 MEDIUM

Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected …

Jan 30, 2025
CVE-2025-0571
6.5 MEDIUM

Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations …

Jan 30, 2025
CVE-2025-0570
6.5 MEDIUM

Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations …

Jan 30, 2025
CVE-2025-0145
4.6 MEDIUM

Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via …

Jan 30, 2025
CVE-2025-0143
4.3 MEDIUM

Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network …

Jan 30, 2025
CVE-2025-0142
4.3 MEDIUM

Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information …

Jan 30, 2025
CVE-2024-10604
5.3 MEDIUM

Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and …

Jan 30, 2025
CVE-2024-10603
5.3 MEDIUM

Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker …

Jan 30, 2025
CVE-2024-10026
5.3 MEDIUM

A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a …

Jan 30, 2025
CVE-2025-0683
5.9 MEDIUM

In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up …

Jan 30, 2025
CVE-2025-0681
6.2 MEDIUM

The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service …

Jan 30, 2025
CVE-2025-0874
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Simple Plugins Car Rental Management 1.0. Affected by this issue is some unknown …

Jan 30, 2025
CVE-2025-24099
5.1 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker may …

Jan 30, 2025
CVE-2025-0873
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. …

Jan 30, 2025
CVE-2025-0367
6.5 MEDIUM

In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to …

Jan 30, 2025
CVE-2025-24784
4.3 MEDIUM

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. By …

Jan 30, 2025
CVE-2025-24376
6.5 MEDIUM

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can evaluate only namespaced resources. The …

Jan 30, 2025
CVE-2025-23216
6.8 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages …

Jan 30, 2025
CVE-2025-22221
5.2 MEDIUM

VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be …

Jan 30, 2025
CVE-2025-22220
4.3 MEDIUM

VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API …

Jan 30, 2025
CVE-2025-22219
6.8 MEDIUM

VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script …

Jan 30, 2025
CVE-2025-0872
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file /addpayment.php. The manipulation …

Jan 30, 2025
CVE-2025-23367
6.5 MEDIUM

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role …

Jan 30, 2025
CVE-2024-55417
4.3 MEDIUM

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user …

Jan 30, 2025
CVE-2024-55415
5.7 MEDIUM

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

Jan 30, 2025
CVE-2024-53615
6.5 MEDIUM

A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via …

Jan 30, 2025
CVE-2024-8494
4.3 MEDIUM

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 via the 'elementor-template' …

Jan 30, 2025
CVE-2024-13715
4.3 MEDIUM

The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in …

Jan 30, 2025
CVE-2024-13705
6.1 MEDIUM

The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all …

Jan 30, 2025
CVE-2024-13700
6.4 MEDIUM

The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, …

Jan 30, 2025
CVE-2024-13670
6.4 MEDIUM

The Music Sheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pn_msv' shortcode in all versions up to, and including, …

Jan 30, 2025
CVE-2024-13664
6.4 MEDIUM

The WP Post List Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpb_post_list_table' shortcode in all versions up to, and …

Jan 30, 2025
CVE-2024-13661
6.4 MEDIUM

The Table Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wptableeditor_vtabs' shortcode in all versions up to, and including, 1.5.1 …

Jan 30, 2025
CVE-2024-13652
4.3 MEDIUM

The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX …

Jan 30, 2025
CVE-2024-13596
6.5 MEDIUM

The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute …

Jan 30, 2025
CVE-2024-13549
6.4 MEDIUM

The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in all versions up to, and including, 1.3.26 …

Jan 30, 2025
CVE-2024-13512
6.1 MEDIUM

The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing …

Jan 30, 2025
CVE-2024-13460
6.4 MEDIUM

The WE – Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Testimonial Author Names in all versions up to, and including, …

Jan 30, 2025
CVE-2024-13400
6.4 MEDIUM

The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gutenberg" Block, specifically in the "align" attribute, …

Jan 30, 2025
CVE-2024-13349
6.4 MEDIUM

The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockdio-historical-chart' shortcode in all versions up to, and including, …

Jan 30, 2025
CVE-2024-12861
6.5 MEDIUM

The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via …

Jan 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.