CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12451
6.4 MEDIUM

The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode in all versions up to, and including, 1.07 …

Jan 30, 2025
CVE-2024-12444
6.4 MEDIUM

The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcode in all versions up to, and including, 4.5.0 …

Jan 30, 2025
CVE-2024-12320
6.1 MEDIUM

The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due …

Jan 30, 2025
CVE-2024-12299
6.1 MEDIUM

The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due …

Jan 30, 2025
CVE-2024-12177
6.1 MEDIUM

The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up …

Jan 30, 2025
CVE-2024-12102
4.3 MEDIUM

The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 via the 'elementor-template' shortcode due to …

Jan 30, 2025
CVE-2024-11583
4.3 MEDIUM

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a …

Jan 30, 2025
CVE-2024-10847
6.4 MEDIUM

The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 18 due …

Jan 30, 2025
CVE-2025-0870
5.6 MEDIUM

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in …

Jan 30, 2025
CVE-2025-0869
4.3 MEDIUM

A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Jan 30, 2025
CVE-2024-13466
6.4 MEDIUM

The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, …

Jan 30, 2025
CVE-2024-13380
6.4 MEDIUM

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, …

Jan 30, 2025
CVE-2025-0746
6.1 MEDIUM

A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging …

Jan 30, 2025
CVE-2025-0743
5.3 MEDIUM

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to …

Jan 30, 2025
CVE-2025-0742
5.8 MEDIUM

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others …

Jan 30, 2025
CVE-2022-43916
6.8 MEDIUM

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, …

Jan 30, 2025
CVE-2025-0741
5.8 MEDIUM

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users …

Jan 30, 2025
CVE-2024-13706
6.1 MEDIUM

The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in all versions up to, and including, 1.0.1 …

Jan 30, 2025
CVE-2024-12524
6.4 MEDIUM

The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-login-button' shortcode in all versions up to, and including, …

Jan 30, 2025
CVE-2024-12409
6.1 MEDIUM

The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due …

Jan 30, 2025
CVE-2025-23007
5.5 MEDIUM

A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.

Jan 30, 2025
CVE-2025-0861
4.9 MEDIUM

The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 3.0.1 …

Jan 30, 2025
CVE-2025-0860
6.1 MEDIUM

The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in all versions up to, and including, …

Jan 30, 2025
CVE-2024-13758
6.5 MEDIUM

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is …

Jan 30, 2025
CVE-2024-13732
6.4 MEDIUM

The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, …

Jan 30, 2025
CVE-2024-13470
6.4 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode …

Jan 30, 2025
CVE-2024-13642
6.4 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hotspot widget in all versions up to, …

Jan 30, 2025
CVE-2024-13457
5.3 MEDIUM

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the …

Jan 30, 2025
CVE-2024-12921
6.4 MEDIUM

The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcode in all versions up to, and including, 2.4.6 due …

Jan 30, 2025
CVE-2024-12709
4.3 MEDIUM

The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Jan 30, 2025
CVE-2024-12163
6.5 MEDIUM

The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.

Jan 30, 2025
CVE-2024-10309
5.9 MEDIUM

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which …

Jan 30, 2025
CVE-2025-0662
4.9 MEDIUM

In some cases, the ktrace facility will log the contents of kernel structures to userspace. In one such case, ktrace dumps a variable-sized sockaddr to …

Jan 30, 2025
CVE-2025-0374
6.5 MEDIUM

When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the …

Jan 30, 2025
CVE-2025-0373
6.0 MEDIUM

On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destination FID buffer by 4 bytes, a stack buffer …

Jan 30, 2025
CVE-2025-0849
6.3 MEDIUM

A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the …

Jan 30, 2025
CVE-2025-0848
6.5 MEDIUM

A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file …

Jan 30, 2025
CVE-2025-0844
4.3 MEDIUM

A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jan 30, 2025
CVE-2024-57513
6.5 MEDIUM

A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.

Jan 29, 2025
CVE-2024-51182
6.1 MEDIUM

HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML code via the "erro" parameter.

Jan 29, 2025
CVE-2025-24795
4.4 MEDIUM

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and …

Jan 29, 2025
CVE-2025-24794
6.7 MEDIUM

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and …

Jan 29, 2025
CVE-2025-24788
5.0 MEDIUM

snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages …

Jan 29, 2025
CVE-2025-0840
5.0 MEDIUM

A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The …

Jan 29, 2025
CVE-2025-24882
5.2 MEDIUM

regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This …

Jan 29, 2025
CVE-2025-24790
4.4 MEDIUM

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability …

Jan 29, 2025
CVE-2025-24791
4.4 MEDIUM

snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential …

Jan 29, 2025
CVE-2023-37413
5.3 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.

Jan 29, 2025
CVE-2023-37412
4.4 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.

Jan 29, 2025
CVE-2023-37398
5.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise …

Jan 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.