CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52327
6.5 MEDIUM

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.

Jan 23, 2025
CVE-2024-12078
6.3 MEDIUM

ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control …

Jan 23, 2025
CVE-2024-10846
5.9 MEDIUM

The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of …

Jan 23, 2025
CVE-2024-57947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The initial buffer has to be inited to all-ones, …

Jan 23, 2025
CVE-2024-10539
5.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft Informatin Systems Uyumsoft ERP allows XSS Using Invalid Characters, Reflected …

Jan 23, 2025
CVE-2024-13422
6.1 MEDIUM

The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions …

Jan 23, 2025
CVE-2024-13389
6.4 MEDIUM

The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email' shortcode in all versions up to, and including, 1.3.4 due …

Jan 23, 2025
CVE-2024-13340
6.4 MEDIUM

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdf_results_by_ajax' shortcode in all versions …

Jan 23, 2025
CVE-2024-13236
6.5 MEDIUM

The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient …

Jan 23, 2025
CVE-2024-12504
6.4 MEDIUM

The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Jan 23, 2025
CVE-2024-12118
6.4 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all …

Jan 23, 2025
CVE-2025-0648
4.9 MEDIUM

Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of …

Jan 23, 2025
CVE-2025-0619
4.9 MEDIUM

Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords

Jan 23, 2025
CVE-2024-43708
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of …

Jan 23, 2025
CVE-2024-12043
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored …

Jan 23, 2025
CVE-2024-13511
4.3 MEDIUM

The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its …

Jan 23, 2025
CVE-2024-53299
6.5 MEDIUM

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server …

Jan 23, 2025
CVE-2024-52972
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot. This can …

Jan 23, 2025
CVE-2025-24530
6.4 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database …

Jan 23, 2025
CVE-2025-24529
6.4 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.

Jan 23, 2025
CVE-2024-43710
4.3 MEDIUM

A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to …

Jan 23, 2025
CVE-2024-42187
5.3 MEDIUM

BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local repository which is vulnerable …

Jan 23, 2025
CVE-2023-50309
6.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Jan 23, 2025
CVE-2023-32340
4.6 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Jan 23, 2025
CVE-2024-57724
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.

Jan 23, 2025
CVE-2024-57723
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.

Jan 23, 2025
CVE-2024-57721
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.

Jan 23, 2025
CVE-2024-57720
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.

Jan 23, 2025
CVE-2024-57719
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.

Jan 23, 2025
CVE-2024-12477
6.4 MEDIUM

The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due …

Jan 22, 2025
CVE-2024-56923
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute …

Jan 22, 2025
CVE-2024-56914
5.7 MEDIUM

D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.

Jan 22, 2025
CVE-2025-23047
6.5 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure for …

Jan 22, 2025
CVE-2025-24403
4.3 MEDIUM

A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials …

Jan 22, 2025
CVE-2025-24402
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using …

Jan 22, 2025
CVE-2025-24401
6.8 MEDIUM

Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically …

Jan 22, 2025
CVE-2025-24400
4.3 MEDIUM

Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create …

Jan 22, 2025
CVE-2025-24397
4.3 MEDIUM

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) …

Jan 22, 2025
CVE-2025-23028
5.3 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, …

Jan 22, 2025
CVE-2025-20128
5.3 MEDIUM

A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of …

Jan 22, 2025
CVE-2024-51457
4.4 MEDIUM

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user …

Jan 22, 2025
CVE-2025-23992
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion allows Stored XSS.This issue affects Toocheke Companion: from n/a …

Jan 22, 2025
CVE-2024-55488
6.5 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This …

Jan 22, 2025
CVE-2024-42013
6.4 MEDIUM

In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attacker with Windows administrative or debugging privileges can patch …

Jan 22, 2025
CVE-2024-42012
5.7 MEDIUM

GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext …

Jan 22, 2025
CVE-2024-10929
5.1 MEDIUM

In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of …

Jan 22, 2025
CVE-2025-24027
6.2 MEDIUM

ps_contactinfo, a PrestaShop module for displaying store contact information, has a cross-site scripting (XSS) vulnerability in versions up to and including 3.3.2. This can not …

Jan 22, 2025
CVE-2025-23684
4.3 MEDIUM

Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Debug Tool: from n/a through <= …

Jan 22, 2025
CVE-2025-23562
5.8 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-viewer allows Path Traversal.This issue affects XLSXviewer: from n/a through …

Jan 22, 2025
CVE-2025-23486
6.5 MEDIUM

Missing Authorization vulnerability in tamlyn Database Sync database-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database Sync: from n/a through <= 0.5.1.

Jan 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.