CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0561
6.3 MEDIUM

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-pig.php. The …

Jan 19, 2025
CVE-2024-49824
6.5 MEDIUM

IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through …

Jan 18, 2025
CVE-2024-49354
5.3 MEDIUM

IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.

Jan 18, 2025
CVE-2024-47106
5.3 MEDIUM

IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information from improper access restrictions that could aid in …

Jan 18, 2025
CVE-2024-51448
6.7 MEDIUM

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install …

Jan 18, 2025
CVE-2024-49338
4.4 MEDIUM

IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.

Jan 18, 2025
CVE-2025-0558
6.3 MEDIUM

A vulnerability classified as critical was found in TDuckCloud tduck-platform up to 4.0. This vulnerability affects the function QueryProThemeRequest of the file src/main/java/com/tduck/cloud/form/request/QueryProThemeRequest.java. The manipulation …

Jan 18, 2025
CVE-2025-0557
4.3 MEDIUM

A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part …

Jan 18, 2025
CVE-2024-13392
6.4 MEDIUM

The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode …

Jan 18, 2025
CVE-2025-0515
4.3 MEDIUM

The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can …

Jan 18, 2025
CVE-2025-0369
6.4 MEDIUM

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to …

Jan 18, 2025
CVE-2024-13519
4.4 MEDIUM

The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, …

Jan 18, 2025
CVE-2024-13517
4.4 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in …

Jan 18, 2025
CVE-2024-13433
6.4 MEDIUM

The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' shortcode in all versions up to, and including, …

Jan 18, 2025
CVE-2024-13432
6.1 MEDIUM

The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or …

Jan 18, 2025
CVE-2024-13393
6.4 MEDIUM

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_videos' shortcode in …

Jan 18, 2025
CVE-2024-13391
6.4 MEDIUM

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' …

Jan 18, 2025
CVE-2024-13385
6.4 MEDIUM

The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ssm' shortcode in all versions up to, and …

Jan 18, 2025
CVE-2024-13317
4.3 MEDIUM

The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due …

Jan 18, 2025
CVE-2024-12696
6.4 MEDIUM

The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videowhisper_picture_upload_guest shortcode in …

Jan 18, 2025
CVE-2024-12385
6.1 MEDIUM

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing …

Jan 18, 2025
CVE-2025-0554
4.4 MEDIUM

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value in version <= 4.1.25 due to insufficient …

Jan 18, 2025
CVE-2025-0318
5.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all …

Jan 18, 2025
CVE-2024-9020
5.4 MEDIUM

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jan 18, 2025
CVE-2024-13516
6.1 MEDIUM

The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, …

Jan 18, 2025
CVE-2024-13515
6.1 MEDIUM

The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'path' parameter in …

Jan 18, 2025
CVE-2024-12071
5.3 MEDIUM

The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data …

Jan 18, 2025
CVE-2024-11923
5.5 MEDIUM

Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior …

Jan 18, 2025
CVE-2018-9406
5.5 MEDIUM

In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privilege …

Jan 18, 2025
CVE-2018-9405
6.7 MEDIUM

In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Jan 18, 2025
CVE-2018-9447
5.5 MEDIUM

In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to …

Jan 17, 2025
CVE-2018-9384
4.4 MEDIUM

In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with …

Jan 17, 2025
CVE-2018-9383
4.4 MEDIUM

In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jan 17, 2025
CVE-2018-9379
5.5 MEDIUM

In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could lead …

Jan 17, 2025
CVE-2017-13322
5.5 MEDIUM

In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could …

Jan 17, 2025
CVE-2025-23207
6.3 MEDIUM

KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter …

Jan 17, 2025
CVE-2025-0541
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/edit_member.php. The …

Jan 17, 2025
CVE-2025-23039
5.2 MEDIUM

Caido is a web security auditing toolkit. A Cross-Site Scripting (XSS) vulnerability was identified in Caido v0.45.0 due to improper sanitization in the URL decoding …

Jan 17, 2025
CVE-2025-0540
6.3 MEDIUM

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /expadd.php. The …

Jan 17, 2025
CVE-2024-57252
4.3 MEDIUM

OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.

Jan 17, 2025
CVE-2024-57033
6.1 MEDIUM

WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.

Jan 17, 2025
CVE-2023-50738
4.3 MEDIUM

A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this downgrade protection has been identified.

Jan 17, 2025
CVE-2025-21185
6.5 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 17, 2025
CVE-2025-0536
6.3 MEDIUM

A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The …

Jan 17, 2025
CVE-2024-57372
6.1 MEDIUM

Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters

Jan 17, 2025
CVE-2024-57370
6.1 MEDIUM

Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.

Jan 17, 2025
CVE-2024-57369
6.4 MEDIUM

Clickjacking vulnerability in typecho v1.2.1.

Jan 17, 2025
CVE-2025-0535
6.3 MEDIUM

A vulnerability classified as critical has been found in Codezips Gym Management System 1.0. This affects an unknown part of the file /dashboard/admin/edit_mem_submit.php. The manipulation …

Jan 17, 2025
CVE-2025-0532
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/new_submit.php. …

Jan 17, 2025
CVE-2024-53683
4.4 MEDIUM

A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use …

Jan 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.