CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0441
6.5 MEDIUM

Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information from the system via a …

Jan 15, 2025
CVE-2025-0440
6.5 MEDIUM

Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Jan 15, 2025
CVE-2025-0439
6.5 MEDIUM

Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform …

Jan 15, 2025
CVE-2025-0435
6.5 MEDIUM

Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Jan 15, 2025
CVE-2024-35280
5.4 MEDIUM

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all …

Jan 15, 2025
CVE-2024-12818
6.4 MEDIUM

The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tv-video-player' shortcode in all versions up to, and including, …

Jan 15, 2025
CVE-2024-12423
6.1 MEDIUM

The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions …

Jan 15, 2025
CVE-2024-12403
6.1 MEDIUM

The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'awsmgallery' parameter in all versions up to, …

Jan 15, 2025
CVE-2024-10775
4.3 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.4.32 via the 'pafe-template' shortcode …

Jan 15, 2025
CVE-2025-0354
4.8 MEDIUM

Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 …

Jan 15, 2025
CVE-2024-7322
5.8 MEDIUM

A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change in node ID …

Jan 15, 2025
CVE-2024-11870
6.4 MEDIUM

The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and …

Jan 15, 2025
CVE-2024-13394
6.4 MEDIUM

The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortcode in all versions up to, and including, 1.4.18 …

Jan 15, 2025
CVE-2025-22394
6.7 MEDIUM

Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit …

Jan 15, 2025
CVE-2025-21101
6.6 MEDIUM

Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability. A local malicious user could potentially exploit this vulnerability during installation, leading to …

Jan 15, 2025
CVE-2024-13334
6.1 MEDIUM

The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter in all versions up to, and including, 1.8.1 due …

Jan 15, 2025
CVE-2025-22997
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML …

Jan 15, 2025
CVE-2025-22996
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML …

Jan 15, 2025
CVE-2024-57760
6.5 MEDIUM

JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.

Jan 15, 2025
CVE-2024-53277
5.4 MEDIUM

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, …

Jan 14, 2025
CVE-2024-47605
5.4 MEDIUM

silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON includes an HTML attribute which will …

Jan 14, 2025
CVE-2024-50861
6.1 MEDIUM

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved …

Jan 14, 2025
CVE-2024-50859
4.8 MEDIUM

The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in …

Jan 14, 2025
CVE-2024-50857
4.8 MEDIUM

The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user …

Jan 14, 2025
CVE-2024-45102
6.8 MEDIUM

A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using …

Jan 14, 2025
CVE-2024-10254
4.7 MEDIUM

A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a …

Jan 14, 2025
CVE-2024-10253
4.7 MEDIUM

A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system …

Jan 14, 2025
CVE-2025-23019
5.4 MEDIUM

IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.

Jan 14, 2025
CVE-2025-23018
5.4 MEDIUM

IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof …

Jan 14, 2025
CVE-2024-55945
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55923
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55922
5.4 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55920
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55894
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55893
4.3 MEDIUM

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, …

Jan 14, 2025
CVE-2024-55892
4.8 MEDIUM

TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and …

Jan 14, 2025
CVE-2025-23072
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RefreshSpecial Extension allows Cross-Site Scripting (XSS).This issue …

Jan 14, 2025
CVE-2025-23041
5.8 MEDIUM

Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only …

Jan 14, 2025
CVE-2024-56374
5.8 MEDIUM

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when …

Jan 14, 2025
CVE-2024-50349
4.7 MEDIUM

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. …

Jan 14, 2025
CVE-2024-48855
5.3 MEDIUM

Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure …

Jan 14, 2025
CVE-2024-48854
5.3 MEDIUM

Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure …

Jan 14, 2025
CVE-2025-23366
6.5 MEDIUM

A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed …

Jan 14, 2025
CVE-2025-21403
6.4 MEDIUM

On-Premises Data Gateway Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21393
6.3 MEDIUM

Microsoft SharePoint Server Spoofing Vulnerability

Jan 14, 2025
CVE-2025-21374
5.5 MEDIUM

Windows CSC Service Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21357
6.7 MEDIUM

Microsoft Outlook Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21341
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21340
5.5 MEDIUM

Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21336
5.6 MEDIUM

Windows Cryptographic Information Disclosure Vulnerability

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.