CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23109
6.5 MEDIUM

Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in …

Jan 11, 2025
CVE-2025-23108
4.3 MEDIUM

Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the …

Jan 11, 2025
CVE-2024-12304
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link …

Jan 11, 2025
CVE-2025-0106
5.3 MEDIUM

A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.

Jan 11, 2025
CVE-2025-0104
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition …

Jan 11, 2025
CVE-2024-12505
6.4 MEDIUM

The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in all versions up to, and including, 5.0.2 due …

Jan 11, 2025
CVE-2024-12472
4.3 MEDIUM

The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to …

Jan 11, 2025
CVE-2024-12204
5.4 MEDIUM

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access due to …

Jan 11, 2025
CVE-2024-11327
6.1 MEDIUM

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Jan 11, 2025
CVE-2025-23112
6.1 MEDIUM

An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name …

Jan 10, 2025
CVE-2025-23111
4.7 MEDIUM

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. …

Jan 10, 2025
CVE-2025-23110
6.1 MEDIUM

An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an upload of a CSV …

Jan 10, 2025
CVE-2024-9133
6.6 MEDIUM

A user with administrator privileges is able to retrieve authentication tokens

Jan 10, 2025
CVE-2024-7142
4.6 MEDIUM

On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. …

Jan 10, 2025
CVE-2024-47518
6.4 MEDIUM

Specially constructed queries targeting ETM could discover active remote access sessions

Jan 10, 2025
CVE-2024-47517
6.8 MEDIUM

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

Jan 10, 2025
CVE-2024-7095
4.3 MEDIUM

On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the …

Jan 10, 2025
CVE-2024-5872
6.5 MEDIUM

On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane …

Jan 10, 2025
CVE-2024-54998
5.4 MEDIUM

MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.

Jan 10, 2025
CVE-2024-54997
5.4 MEDIUM

MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.

Jan 10, 2025
CVE-2024-54994
6.5 MEDIUM

MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.

Jan 10, 2025
CVE-2024-6437
5.8 MEDIUM

On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP …

Jan 10, 2025
CVE-2024-33299
4.7 MEDIUM

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the …

Jan 10, 2025
CVE-2024-33298
6.1 MEDIUM

Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint …

Jan 10, 2025
CVE-2024-33297
4.7 MEDIUM

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add …

Jan 10, 2025
CVE-2025-23079
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - ArticleFeedbackv5 extension allows Cross-Site Scripting (XSS).This issue …

Jan 10, 2025
CVE-2024-54910
4.7 MEDIUM

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

Jan 10, 2025
CVE-2025-23078
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue …

Jan 10, 2025
CVE-2024-57222
6.3 MEDIUM

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

Jan 10, 2025
CVE-2024-54687
6.1 MEDIUM

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

Jan 10, 2025
CVE-2024-57214
6.3 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

Jan 10, 2025
CVE-2024-57213
6.3 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.

Jan 10, 2025
CVE-2024-57212
5.1 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.

Jan 10, 2025
CVE-2024-54849
5.9 MEDIUM

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack.

Jan 10, 2025
CVE-2024-54847
5.9 MEDIUM

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack.

Jan 10, 2025
CVE-2024-54846
5.9 MEDIUM

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack.

Jan 10, 2025
CVE-2025-22600
6.5 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_doacao.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22599
6.5 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22596
6.5 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the modulos_visiveis.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2024-50807
6.1 MEDIUM

Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf extensions.

Jan 10, 2025
CVE-2025-23022
4.0 MEDIUM

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

Jan 10, 2025
CVE-2024-57822
4.0 MEDIUM

In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

Jan 10, 2025
CVE-2024-13318
5.3 MEDIUM

The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all …

Jan 10, 2025
CVE-2024-13183
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, …

Jan 10, 2025
CVE-2025-0311
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, …

Jan 10, 2025
CVE-2024-12606
4.3 MEDIUM

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is …

Jan 10, 2025
CVE-2024-12473
6.5 MEDIUM

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is …

Jan 10, 2025
CVE-2024-56377
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or …

Jan 9, 2025
CVE-2024-56376
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When …

Jan 9, 2025
CVE-2024-55226
5.4 MEDIUM

Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.

Jan 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.