CVE Database

46976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-58335
5.0 MEDIUM

OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/VisualizerImpl.java.

Dec 24, 2025
CVE-2025-15050
6.3 MEDIUM

A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.php. Such manipulation of …

Dec 24, 2025
CVE-2025-14421
5.5 MEDIUM

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of pdfforge …

Dec 23, 2025
CVE-2025-14411
5.5 MEDIUM

Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda …

Dec 23, 2025
CVE-2025-14410
5.5 MEDIUM

Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda …

Dec 23, 2025
CVE-2025-14407
5.5 MEDIUM

Soda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda …

Dec 23, 2025
CVE-2025-14405
6.8 MEDIUM

PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phyiscally-present attackers to escalate privileges on affected installations of PDFsam Enhanced. An …

Dec 23, 2025
CVE-2025-13698
4.5 MEDIUM

Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Deciso OPNsense. …

Dec 23, 2025
CVE-2021-47738
5.4 MEDIUM

CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with …

Dec 23, 2025
CVE-2021-47737
5.4 MEDIUM

CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to …

Dec 23, 2025
CVE-2021-47733
6.1 MEDIUM

CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attackers can inject malicious scripts …

Dec 23, 2025
CVE-2021-47732
6.1 MEDIUM

CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered …

Dec 23, 2025
CVE-2021-47716
5.4 MEDIUM

Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', …

Dec 23, 2025
CVE-2025-65713
4.0 MEDIUM

Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal …

Dec 23, 2025
CVE-2025-65410
6.2 MEDIUM

A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input …

Dec 23, 2025
CVE-2025-45493
6.5 MEDIUM

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.

Dec 23, 2025
CVE-2025-68340
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of team_port_add Attempting to add a …

Dec 23, 2025
CVE-2025-66845
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoint reflects the id query parameter directly into the HTML …

Dec 23, 2025
CVE-2025-68559
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for …

Dec 23, 2025
CVE-2025-68557
4.3 MEDIUM

Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chakra test: from n/a through <= …

Dec 23, 2025
CVE-2025-68556
5.3 MEDIUM

Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9.

Dec 23, 2025
CVE-2025-68551
6.5 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form allows Retrieve Embedded Sensitive Data.This issue affects VPSUForm: from …

Dec 23, 2025
CVE-2025-68548
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Stored XSS.This issue affects Responsive Posts …

Dec 23, 2025
CVE-2025-14635
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, …

Dec 23, 2025
CVE-2025-14000
6.4 MEDIUM

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions …

Dec 23, 2025
CVE-2023-52210
5.3 MEDIUM

Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.0.

Dec 23, 2025
CVE-2025-14548
6.4 MEDIUM

The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all versions up to, and including, 1.3.16 due to …

Dec 23, 2025
CVE-2025-14163
4.3 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.11.53. This is due …

Dec 23, 2025
CVE-2025-14155
5.3 MEDIUM

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Dec 23, 2025
CVE-2025-67743
6.3 MEDIUM

Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP …

Dec 23, 2025
CVE-2025-68614
4.3 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules …

Dec 23, 2025
CVE-2025-68480
5.3 MEDIUM

Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 …

Dec 22, 2025
CVE-2025-67436
6.5 MEDIUM

Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme …

Dec 22, 2025
CVE-2023-53978
5.4 MEDIUM

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. …

Dec 22, 2025
CVE-2023-53977
5.4 MEDIUM

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new …

Dec 22, 2025
CVE-2023-53976
5.4 MEDIUM

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new …

Dec 22, 2025
CVE-2023-53961
4.3 MEDIUM

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages …

Dec 22, 2025
CVE-2022-50689
6.2 MEDIUM

Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can …

Dec 22, 2025
CVE-2022-50687
5.5 MEDIUM

Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers …

Dec 22, 2025
CVE-2021-47715
5.3 MEDIUM

Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit …

Dec 22, 2025
CVE-2021-47714
5.5 MEDIUM

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can …

Dec 22, 2025
CVE-2025-67291
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting …

Dec 22, 2025
CVE-2025-67290
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via …

Dec 22, 2025
CVE-2025-65837
5.4 MEDIUM

PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.

Dec 22, 2025
CVE-2025-65790
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or …

Dec 22, 2025
CVE-2024-25812
6.1 MEDIUM

MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.

Dec 22, 2025
CVE-2025-26787
4.7 MEDIUM

An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate …

Dec 22, 2025
CVE-2025-15033
6.5 MEDIUM

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This …

Dec 22, 2025
CVE-2024-35321
4.3 MEDIUM

MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parameter.

Dec 22, 2025
CVE-2024-25814
6.1 MEDIUM

MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.

Dec 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.