CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35164
6.8 MEDIUM

The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a …

Jul 2, 2025
CVE-2025-39362
6.5 MEDIUM

Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue affects Mollie Payments for WooCommerce: from n/a through <= 8.0.2.

Jul 2, 2025
CVE-2025-4946
8.1 HIGH

The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the vikinger_delete_activity_media_ajax() function in all versions up …

Jul 2, 2025
CVE-2025-2330
6.4 MEDIUM

The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button+modal' widget in all versions up …

Jul 2, 2025
CVE-2025-27025
8.8 HIGH

The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is granted using a Basic …

Jul 2, 2025
CVE-2025-27024
6.5 MEDIUM

Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via SFTP connections. …

Jul 2, 2025
CVE-2025-27023
6.5 MEDIUM

Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via crafted …

Jul 2, 2025
CVE-2025-27022
7.5 HIGH

A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files via HTTP …

Jul 2, 2025
CVE-2025-27021
7.0 HIGH

The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/write physical memory via …

Jul 2, 2025
CVE-2025-24335
2.0 LOW

Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used …

Jul 2, 2025
CVE-2025-24334
3.3 LOW

The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release version by sending a specific …

Jul 2, 2025
CVE-2025-24333
6.4 MEDIUM

Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use …

Jul 2, 2025
CVE-2025-24332
7.1 HIGH

Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after performing a single login to the baseband system board. …

Jul 2, 2025
CVE-2025-24331
6.4 MEDIUM

The Single RAN baseband OAM service is intended to run as an unprivileged service. However, it initially starts with root privileges and assigns certain capabilities …

Jul 2, 2025
CVE-2025-24330
6.4 MEDIUM

Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path …

Jul 2, 2025
CVE-2025-24329
6.4 MEDIUM

Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path …

Jul 2, 2025
CVE-2025-24328
4.2 MEDIUM

Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN …

Jul 2, 2025
CVE-2025-6017
5.5 MEDIUM

A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows …

Jul 2, 2025
CVE-2024-13786
9.8 CRITICAL

The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted input in …

Jul 2, 2025
CVE-2025-6464
7.5 HIGH

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Jul 2, 2025
CVE-2024-13451
5.3 MEDIUM

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Jul 2, 2025
CVE-2025-6463
8.8 HIGH

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file …

Jul 2, 2025
CVE-2025-52463
3.1 LOW

Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerability is exploited, unintended E-mail may be sent when a …

Jul 2, 2025
CVE-2025-52462
6.1 MEDIUM

Cross-site scripting vulnerability exists in Active! mail 6 BuildInfo: 6.30.01004145 to 6.60.06008562. If this vulnerability is exploited, an arbitrary script may be executed on the …

Jul 2, 2025
CVE-2025-6687
6.4 MEDIUM

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and …

Jul 2, 2025
CVE-2025-6686
6.4 MEDIUM

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and …

Jul 2, 2025
CVE-2025-6459
8.8 HIGH

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jul 2, 2025
CVE-2025-6437
7.5 HIGH

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘oid’ parameter in all versions up …

Jul 2, 2025
CVE-2025-5817
7.2 HIGH

The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.7 via the wcta2w_get_urls(). …

Jul 2, 2025
CVE-2025-5746
9.8 CRITICAL

The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Jul 2, 2025
CVE-2025-5339
7.5 HIGH

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘bsa_pro_id’ parameter in all versions …

Jul 2, 2025
CVE-2025-5014
8.8 HIGH

The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the …

Jul 2, 2025
CVE-2025-52925
5.0 MEDIUM

In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.

Jul 2, 2025
CVE-2025-4689
9.8 CRITICAL

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in …

Jul 2, 2025
CVE-2025-4654
3.7 LOW

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in …

Jul 2, 2025
CVE-2025-4381
7.5 HIGH

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘$id’ variable of the getSpace() function …

Jul 2, 2025
CVE-2025-4380
8.1 HIGH

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Jul 2, 2025
CVE-2024-11405
6.1 MEDIUM

The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email and wpmp_reset_password_token parameters in all versions up …

Jul 2, 2025
CVE-2025-5692
6.3 MEDIUM

The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in …

Jul 2, 2025
CVE-2025-36630
8.4 HIGH

In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with …

Jul 2, 2025
CVE-2025-49741
7.4 HIGH

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Jul 1, 2025
CVE-2025-52101
9.8 CRITICAL

linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and …

Jul 1, 2025
CVE-2025-45006
9.1 CRITICAL

Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks.

Jul 1, 2025
CVE-2025-6600
4.3 MEDIUM

An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within …

Jul 1, 2025
CVE-2025-53104
9.1 CRITICAL

gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commit e6b4271, a command injection vulnerability was discovered in …

Jul 1, 2025
CVE-2025-48379
7.1 HIGH

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded …

Jul 1, 2025
CVE-2025-46259
5.4 MEDIUM

Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons …

Jul 1, 2025
CVE-2025-27153
6.5 MEDIUM

Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This can lead …

Jul 1, 2025
CVE-2025-53107
7.5 HIGH

@cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is a command injection vulnerability caused by the unsanitized …

Jul 1, 2025
CVE-2025-53103
5.8 MEDIUM

JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can …

Jul 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.