CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5933
4.3 MEDIUM

The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing …

Jul 4, 2025
CVE-2025-5924
4.3 MEDIUM

The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due …

Jul 4, 2025
CVE-2025-5567
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-url' DOM element attribute in all versions …

Jul 4, 2025
CVE-2025-52554
4.3 MEDIUM

n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can …

Jul 3, 2025
CVE-2025-45809
5.4 MEDIUM

SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

Jul 3, 2025
CVE-2025-6074
6.5 MEDIUM

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains …

Jul 3, 2025
CVE-2025-6071
5.3 MEDIUM

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to salted information to decrypt MQTT information. This …

Jul 3, 2025
CVE-2025-53502
6.5 MEDIUM

Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - FeaturedFeeds Extension: 1.39.X, 1.42.X, 1.43.X.

Jul 3, 2025
CVE-2025-53500
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects …

Jul 3, 2025
CVE-2025-53489
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue …

Jul 3, 2025
CVE-2025-48939
4.2 MEDIUM

tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that …

Jul 3, 2025
CVE-2025-53490
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue …

Jul 3, 2025
CVE-2025-45938
5.4 MEDIUM

Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName parameter.

Jul 3, 2025
CVE-2025-43713
6.5 MEDIUM

ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated …

Jul 3, 2025
CVE-2025-49618
5.8 MEDIUM

In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

Jul 3, 2025
CVE-2025-49595
4.9 MEDIUM

n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs …

Jul 3, 2025
CVE-2025-49032
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Gutenberg Blocks advanced-gutenberg allows Stored XSS.This issue affects Gutenberg Blocks: from n/a …

Jul 3, 2025
CVE-2025-3702
5.4 MEDIUM

Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Melapress File Monitor: from n/a through …

Jul 3, 2025
CVE-2025-2537
6.4 MEDIUM

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScript library (version 3.1) in various versions due to insufficient …

Jul 3, 2025
CVE-2025-2540
6.4 MEDIUM

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto library (version 3.1.6) in various versions due to insufficient input …

Jul 3, 2025
CVE-2025-27459
4.4 MEDIUM

The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.

Jul 3, 2025
CVE-2025-27458
6.5 MEDIUM

The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from …

Jul 3, 2025
CVE-2025-27457
6.5 MEDIUM

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.

Jul 3, 2025
CVE-2025-27455
4.3 MEDIUM

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking …

Jul 3, 2025
CVE-2025-27454
4.3 MEDIUM

The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitting a web request that they did …

Jul 3, 2025
CVE-2025-27453
5.3 MEDIUM

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

Jul 3, 2025
CVE-2025-27452
5.3 MEDIUM

The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for …

Jul 3, 2025
CVE-2025-27451
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Jul 3, 2025
CVE-2025-27450
6.5 MEDIUM

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to …

Jul 3, 2025
CVE-2025-27448
6.8 MEDIUM

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will …

Jul 3, 2025
CVE-2025-1711
4.3 MEDIUM

Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.

Jul 3, 2025
CVE-2025-1709
6.5 MEDIUM

Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).

Jul 3, 2025
CVE-2024-5647
6.4 MEDIUM

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient …

Jul 3, 2025
CVE-2025-38173
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/cesa - Handle zero-length skcipher requests Do not access random memory for zero-length skcipher …

Jul 3, 2025
CVE-2025-38171
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: power: supply: max77705: Fix workqueue error handling in probe The create_singlethread_workqueue() doesn't return error pointers, …

Jul 3, 2025
CVE-2025-38170
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Discard stale CPU state when handling SME traps The logic for handling SME traps …

Jul 3, 2025
CVE-2025-38169
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Avoid clobbering kernel FPSIMD state with SMSTOP On system with SME, a thread's kernel …

Jul 3, 2025
CVE-2025-38168
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf: arm-ni: Unregister PMUs on probe failure When a resource allocation fails in one clock …

Jul 3, 2025
CVE-2025-38167
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: handle hdr_first_de() return value The hdr_first_de() function returns a pointer to a struct NTFS_DE. …

Jul 3, 2025
CVE-2025-38166
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: fix ktls panic with sockmap [ 2172.936997] ------------[ cut here ]------------ [ 2172.936999] kernel …

Jul 3, 2025
CVE-2025-38165
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix panic when calling skb_linearize The panic can be reproduced by executing the …

Jul 3, 2025
CVE-2025-38164
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: zone: fix to avoid inconsistence in between SIT and SSA w/ below testcase, it …

Jul 3, 2025
CVE-2025-38163
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on sbi->total_valid_block_count syzbot reported a f2fs bug as below: …

Jul 3, 2025
CVE-2025-38162
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: prevent overflow in lookup table allocation When calculating the lookup table size, ensure …

Jul 3, 2025
CVE-2025-38161
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix error flow upon firmware failure for RQ destruction Upon RQ destruction if the …

Jul 3, 2025
CVE-2025-38160
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() devm_kasprintf() returns NULL when memory allocation fails. …

Jul 3, 2025
CVE-2025-38158
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: fix XQE dma address error The dma addresses of EQE and AEQE are wrong …

Jul 3, 2025
CVE-2025-38156
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Fix null-ptr-deref in mt7996_mmio_wed_init() devm_ioremap() returns NULL on error. Currently, mt7996_mmio_wed_init() does …

Jul 3, 2025
CVE-2025-38155
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: Fix null-ptr-deref in mt7915_mmio_wed_init() devm_ioremap() returns NULL on error. Currently, mt7915_mmio_wed_init() does …

Jul 3, 2025
CVE-2025-38151
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix hang when cma_netevent_callback fails to queue_work The cited commit fixed a crash when …

Jul 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.