CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5589
6.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 …

Jun 14, 2025
CVE-2025-5336
6.4 MEDIUM

The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 …

Jun 14, 2025
CVE-2025-4592
4.3 MEDIUM

The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 14, 2025
CVE-2025-4216
6.4 MEDIUM

The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and …

Jun 14, 2025
CVE-2025-4187
5.9 MEDIUM

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 …

Jun 14, 2025
CVE-2025-6059
4.3 MEDIUM

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing …

Jun 14, 2025
CVE-2025-6083
4.3 MEDIUM

In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search …

Jun 13, 2025
CVE-2025-6035
6.1 MEDIUM

A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image …

Jun 13, 2025
CVE-2025-48919
5.0 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 …

Jun 13, 2025
CVE-2025-48917
5.0 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie Compliance (GDPR Compliance) allows Cross-Site Scripting (XSS).This issue affects EU …

Jun 13, 2025
CVE-2025-48916
6.5 MEDIUM

Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.13.

Jun 13, 2025
CVE-2025-28380
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Jun 13, 2025
CVE-2025-46096
6.1 MEDIUM

Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component

Jun 13, 2025
CVE-2025-36506
6.5 MEDIUM

External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a …

Jun 13, 2025
CVE-2025-6012
5.5 MEDIUM

The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.5 due to …

Jun 13, 2025
CVE-2025-5923
6.4 MEDIUM

The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 4.8.1 …

Jun 13, 2025
CVE-2025-22242
5.6 MEDIUM

Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method which is exposed to all minions. The un-sanitized …

Jun 13, 2025
CVE-2025-22241
5.6 MEDIUM

File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. …

Jun 13, 2025
CVE-2025-22240
6.3 MEDIUM

Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the …

Jun 13, 2025
CVE-2025-22238
4.2 MEDIUM

Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write …

Jun 13, 2025
CVE-2025-22237
6.7 MEDIUM

An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and …

Jun 13, 2025
CVE-2024-38825
6.4 MEDIUM

The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. …

Jun 13, 2025
CVE-2025-5815
5.3 MEDIUM

The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all …

Jun 13, 2025
CVE-2025-5950
6.4 MEDIUM

The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versions up to, and including, 0.13.2 due to …

Jun 13, 2025
CVE-2025-5939
4.4 MEDIUM

The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.1 due …

Jun 13, 2025
CVE-2025-5938
5.3 MEDIUM

The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 13, 2025
CVE-2025-5930
4.3 MEDIUM

The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or …

Jun 13, 2025
CVE-2025-5928
4.3 MEDIUM

The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due …

Jun 13, 2025
CVE-2025-5926
6.1 MEDIUM

The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.4. This is due to missing …

Jun 13, 2025
CVE-2025-5841
6.4 MEDIUM

The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.9 …

Jun 13, 2025
CVE-2025-5233
6.4 MEDIUM

The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versions up to, and including, 4.3.2 due …

Jun 13, 2025
CVE-2025-5123
6.4 MEDIUM

The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, …

Jun 13, 2025
CVE-2025-4586
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-4585
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-4584
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-41234
6.5 MEDIUM

Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when …

Jun 12, 2025
CVE-2025-41233
6.8 MEDIUM

Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate …

Jun 12, 2025
CVE-2025-44091
5.4 MEDIUM

yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function.

Jun 12, 2025
CVE-2025-4418
4.4 MEDIUM

An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a …

Jun 12, 2025
CVE-2025-4417
5.5 MEDIUM

A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local …

Jun 12, 2025
CVE-2025-36539
6.5 MEDIUM

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI …

Jun 12, 2025
CVE-2025-2745
6.5 MEDIUM

A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges …

Jun 12, 2025
CVE-2025-49579
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted …

Jun 12, 2025
CVE-2025-49578
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing …

Jun 12, 2025
CVE-2025-49577
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can …

Jun 12, 2025
CVE-2025-49576
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing …

Jun 12, 2025
CVE-2025-49575
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing …

Jun 12, 2025
CVE-2025-49081
4.9 MEDIUM

There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions …

Jun 12, 2025
CVE-2023-45256
5.4 MEDIUM

Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, …

Jun 12, 2025
CVE-2025-29744
5.4 MEDIUM

pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.

Jun 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.