CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-5932
4.8 MEDIUM

The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a parameter before outputting it back in the …

May 15, 2025
CVE-2023-5529
4.8 MEDIUM

The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2023-2334
5.4 MEDIUM

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access …

May 15, 2025
CVE-2025-30476
5.3 MEDIUM

Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial …

May 15, 2025
CVE-2024-56006
5.3 MEDIUM

Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1.

May 15, 2025
CVE-2024-51666
4.3 MEDIUM

Missing Authorization vulnerability in Tosin Oguntuyi Tours tours.This issue affects Tours: from n/a through <= 1.0.0.

May 15, 2025
CVE-2025-44110
5.4 MEDIUM

FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php.

May 15, 2025
CVE-2025-43853
5.5 MEDIUM

The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. …

May 15, 2025
CVE-2025-47580
5.4 MEDIUM

Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through …

May 15, 2025
CVE-2025-1647
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before …

May 15, 2025
CVE-2025-48051
4.7 MEDIUM

powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a …

May 15, 2025
CVE-2025-3440
5.5 MEDIUM

IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI …

May 15, 2025
CVE-2025-2527
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group …

May 15, 2025
CVE-2025-4701
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file …

May 15, 2025
CVE-2025-46053
5.1 MEDIUM

A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the …

May 15, 2025
CVE-2025-44185
5.4 MEDIUM

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.

May 15, 2025
CVE-2025-44183
6.1 MEDIUM

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the name, email, and mobile parameters.

May 15, 2025
CVE-2025-44182
6.1 MEDIUM

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum, enginenumber' in the /admin/edit-vehicle.php component. …

May 15, 2025
CVE-2025-44181
6.1 MEDIUM

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via the brandname parameter.

May 15, 2025
CVE-2025-44180
6.1 MEDIUM

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={brandId}.

May 15, 2025
CVE-2025-4696
6.3 MEDIUM

A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 15, 2025
CVE-2025-4695
6.3 MEDIUM

A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

May 15, 2025
CVE-2025-3446
4.3 MEDIUM

Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct permissions which allows authenticated users who …

May 15, 2025
CVE-2025-31947
5.8 MEDIUM

Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows …

May 15, 2025
CVE-2025-32738
5.3 MEDIUM

Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated …

May 15, 2025
CVE-2025-4737
6.2 MEDIUM

Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage.

May 15, 2025
CVE-2025-27524
5.3 MEDIUM

Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: …

May 15, 2025
CVE-2025-48027
5.4 MEDIUM

The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolution for pginaloginserver.

May 15, 2025
CVE-2025-3742
6.8 MEDIUM

The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, …

May 15, 2025
CVE-2025-48024
5.0 MEDIUM

In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.

May 15, 2025
CVE-2025-4591
6.4 MEDIUM

The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'weluka-map' shortcode in all versions up to, and including, 1.0.3 …

May 15, 2025
CVE-2025-4589
6.4 MEDIUM

The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt-map' shortcode in all versions up to, and including, 1.3.2 …

May 15, 2025
CVE-2025-4126
6.4 MEDIUM

The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in all versions up to, and including, 2.1.1 due …

May 15, 2025
CVE-2025-47783
6.1 MEDIUM

Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script …

May 14, 2025
CVE-2025-46836
6.6 MEDIUM

net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to …

May 14, 2025
CVE-2025-29691
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

May 14, 2025
CVE-2025-29690
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

May 14, 2025
CVE-2025-29689
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

May 14, 2025
CVE-2025-29688
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

May 14, 2025
CVE-2025-29686
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

May 14, 2025
CVE-2025-47888
5.9 MEDIUM

Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.

May 14, 2025
CVE-2025-47887
4.3 MEDIUM

Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username …

May 14, 2025
CVE-2025-47886
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username …

May 14, 2025
CVE-2025-44024
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exists due to insufficient sanitization of user input in the …

May 14, 2025
CVE-2024-56427
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, …

May 14, 2025
CVE-2025-25370
4.6 MEDIUM

An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the …

May 14, 2025
CVE-2024-57096
5.5 MEDIUM

An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.

May 14, 2025
CVE-2024-45516
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site …

May 14, 2025
CVE-2025-33104
4.4 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 14, 2025
CVE-2025-4664
4.3 MEDIUM

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

May 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.