CVE Database

39635+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1702
7.5 HIGH

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via …

Mar 5, 2025
CVE-2024-13471
7.5 HIGH

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in …

Mar 5, 2025
CVE-2025-0956
8.1 HIGH

The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.4.0 via deserialization of …

Mar 5, 2025
CVE-2024-13777
8.1 HIGH

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Mar 5, 2025
CVE-2024-13232
8.8 HIGH

The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitrary SQL Execution and privilege escalation due …

Mar 5, 2025
CVE-2025-27685
7.5 HIGH

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.

Mar 5, 2025
CVE-2025-27684
7.5 HIGH

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Contains Sensitive Data V-2022-003.

Mar 5, 2025
CVE-2025-27683
8.8 HIGH

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type V-2022-006.

Mar 5, 2025
CVE-2025-27669
7.5 HIGH

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network Scanning (XSPA)/DoS OVE-20230524-0013.

Mar 5, 2025
CVE-2025-27664
8.8 HIGH

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient CSRF Protection OVE-20230524-0008.

Mar 5, 2025
CVE-2025-27644
7.8 HIGH

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-007.

Mar 5, 2025
CVE-2025-27639
8.8 HIGH

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015.

Mar 5, 2025
CVE-2025-1919
8.8 HIGH

Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via …

Mar 5, 2025
CVE-2025-1918
8.8 HIGH

Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via …

Mar 5, 2025
CVE-2025-1916
8.8 HIGH

Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to potentially …

Mar 5, 2025
CVE-2025-1915
8.1 HIGH

Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who convinced a …

Mar 5, 2025
CVE-2025-1914
8.8 HIGH

Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out of bounds memory access via a …

Mar 5, 2025
CVE-2025-1966
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. …

Mar 5, 2025
CVE-2024-0114
8.1 HIGH

NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the …

Mar 5, 2025
CVE-2025-1965
7.3 HIGH

A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation …

Mar 5, 2025
CVE-2025-1964
7.3 HIGH

A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Mar 5, 2025
CVE-2025-1963
7.3 HIGH

A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. …

Mar 5, 2025
CVE-2025-1962
7.3 HIGH

A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been classified as critical. This affects an unknown part of the file /admin/addroom.php. …

Mar 5, 2025
CVE-2025-1959
7.3 HIGH

A vulnerability, which was classified as critical, was found in Codezips Gym Management System 1.0. Affected is an unknown function of the file /change_s_pwd.php. The …

Mar 4, 2025
CVE-2025-25426
7.2 HIGH

yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.

Mar 4, 2025
CVE-2025-1956
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component …

Mar 4, 2025
CVE-2025-1954
7.3 HIGH

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Mar 4, 2025
CVE-2021-41719
7.5 HIGH

Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive …

Mar 4, 2025
CVE-2020-23438
7.8 HIGH

Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.

Mar 4, 2025
CVE-2025-1259
7.7 HIGH

On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result …

Mar 4, 2025
CVE-2025-1080
7.8 HIGH

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In …

Mar 4, 2025
CVE-2025-1952
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/password-recovery.php. …

Mar 4, 2025
CVE-2024-41147
7.7 HIGH

An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker …

Mar 4, 2025
CVE-2024-10930
7.8 HIGH

An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

Mar 4, 2025
CVE-2025-27111
7.5 HIGH

Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by …

Mar 4, 2025
CVE-2025-23368
8.1 HIGH

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time …

Mar 4, 2025
CVE-2024-9149
8.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection.This issue affects E-Commerce …

Mar 4, 2025
CVE-2024-50705
7.1 HIGH

Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.

Mar 4, 2025
CVE-2025-1943
8.2 HIGH

Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Mar 4, 2025
CVE-2025-1940
7.1 HIGH

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching …

Mar 4, 2025
CVE-2025-1937
7.5 HIGH

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of …

Mar 4, 2025
CVE-2025-1936
7.3 HIGH

jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the …

Mar 4, 2025
CVE-2025-1933
7.6 HIGH

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them …

Mar 4, 2025
CVE-2025-1932
8.1 HIGH

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox …

Mar 4, 2025
CVE-2025-1931
7.5 HIGH

It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was …

Mar 4, 2025
CVE-2025-1930
8.8 HIGH

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led …

Mar 4, 2025
CVE-2025-22226
7.1 HIGH KEV

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a …

Mar 4, 2025
CVE-2025-22225
8.2 HIGH KEV

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an …

Mar 4, 2025
CVE-2024-58045
8.6 HIGH

Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.

Mar 4, 2025
CVE-2024-58044
8.4 HIGH

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

Mar 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.