CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2811
5.7 MEDIUM

A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 …

Apr 26, 2025
CVE-2025-3915
4.3 MEDIUM

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function …

Apr 26, 2025
CVE-2025-1458
6.4 MEDIUM

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 26, 2025
CVE-2025-32984
6.1 MEDIUM

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.

Apr 25, 2025
CVE-2025-32979
6.5 MEDIUM

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

Apr 25, 2025
CVE-2024-30152
6.5 MEDIUM

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify …

Apr 25, 2025
CVE-2025-2070
5.0 MEDIUM

An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is …

Apr 25, 2025
CVE-2025-2069
5.0 MEDIUM

A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local …

Apr 25, 2025
CVE-2025-2068
5.0 MEDIUM

An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.

Apr 25, 2025
CVE-2025-46433
4.9 MEDIUM

In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

Apr 25, 2025
CVE-2025-46432
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs

Apr 25, 2025
CVE-2025-43016
5.4 MEDIUM

In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

Apr 25, 2025
CVE-2025-3647
4.3 MEDIUM

A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.

Apr 25, 2025
CVE-2025-3645
4.3 MEDIUM

A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

Apr 25, 2025
CVE-2025-3644
4.3 MEDIUM

A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

Apr 25, 2025
CVE-2025-3643
5.4 MEDIUM

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

Apr 25, 2025
CVE-2025-3640
4.3 MEDIUM

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as …

Apr 25, 2025
CVE-2025-3636
4.3 MEDIUM

A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.

Apr 25, 2025
CVE-2025-3628
4.3 MEDIUM

A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.

Apr 25, 2025
CVE-2025-3627
4.3 MEDIUM

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using …

Apr 25, 2025
CVE-2025-32045
5.3 MEDIUM

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

Apr 25, 2025
CVE-2025-28076
6.5 MEDIUM

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) …

Apr 25, 2025
CVE-2025-3634
4.3 MEDIUM

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can …

Apr 25, 2025
CVE-2025-28354
6.5 MEDIUM

An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted …

Apr 25, 2025
CVE-2025-3912
5.3 MEDIUM

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to …

Apr 25, 2025
CVE-2025-2986
5.5 MEDIUM

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web …

Apr 25, 2025
CVE-2025-3870
6.1 MEDIUM

The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.dec.2012. This is due to …

Apr 25, 2025
CVE-2025-46535
5.4 MEDIUM

Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a …

Apr 25, 2025
CVE-2025-46482
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz wp-quiz allows Stored XSS.This issue affects WP Quiz: from n/a …

Apr 25, 2025
CVE-2025-3868
6.1 MEDIUM

The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 …

Apr 25, 2025
CVE-2025-3867
6.1 MEDIUM

The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due …

Apr 25, 2025
CVE-2025-3866
6.1 MEDIUM

The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Apr 25, 2025
CVE-2025-3743
5.3 MEDIUM

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due …

Apr 25, 2025
CVE-2025-3923
5.3 MEDIUM

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 …

Apr 25, 2025
CVE-2025-3861
5.4 MEDIUM

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability …

Apr 25, 2025
CVE-2025-2580
4.9 MEDIUM

The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Apr 25, 2025
CVE-2025-0671
6.1 MEDIUM

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as …

Apr 25, 2025
CVE-2025-46599
6.8 MEDIUM

CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For …

Apr 25, 2025
CVE-2025-3775
6.5 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side …

Apr 25, 2025
CVE-2025-3752
6.4 MEDIUM

The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘preload’ parameter in all versions up to, …

Apr 25, 2025
CVE-2025-46595
6.4 MEDIUM

An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to …

Apr 25, 2025
CVE-2025-46547
5.4 MEDIUM

In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user …

Apr 25, 2025
CVE-2025-46545
4.4 MEDIUM

In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS …

Apr 25, 2025
CVE-2025-46544
6.4 MEDIUM

In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

Apr 25, 2025
CVE-2025-3749
6.4 MEDIUM

The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due …

Apr 24, 2025
CVE-2025-43861
4.4 MEDIUM

ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review …

Apr 24, 2025
CVE-2025-29529
6.5 MEDIUM

ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.

Apr 24, 2025
CVE-2022-44760
4.6 MEDIUM

Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

Apr 24, 2025
CVE-2022-44759
4.6 MEDIUM

Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

Apr 24, 2025
CVE-2024-30147
6.5 MEDIUM

Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

Apr 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.