CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43716
5.8 MEDIUM

A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the /client/index.php endpoint, an attacker can …

Apr 23, 2025
CVE-2025-2703
6.8 MEDIUM

The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in …

Apr 23, 2025
CVE-2025-1054
6.4 MEDIUM

The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the UI Counter, UI Icon Box, …

Apr 23, 2025
CVE-2024-10306
5.4 MEDIUM

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not …

Apr 23, 2025
CVE-2025-2595
5.3 MEDIUM

An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.

Apr 23, 2025
CVE-2025-0618
6.5 MEDIUM

A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protection event to the …

Apr 23, 2025
CVE-2025-1056
6.1 MEDIUM

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin …

Apr 23, 2025
CVE-2025-0926
5.9 MEDIUM

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing …

Apr 23, 2025
CVE-2025-37088
6.8 MEDIUM

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster …

Apr 22, 2025
CVE-2025-27087
5.5 MEDIUM

A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.

Apr 22, 2025
CVE-2025-29743
6.5 MEDIUM

D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

Apr 22, 2025
CVE-2025-26159
6.1 MEDIUM

Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can …

Apr 22, 2025
CVE-2025-31328
4.6 MEDIUM

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based …

Apr 22, 2025
CVE-2025-31327
4.3 MEDIUM

SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an …

Apr 22, 2025
CVE-2024-53569
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web …

Apr 22, 2025
CVE-2024-53568
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts …

Apr 22, 2025
CVE-2025-43952
6.1 MEDIUM

A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts …

Apr 22, 2025
CVE-2025-32964
4.6 MEDIUM

ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically …

Apr 22, 2025
CVE-2025-32961
6.4 MEDIUM

The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTTP requests. Prior to version …

Apr 22, 2025
CVE-2025-32960
6.4 MEDIUM

The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and …

Apr 22, 2025
CVE-2025-32959
6.5 MEDIUM

CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file storage implementation does not restrict the size …

Apr 22, 2025
CVE-2025-32952
6.5 MEDIUM

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, …

Apr 22, 2025
CVE-2025-32951
6.4 MEDIUM

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, …

Apr 22, 2025
CVE-2025-32950
6.5 MEDIUM

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, …

Apr 22, 2025
CVE-2025-32788
4.3 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker …

Apr 22, 2025
CVE-2023-44753
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

Apr 22, 2025
CVE-2023-43378
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 …

Apr 22, 2025
CVE-2025-27907
4.1 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from …

Apr 22, 2025
CVE-2025-28031
6.5 MEDIUM

TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.

Apr 22, 2025
CVE-2025-23175
6.1 MEDIUM

Multiple XSS (CWE-79)

Apr 22, 2025
CVE-2025-3472
6.5 MEDIUM

The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the …

Apr 22, 2025
CVE-2025-3458
6.4 MEDIUM

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due …

Apr 22, 2025
CVE-2025-3457
6.4 MEDIUM

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 …

Apr 22, 2025
CVE-2024-11299
5.3 MEDIUM

The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.37 via the WordPress core search feature. …

Apr 22, 2025
CVE-2025-46254
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Stored XSS.This issue affects Visual …

Apr 22, 2025
CVE-2025-46253
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit gutenkit-blocks-addon allows Stored XSS.This issue affects GutenKit: from n/a through …

Apr 22, 2025
CVE-2025-46250
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VPSUForm v-form allows Stored XSS.This issue affects VPSUForm: from n/a through …

Apr 22, 2025
CVE-2025-46249
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor allows Cross Site Request Forgery.This issue affects Simple calendar for Elementor: from n/a …

Apr 22, 2025
CVE-2025-46247
5.3 MEDIUM

Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Appointment Booking Calendar: from n/a through …

Apr 22, 2025
CVE-2025-46246
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers: from n/a through <= 3.3.3.

Apr 22, 2025
CVE-2025-46245
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM Ad Changer: from n/a through <= …

Apr 22, 2025
CVE-2025-46244
5.3 MEDIUM

Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Linked Variations for …

Apr 22, 2025
CVE-2025-46243
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows Cross Site Request Forgery.This issue affects Recover abandoned cart for WooCommerce: …

Apr 22, 2025
CVE-2025-46240
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored XSS.This issue affects Simple Download …

Apr 22, 2025
CVE-2025-46239
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This issue affects Theme Switcha: from …

Apr 22, 2025
CVE-2025-46238
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer List Last Changes list-last-changes allows Stored XSS.This issue affects List Last Changes: …

Apr 22, 2025
CVE-2025-46237
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affects Link Library: from …

Apr 22, 2025
CVE-2025-46236
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Stored XSS.This issue affects HTML Forms: …

Apr 22, 2025
CVE-2025-46235
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a …

Apr 22, 2025
CVE-2025-46233
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv: …

Apr 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.