CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46232
4.3 MEDIUM

Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from …

Apr 22, 2025
CVE-2025-46231
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Cross Site Request Forgery.This issue affects affiliate-toolkit: from n/a through <= 3.7.3.

Apr 22, 2025
CVE-2025-46229
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= …

Apr 22, 2025
CVE-2025-46228
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows DOM-Based XSS.This issue affects Event post: from …

Apr 22, 2025
CVE-2025-46227
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts custom-related-posts allows Stored XSS.This issue affects Custom Related Posts: …

Apr 22, 2025
CVE-2025-46226
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher mpl-publisher allows Stored XSS.This issue affects MPL-Publisher: from n/a through <= …

Apr 22, 2025
CVE-2025-46225
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post …

Apr 22, 2025
CVE-2025-3518
4.3 MEDIUM

It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can …

Apr 22, 2025
CVE-2025-3814
6.4 MEDIUM

The Tax Switch for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class-name’ parameter in all versions up to, and including, …

Apr 22, 2025
CVE-2025-2839
6.4 MEDIUM

The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, …

Apr 22, 2025
CVE-2025-2300
5.5 MEDIUM

Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 …

Apr 22, 2025
CVE-2025-3577
4.9 MEDIUM

**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with …

Apr 22, 2025
CVE-2025-1732
6.7 MEDIUM

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an …

Apr 22, 2025
CVE-2025-3856
6.3 MEDIUM

A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/searchByPage. The manipulation …

Apr 22, 2025
CVE-2025-3855
4.3 MEDIUM

A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the …

Apr 22, 2025
CVE-2025-3849
4.3 MEDIUM

A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument …

Apr 22, 2025
CVE-2025-3843
4.3 MEDIUM

A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request …

Apr 21, 2025
CVE-2025-3842
6.3 MEDIUM

A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUserPic.action of the file src/com/phn/action/FileUpload.java. The manipulation of …

Apr 21, 2025
CVE-2025-32955
6.0 MEDIUM

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `disable-sudo` …

Apr 21, 2025
CVE-2025-28103
6.4 MEDIUM

Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.

Apr 21, 2025
CVE-2025-28102
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent …

Apr 21, 2025
CVE-2025-28099
4.3 MEDIUM

opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,

Apr 21, 2025
CVE-2025-32793
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable …

Apr 21, 2025
CVE-2025-28367
6.5 MEDIUM

mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file …

Apr 21, 2025
CVE-2025-28121
6.1 MEDIUM

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary …

Apr 21, 2025
CVE-2024-42699
6.5 MEDIUM

Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the …

Apr 21, 2025
CVE-2024-41446
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 21, 2025
CVE-2025-43973
6.8 MEDIUM

An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are …

Apr 21, 2025
CVE-2025-43972
6.8 MEDIUM

An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes …

Apr 21, 2025
CVE-2025-43970
4.3 MEDIUM

An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or …

Apr 21, 2025
CVE-2020-36845
5.3 MEDIUM

The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a …

Apr 20, 2025
CVE-2020-36844
6.1 MEDIUM

The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.

Apr 20, 2025
CVE-2025-43954
4.9 MEDIUM

QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.

Apr 20, 2025
CVE-2025-3830
6.3 MEDIUM

A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUpload of the file …

Apr 20, 2025
CVE-2025-43929
4.1 MEDIUM

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted …

Apr 20, 2025
CVE-2025-43928
5.8 MEDIUM

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username …

Apr 20, 2025
CVE-2025-43921
5.3 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that …

Apr 20, 2025
CVE-2025-43920
5.4 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters …

Apr 20, 2025
CVE-2025-43919
5.8 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private …

Apr 20, 2025
CVE-2025-43918
6.4 MEDIUM

SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain …

Apr 19, 2025
CVE-2025-3818
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of …

Apr 19, 2025
CVE-2025-3817
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file …

Apr 19, 2025
CVE-2025-3816
4.7 MEDIUM

A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task …

Apr 19, 2025
CVE-2025-3808
4.3 MEDIUM

A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. …

Apr 19, 2025
CVE-2025-3807
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/UploadController.java of the component …

Apr 19, 2025
CVE-2025-3805
5.3 MEDIUM

A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file check_id.py …

Apr 19, 2025
CVE-2025-3804
5.3 MEDIUM

A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 …

Apr 19, 2025
CVE-2025-3798
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminController.php of the …

Apr 19, 2025
CVE-2025-3661
6.4 MEDIUM

The SB Chart block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.2.6 …

Apr 19, 2025
CVE-2025-3797
4.7 MEDIUM

A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=delall. The manipulation of the …

Apr 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.