CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3275
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, …

Apr 19, 2025
CVE-2025-1457
6.4 MEDIUM

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 19, 2025
CVE-2025-3284
4.3 MEDIUM

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Apr 19, 2025
CVE-2025-43903
4.3 MEDIUM

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Apr 18, 2025
CVE-2025-3796
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The …

Apr 18, 2025
CVE-2025-36625
4.3 MEDIUM

In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.

Apr 18, 2025
CVE-2025-32377
6.5 MEDIUM

Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa …

Apr 18, 2025
CVE-2025-25984
6.8 MEDIUM

An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.

Apr 18, 2025
CVE-2024-57493
5.5 MEDIUM

An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockopt function.

Apr 18, 2025
CVE-2025-28355
4.7 MEDIUM

Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the …

Apr 18, 2025
CVE-2025-29513
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.

Apr 18, 2025
CVE-2025-29512
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until …

Apr 18, 2025
CVE-2024-41447
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 18, 2025
CVE-2025-32796
6.5 MEDIUM

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or …

Apr 18, 2025
CVE-2025-32795
6.5 MEDIUM

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted …

Apr 18, 2025
CVE-2025-32389
6.5 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by …

Apr 18, 2025
CVE-2025-31120
5.3 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in …

Apr 18, 2025
CVE-2025-27599
6.5 MEDIUM

Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed …

Apr 18, 2025
CVE-2025-3792
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. …

Apr 18, 2025
CVE-2025-3791
5.3 MEDIUM

A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This vulnerability affects the function jx9MemObjStore of the file /data/src/benchmarks/unqlite/unqlite.c. The manipulation …

Apr 18, 2025
CVE-2025-2950
5.4 MEDIUM

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM …

Apr 18, 2025
CVE-2025-3790
5.3 MEDIUM

A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the component Apache …

Apr 18, 2025
CVE-2025-32790
6.3 MEDIUM

Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are …

Apr 18, 2025
CVE-2024-46089
6.3 MEDIUM

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

Apr 18, 2025
CVE-2024-49808
6.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization …

Apr 18, 2025
CVE-2024-45651
6.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate …

Apr 18, 2025
CVE-2025-3106
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions …

Apr 18, 2025
CVE-2025-3056
5.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due …

Apr 18, 2025
CVE-2025-40325
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard request with REQ_NOWAIT raid10_handle_discard should wait barrier before returning …

Apr 18, 2025
CVE-2025-39989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-from-user context Patch series "mm/hwpoison: Fix regressions in memory failure …

Apr 18, 2025
CVE-2025-39930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai() commit 419d1918105e ("ASoC: simple-card-utils: use __free(device_node) for device …

Apr 18, 2025
CVE-2025-39755
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_driver struct was still only using the old …

Apr 18, 2025
CVE-2025-39728
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due …

Apr 18, 2025
CVE-2025-39688
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against …

Apr 18, 2025
CVE-2025-38637
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue assertions In the current implementation, skbprio enqueue/dequeue contains an …

Apr 18, 2025
CVE-2025-38575
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free() instead of kfree() to properly free memory …

Apr 18, 2025
CVE-2025-38240
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr The function mtk_dp_wait_hpd_asserted() …

Apr 18, 2025
CVE-2025-38152
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdown There is case as below could trigger kernel dump: …

Apr 18, 2025
CVE-2025-38104
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRIOV …

Apr 18, 2025
CVE-2025-38049
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors Commit 6eac36bb9eb0 ("x86/resctrl: Allocate …

Apr 18, 2025
CVE-2025-37925
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type Syzbot has reported the following BUG: kernel …

Apr 18, 2025
CVE-2025-37893
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prologue() Vincent reported that running BPF progs with tailcalls …

Apr 18, 2025
CVE-2025-37860
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_param() Since cited commit, ef100_probe_main() and hence also ef100_check_design_params() run …

Apr 18, 2025
CVE-2025-3783
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Apr 18, 2025
CVE-2025-3598
6.1 MEDIUM

The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up …

Apr 18, 2025
CVE-2025-2162
4.8 MEDIUM

The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 18, 2025
CVE-2025-2613
4.4 MEDIUM

The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom logo …

Apr 18, 2025
CVE-2024-13650
6.4 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all …

Apr 18, 2025
CVE-2025-25427
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote …

Apr 18, 2025
CVE-2025-3124
4.3 MEDIUM

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise …

Apr 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.