CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27571
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel …

Apr 16, 2025
CVE-2025-0101
6.5 MEDIUM

A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This …

Apr 16, 2025
CVE-2025-3675
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServerCfg of the file …

Apr 16, 2025
CVE-2025-3674
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file …

Apr 16, 2025
CVE-2025-3247
5.3 MEDIUM

The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due …

Apr 16, 2025
CVE-2024-10680
4.8 MEDIUM

The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such …

Apr 16, 2025
CVE-2025-3668
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The …

Apr 16, 2025
CVE-2025-3667
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Apr 16, 2025
CVE-2025-22018
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_impos_rcvd() receives the msg, it can trigger Null Pointer …

Apr 16, 2025
CVE-2025-3666
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The …

Apr 16, 2025
CVE-2025-3665
5.3 MEDIUM

A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. …

Apr 16, 2025
CVE-2025-3664
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads …

Apr 16, 2025
CVE-2025-3663
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of …

Apr 16, 2025
CVE-2025-2314
6.4 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 16, 2025
CVE-2024-13452
6.1 MEDIUM

The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.29. This is due …

Apr 16, 2025
CVE-2025-30100
6.7 MEDIUM

Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 contain an Improper Access Control Vulnerability. A low privileged attacker with local access could potentially exploit …

Apr 16, 2025
CVE-2025-32385
5.3 MEDIUM

EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to display iframes with arbitrary URLs. As the sandbox …

Apr 16, 2025
CVE-2025-32388
5.4 MEDIUM

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsanitized search param names cause XSS vulnerability. You …

Apr 15, 2025
CVE-2025-25458
4.6 MEDIUM

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

Apr 15, 2025
CVE-2025-25453
4.6 MEDIUM

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.

Apr 15, 2025
CVE-2025-22911
5.6 MEDIUM

RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.

Apr 15, 2025
CVE-2025-32782
5.3 MEDIUM

Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent …

Apr 15, 2025
CVE-2025-31950
5.3 MEDIUM

An unauthenticated attacker can obtain EV charger energy consumption information of other users.

Apr 15, 2025
CVE-2025-31945
5.3 MEDIUM

An unauthenticated attacker can obtain other users' charger information.

Apr 15, 2025
CVE-2025-31654
5.3 MEDIUM

An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").

Apr 15, 2025
CVE-2025-31360
6.5 MEDIUM

Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.

Apr 15, 2025
CVE-2025-31147
5.3 MEDIUM

Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

Apr 15, 2025
CVE-2025-30982
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookProgress by Stormhill Media mybookprogress allows Stored XSS.This issue affects MyBookProgress by …

Apr 15, 2025
CVE-2025-30966
5.4 MEDIUM

Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a through n/a.

Apr 15, 2025
CVE-2025-30512
6.5 MEDIUM

Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

Apr 15, 2025
CVE-2025-30257
5.3 MEDIUM

Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.

Apr 15, 2025
CVE-2025-27929
5.3 MEDIUM

Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.

Apr 15, 2025
CVE-2025-27927
5.3 MEDIUM

An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

Apr 15, 2025
CVE-2025-27892
6.8 MEDIUM

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and …

Apr 15, 2025
CVE-2025-27719
5.3 MEDIUM

Unauthenticated attackers can query an API endpoint and get device details.

Apr 15, 2025
CVE-2025-27575
5.3 MEDIUM

An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.

Apr 15, 2025
CVE-2025-27565
5.3 MEDIUM

An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

Apr 15, 2025
CVE-2025-27561
5.3 MEDIUM

Unauthenticated attackers can rename "rooms" of arbitrary users.

Apr 15, 2025
CVE-2025-26998
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a …

Apr 15, 2025
CVE-2025-26996
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through …

Apr 15, 2025
CVE-2025-26951
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in covertnine C9 Blocks c9-blocks allows DOM-Based XSS.This issue affects C9 Blocks: from n/a …

Apr 15, 2025
CVE-2025-26950
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonsPress Nepali Date Converter nepali-date-converter allows Stored XSS.This issue affects Nepali Date Converter: …

Apr 15, 2025
CVE-2025-26934
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphthemes Glossy Blog glossy-blog allows Stored XSS.This issue affects Glossy Blog: from n/a …

Apr 15, 2025
CVE-2025-26930
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Home Services home-services allows DOM-Based XSS.This issue affects Home Services: from n/a …

Apr 15, 2025
CVE-2025-26919
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainá taina allows Stored XSS.This issue affects Tainá: from n/a through < …

Apr 15, 2025
CVE-2025-26906
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows DOM-Based XSS.This issue affects WP …

Apr 15, 2025
CVE-2025-26903
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery inpost-gallery allows Cross Site Request Forgery.This issue affects InPost Gallery: from n/a through <= 2.1.4.3.

Apr 15, 2025
CVE-2025-26880
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar skt-skill-bar allows Stored XSS.This issue affects SKT Skill Bar: …

Apr 15, 2025
CVE-2025-26870
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows DOM-Based XSS.This issue affects JetEngine: from n/a through <= …

Apr 15, 2025
CVE-2025-26857
5.3 MEDIUM

Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

Apr 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.