CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27980
6.5 MEDIUM

cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.

Apr 15, 2025
CVE-2025-29280
4.8 MEDIUM

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and …

Apr 15, 2025
CVE-2025-28136
6.5 MEDIUM

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.

Apr 15, 2025
CVE-2025-3608
6.5 MEDIUM

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability was fixed …

Apr 15, 2025
CVE-2025-32946
5.3 MEDIUM

This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the …

Apr 15, 2025
CVE-2025-32945
4.3 MEDIUM

The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner …

Apr 15, 2025
CVE-2025-32944
6.5 MEDIUM

The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner. If user import is enabled (which is …

Apr 15, 2025
CVE-2025-32103
5.0 MEDIUM

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC …

Apr 15, 2025
CVE-2025-32102
5.0 MEDIUM

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ …

Apr 15, 2025
CVE-2025-30965
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.

Apr 15, 2025
CVE-2025-30964
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photography: from n/a through < 7.7.6.

Apr 15, 2025
CVE-2025-26990
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server Side Request Forgery.This issue affects Royal Elementor Addons: from n/a through …

Apr 15, 2025
CVE-2025-26982
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächler DSGVO Youtube dsgvo-youtube allows DOM-Based XSS.This issue affects DSGVO Youtube: from …

Apr 15, 2025
CVE-2025-26955
4.3 MEDIUM

Missing Authorization vulnerability in vowelweb Industrial Lite industrial-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Industrial Lite: from n/a through <= 1.0.8.

Apr 15, 2025
CVE-2025-26745
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSTheme RS Elements Elementor Addon rselements-lite allows Stored XSS.This issue affects RS Elements …

Apr 15, 2025
CVE-2025-26744
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows DOM-Based XSS.This issue affects JetBlog: from n/a through <= …

Apr 15, 2025
CVE-2025-1688
5.5 MEDIUM

Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configuration password after the upgrading from older versions using specific installers. …

Apr 15, 2025
CVE-2025-2083
6.4 MEDIUM

The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ parameter in all versions up to, and including, …

Apr 15, 2025
CVE-2025-3622
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file …

Apr 15, 2025
CVE-2025-3576
5.9 MEDIUM

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 …

Apr 15, 2025
CVE-2025-32993
6.5 MEDIUM

Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.

Apr 15, 2025
CVE-2025-2225
6.4 MEDIUM

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rael_title_tag' …

Apr 15, 2025
CVE-2024-13610
4.8 MEDIUM

The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users …

Apr 15, 2025
CVE-2024-13207
4.8 MEDIUM

The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users …

Apr 15, 2025
CVE-2025-3573
6.1 MEDIUM

Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder …

Apr 15, 2025
CVE-2025-29984
6.7 MEDIUM

Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, …

Apr 15, 2025
CVE-2025-29983
6.7 MEDIUM

Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access …

Apr 15, 2025
CVE-2025-3612
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part of the file /visualization of the component …

Apr 15, 2025
CVE-2025-3470
4.9 MEDIUM

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all …

Apr 15, 2025
CVE-2025-32997
4.0 MEDIUM

In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.

Apr 15, 2025
CVE-2025-32996
4.0 MEDIUM

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.

Apr 15, 2025
CVE-2025-32987
6.0 MEDIUM

Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

Apr 15, 2025
CVE-2025-3593
6.3 MEDIUM

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Upload of the file /admin/upload/authorImg/. The …

Apr 14, 2025
CVE-2025-3590
6.3 MEDIUM

A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation …

Apr 14, 2025
CVE-2025-3589
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affected is an unknown function of the file /manage_class.php. …

Apr 14, 2025
CVE-2025-3588
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue affects the function apply of the file org/jsonschema2pojo/rules/SchemaRule.java of …

Apr 14, 2025
CVE-2022-43852
5.3 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.

Apr 14, 2025
CVE-2022-43851
5.9 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Apr 14, 2025
CVE-2022-43850
5.4 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Apr 14, 2025
CVE-2022-43847
5.4 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow …

Apr 14, 2025
CVE-2022-43840
4.3 MEDIUM

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or …

Apr 14, 2025
CVE-2025-3587
6.3 MEDIUM

A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /getTeacherList. The manipulation leads to improper …

Apr 14, 2025
CVE-2025-3585
6.3 MEDIUM

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP …

Apr 14, 2025
CVE-2025-29720
4.8 MEDIUM

Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.

Apr 14, 2025
CVE-2025-2572
5.6 MEDIUM

In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.

Apr 14, 2025
CVE-2025-3571
6.3 MEDIUM

A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnerability affects unknown code of the …

Apr 14, 2025
CVE-2025-32912
6.5 MEDIUM

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.

Apr 14, 2025
CVE-2025-32910
6.5 MEDIUM

A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.

Apr 14, 2025
CVE-2025-32909
5.3 MEDIUM

A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the …

Apr 14, 2025
CVE-2025-2475
5.4 MEDIUM

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot …

Apr 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.