CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2269
6.1 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘image_id’ parameter in all versions …

Apr 12, 2025
CVE-2024-11679
4.4 MEDIUM

An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated …

Apr 11, 2025
CVE-2025-32079
6.5 MEDIUM

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments allows HTTP DoS.This issue affects Mediawiki - GrowthExperiments: from 1.39 through 1.43.

Apr 11, 2025
CVE-2025-32074
5.4 MEDIUM

Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Confirm Account Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Confirm …

Apr 11, 2025
CVE-2025-32073
5.4 MEDIUM

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediawiki - HTML Tags: from 1.39 through …

Apr 11, 2025
CVE-2025-32071
5.4 MEDIUM

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - …

Apr 11, 2025
CVE-2025-32070
5.4 MEDIUM

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - AJAX Poll Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - AJAX Poll Extension: from …

Apr 11, 2025
CVE-2025-32069
5.4 MEDIUM

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Media Info …

Apr 11, 2025
CVE-2025-32068
5.4 MEDIUM

Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawiki - OAuth Extension: from 1.39 through 1.43.

Apr 11, 2025
CVE-2025-32067
5.4 MEDIUM

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Growth Experiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Growth Experiments Extension: from …

Apr 11, 2025
CVE-2025-31935
6.2 MEDIUM

Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API may trigger an exception, …

Apr 11, 2025
CVE-2025-31354
4.3 MEDIUM

Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with crafted F2m parameters, which can lead to excessive CPU …

Apr 11, 2025
CVE-2023-42983
6.4 MEDIUM

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with …

Apr 11, 2025
CVE-2023-42982
6.4 MEDIUM

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with …

Apr 11, 2025
CVE-2023-42981
5.4 MEDIUM

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with …

Apr 11, 2025
CVE-2023-42973
4.0 MEDIUM

Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.

Apr 11, 2025
CVE-2023-42961
6.3 MEDIUM

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS …

Apr 11, 2025
CVE-2023-38614
4.3 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be …

Apr 11, 2025
CVE-2025-32427
5.4 MEDIUM

Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained …

Apr 11, 2025
CVE-2025-32426
4.6 MEDIUM

Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of …

Apr 11, 2025
CVE-2025-3422
5.4 MEDIUM

The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution …

Apr 11, 2025
CVE-2025-3421
6.1 MEDIUM

The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via …

Apr 11, 2025
CVE-2025-2575
6.4 MEDIUM

The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.1 due …

Apr 11, 2025
CVE-2025-2541
6.4 MEDIUM

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 …

Apr 11, 2025
CVE-2025-23387
5.3 MEDIUM

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them …

Apr 11, 2025
CVE-2024-52282
6.2 MEDIUM

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog …

Apr 11, 2025
CVE-2025-2128
6.5 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter in all versions up to, and including, 3.2.67 …

Apr 11, 2025
CVE-2025-1386
4.9 MEDIUM

When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker …

Apr 11, 2025
CVE-2025-26335
5.8 MEDIUM

Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote access …

Apr 11, 2025
CVE-2024-51461
4.3 MEDIUM

IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could …

Apr 11, 2025
CVE-2025-32809
6.4 MEDIUM

W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.

Apr 11, 2025
CVE-2025-32807
5.3 MEDIUM

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or …

Apr 11, 2025
CVE-2025-29918
6.2 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an …

Apr 10, 2025
CVE-2025-29917
6.2 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The bytes setting in the decode_base64 keyword is not properly …

Apr 10, 2025
CVE-2025-29916
6.2 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the …

Apr 10, 2025
CVE-2025-22232
5.3 MEDIUM

Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to Vault. Your application may be …

Apr 10, 2025
CVE-2025-32027
6.1 MEDIUM

Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer …

Apr 10, 2025
CVE-2025-29150
4.3 MEDIUM

BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.

Apr 10, 2025
CVE-2025-0362
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, …

Apr 10, 2025
CVE-2025-32391
6.4 MEDIUM

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file uploaded to HedgeDoc results in the possibility of …

Apr 10, 2025
CVE-2025-32383
4.3 MEDIUM

MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell …

Apr 10, 2025
CVE-2025-29088
5.6 MEDIUM

In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication …

Apr 10, 2025
CVE-2023-43037
6.5 MEDIUM

IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation.

Apr 10, 2025
CVE-2023-43035
4.0 MEDIUM

IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 allows web pages to be stored locally which can be read by another user on the system.

Apr 10, 2025
CVE-2023-42007
5.4 MEDIUM

IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Apr 10, 2025
CVE-2025-30148
5.4 MEDIUM

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could …

Apr 10, 2025
CVE-2025-2408
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions …

Apr 10, 2025
CVE-2025-25197
5.4 MEDIUM

Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page out of rather than …

Apr 10, 2025
CVE-2025-1677
6.5 MEDIUM

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to …

Apr 10, 2025
CVE-2024-11129
6.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers …

Apr 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.