CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50594
4.3 MEDIUM

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead …

Apr 2, 2025
CVE-2024-50385
6.5 MEDIUM

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to …

Apr 2, 2025
CVE-2024-50384
6.5 MEDIUM

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to …

Apr 2, 2025
CVE-2025-27556
5.8 MEDIUM

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, …

Apr 2, 2025
CVE-2025-21992
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera The HP 5MP Camera (USB ID 0408:5473) …

Apr 2, 2025
CVE-2025-21990
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flags PRT BOs may not have …

Apr 2, 2025
CVE-2025-21989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix missing .is_two_pixels_per_container Starting from 6.11, AMDGPU driver, while being loaded with amdgpu.dc=1, due …

Apr 2, 2025
CVE-2025-21988
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending …

Apr 2, 2025
CVE-2025-21987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_buffer Otherwise an uninitialized value can be returned if amdgpu_res_cleared …

Apr 2, 2025
CVE-2025-1805
5.3 MEDIUM

Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.

Apr 2, 2025
CVE-2025-2842
4.3 MEDIUM

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo …

Apr 2, 2025
CVE-2025-2786
4.3 MEDIUM

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This …

Apr 2, 2025
CVE-2025-3099
6.1 MEDIUM

The Advanced Search by My Solr Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This …

Apr 2, 2025
CVE-2025-3098
6.1 MEDIUM

The Video Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.0.0.3 due …

Apr 2, 2025
CVE-2025-3097
6.1 MEDIUM

The wp Time Machine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.0. This is due to …

Apr 2, 2025
CVE-2025-2513
6.4 MEDIUM

The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Apr 2, 2025
CVE-2025-2483
6.1 MEDIUM

The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘receip_address’ parameter in all versions up to, and including, 1.1.0 …

Apr 2, 2025
CVE-2024-13637
6.5 MEDIUM

The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin function in all …

Apr 2, 2025
CVE-2024-12410
4.9 MEDIUM

The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versions up to, and including, 3.2.32 due …

Apr 2, 2025
CVE-2024-45700
6.5 MEDIUM

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will …

Apr 2, 2025
CVE-2024-45699
5.4 MEDIUM

The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML …

Apr 2, 2025
CVE-2025-27244
5.9 MEDIUM

AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitive information may be obtained by …

Apr 2, 2025
CVE-2025-2779
6.5 MEDIUM

The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Apr 2, 2025
CVE-2025-3074
5.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Apr 2, 2025
CVE-2025-3073
5.4 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Apr 2, 2025
CVE-2025-3072
5.4 MEDIUM

Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Apr 2, 2025
CVE-2025-3071
5.4 MEDIUM

Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Apr 2, 2025
CVE-2025-3070
6.5 MEDIUM

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML …

Apr 2, 2025
CVE-2025-29982
6.8 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit …

Apr 2, 2025
CVE-2025-27694
5.3 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this …

Apr 2, 2025
CVE-2025-27693
4.9 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged …

Apr 2, 2025
CVE-2025-27692
4.7 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote …

Apr 2, 2025
CVE-2025-31135
5.3 MEDIUM

Go-Guerrilla SMTP Daemon is a lightweight SMTP server written in Go. Prior to 1.6.7, when ProxyOn is enabled, the PROXY command will be accepted multiple …

Apr 1, 2025
CVE-2023-46988
6.7 MEDIUM

Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor …

Apr 1, 2025
CVE-2025-31889
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor. This issue affects Extensions for Elementor: from n/a through …

Apr 1, 2025
CVE-2025-31819
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks.This issue affects Nova Blocks: from n/a through <= 2.1.8.

Apr 1, 2025
CVE-2025-31753
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser advanced-speed-increaser.This issue affects Advanced Speed Increaser: from n/a through <= 2.2.1.

Apr 1, 2025
CVE-2025-31628
5.3 MEDIUM

Missing Authorization vulnerability in SlicedInvoices Sliced Invoices sliced-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliced Invoices: from n/a through <= 3.10.0.

Apr 1, 2025
CVE-2025-31550
5.8 MEDIUM

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in thom4 WP-LESS wp-less allows Retrieve Embedded Sensitive Data.This issue affects WP-LESS: from n/a through …

Apr 1, 2025
CVE-2025-31525
4.3 MEDIUM

Missing Authorization vulnerability in WP Messiah WP Mobile Bottom Menu mobile-bottom-menu-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mobile Bottom Menu: …

Apr 1, 2025
CVE-2025-30853
5.4 MEDIUM

Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Adaptive Images: from n/a through …

Apr 1, 2025
CVE-2025-29049
6.3 MEDIUM

Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.

Apr 1, 2025
CVE-2025-29036
5.9 MEDIUM

An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.

Apr 1, 2025
CVE-2024-13941
5.3 MEDIUM

A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ouch::archive::zip::convert_zip_date_time of the file zip.rs. …

Apr 1, 2025
CVE-2003-20001
5.6 MEDIUM

An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time …

Apr 1, 2025
CVE-2025-26056
5.4 MEDIUM

A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of …

Apr 1, 2025
CVE-2025-26055
6.5 MEDIUM

An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.

Apr 1, 2025
CVE-2025-26054
5.4 MEDIUM

Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.

Apr 1, 2025
CVE-2025-29208
6.5 MEDIUM

CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.

Apr 1, 2025
CVE-2025-28132
4.6 MEDIUM

A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized …

Apr 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.