CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31414
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder allows Stored XSS.This issue affects Cost Calculator Builder: …

Mar 31, 2025
CVE-2025-31412
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetProductGallery jet-woo-product-gallery allows DOM-Based XSS.This issue affects JetProductGallery: from n/a through <= …

Mar 31, 2025
CVE-2025-31043
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= …

Mar 31, 2025
CVE-2025-30987
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: …

Mar 31, 2025
CVE-2025-2978
6.3 MEDIUM

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=container&CKEditorFuncNum=1 …

Mar 31, 2025
CVE-2025-0613
6.1 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated …

Mar 31, 2025
CVE-2025-24852
4.6 MEDIUM

Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an attacker who can …

Mar 31, 2025
CVE-2025-2973
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file /Admin/student.php. The …

Mar 31, 2025
CVE-2025-2961
4.3 MEDIUM

A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function render_mav of the file /aa of the component …

Mar 30, 2025
CVE-2025-2960
6.5 MEDIUM

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the …

Mar 30, 2025
CVE-2025-2959
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is the function sub_4019A0 of the file …

Mar 30, 2025
CVE-2025-2958
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Mar 30, 2025
CVE-2025-2957
6.5 MEDIUM

A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function sub_401DB0 of the file /usr/sbin/httpd of the …

Mar 30, 2025
CVE-2025-2956
6.5 MEDIUM

A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the …

Mar 30, 2025
CVE-2025-2955
5.3 MEDIUM

A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/ExportIbmsConfig.sh of …

Mar 30, 2025
CVE-2025-2952
6.3 MEDIUM

A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /api/api.php?mod=upload&type=1. The …

Mar 30, 2025
CVE-2025-2951
6.3 MEDIUM

A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the file /api/data.php. The manipulation of …

Mar 30, 2025
CVE-2025-1734
5.3 MEDIUM

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the …

Mar 30, 2025
CVE-2025-1219
5.3 MEDIUM

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the …

Mar 30, 2025
CVE-2024-11180
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, …

Mar 29, 2025
CVE-2025-2840
5.3 MEDIUM

The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the …

Mar 29, 2025
CVE-2024-13557
6.5 MEDIUM

The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6. This is due …

Mar 29, 2025
CVE-2024-7577
4.4 MEDIUM

IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.

Mar 29, 2025
CVE-2024-51477
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.

Mar 29, 2025
CVE-2024-43186
5.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.

Mar 29, 2025
CVE-2025-28097
5.5 MEDIUM

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

Mar 28, 2025
CVE-2025-28096
5.4 MEDIUM

OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

Mar 28, 2025
CVE-2025-28094
6.5 MEDIUM

shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

Mar 28, 2025
CVE-2025-28093
6.3 MEDIUM

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.

Mar 28, 2025
CVE-2025-28092
6.3 MEDIUM

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.

Mar 28, 2025
CVE-2024-58129
5.5 MEDIUM

In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct …

Mar 28, 2025
CVE-2024-58128
5.5 MEDIUM

In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct …

Mar 28, 2025
CVE-2025-28254
5.4 MEDIUM

Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name …

Mar 28, 2025
CVE-2024-6875
6.5 MEDIUM

A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out …

Mar 28, 2025
CVE-2025-31164
6.6 MEDIUM

heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline.

Mar 28, 2025
CVE-2025-31163
6.6 MEDIUM

Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.

Mar 28, 2025
CVE-2025-31162
6.6 MEDIUM

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.

Mar 28, 2025
CVE-2025-2921
6.4 MEDIUM

A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the …

Mar 28, 2025
CVE-2025-2919
6.8 MEDIUM

A vulnerability was found in Netis WF-2404 1.1.124EN. It has been declared as critical. This vulnerability affects unknown code of the component UART. The manipulation …

Mar 28, 2025
CVE-2025-2917
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cms/file/read. The manipulation …

Mar 28, 2025
CVE-2025-2916
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Aishida Call Center System up to 20250314. This issue affects some unknown processing of …

Mar 28, 2025
CVE-2025-31010
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX simply-rets allows Cross Site Request Forgery.This issue affects SimplyRETS Real Estate IDX: from n/a …

Mar 28, 2025
CVE-2024-39311
5.4 MEDIUM

Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions prior to 10.0.2 of the `publify_core` …

Mar 28, 2025
CVE-2025-2877
6.5 MEDIUM

A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain …

Mar 28, 2025
CVE-2025-2865
6.1 MEDIUM

SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with …

Mar 28, 2025
CVE-2025-2864
6.1 MEDIUM

SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie …

Mar 28, 2025
CVE-2025-2860
5.3 MEDIUM

SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials that users have within the web (.xml file). …

Mar 28, 2025
CVE-2025-1781
6.5 MEDIUM

There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF). …

Mar 28, 2025
CVE-2025-0986
4.5 MEDIUM

IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certain Linux processor combability mode configurations, to cause undetected …

Mar 28, 2025
CVE-2025-31474
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in matthewprice1178 WP Database Optimizer wp-database-optimizer allows Cross Site Request Forgery.This issue affects WP Database Optimizer: from n/a through <= …

Mar 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.