CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24972
4.3 MEDIUM

Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, in specific circumstances, users could …

Mar 26, 2025
CVE-2025-24808
4.3 MEDIUM

Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, someone who is about to …

Mar 26, 2025
CVE-2025-23203
5.5 MEDIUM

Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4 on …

Mar 26, 2025
CVE-2022-39163
4.7 MEDIUM

IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could …

Mar 26, 2025
CVE-2025-2228
5.7 MEDIUM

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Mar 26, 2025
CVE-2025-1769
4.9 MEDIUM

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, …

Mar 26, 2025
CVE-2025-1312
6.4 MEDIUM

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttonTextColor’ parameter in all versions up to, …

Mar 26, 2025
CVE-2024-13411
6.4 MEDIUM

The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the updated_user() function. …

Mar 26, 2025
CVE-2025-2596
5.3 MEDIUM

Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)

Mar 26, 2025
CVE-2025-27552
4.0 MEDIUM

DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files Crypt/Eksblowfish/Bcrypt.pm. This issue affects …

Mar 26, 2025
CVE-2025-27551
4.0 MEDIUM

DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files lib/DBIx/Class/EncodedColumn/Digest.pm. This issue affects …

Mar 26, 2025
CVE-2025-1703
6.4 MEDIUM

The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 3.2.7 due …

Mar 26, 2025
CVE-2025-1440
5.3 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, …

Mar 26, 2025
CVE-2025-1439
6.4 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 …

Mar 26, 2025
CVE-2025-1437
6.4 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.2 …

Mar 26, 2025
CVE-2025-1310
6.5 MEDIUM

The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11 via the 'job_postings_get_file' parameter. This …

Mar 26, 2025
CVE-2025-2167
5.4 MEDIUM

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcodes in all versions up to, and including, 5.9.9 …

Mar 26, 2025
CVE-2024-13702
6.4 MEDIUM

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler' and 'vCitaSchedulingCalendar' shortcodes in all …

Mar 26, 2025
CVE-2024-30155
5.5 MEDIUM

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie …

Mar 26, 2025
CVE-2023-52972
5.5 MEDIUM

Huawei PCs have a vulnerability that allows low-privilege users to bypass SDDL permission checks . Successful exploitation this vulnerability could lead to termination of some …

Mar 26, 2025
CVE-2025-1784
6.4 MEDIUM

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and …

Mar 26, 2025
CVE-2024-11847
4.8 MEDIUM

The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious …

Mar 26, 2025
CVE-2025-30742
5.3 MEDIUM

httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req string would not have a final '\0' character.

Mar 26, 2025
CVE-2025-2576
6.4 MEDIUM

The Ayyash Studio — The kick-start kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, …

Mar 26, 2025
CVE-2025-2573
6.4 MEDIUM

The Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads …

Mar 26, 2025
CVE-2025-2165
6.1 MEDIUM

The SH Email Alert plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mid' parameter in all versions up to, and including, 1.0 …

Mar 26, 2025
CVE-2025-1490
6.1 MEDIUM

The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ parameter in all versions up to, and including, 1.5.2 …

Mar 26, 2025
CVE-2025-2302
6.4 MEDIUM

The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aws_search_terms shortcode in all versions up to, and including, …

Mar 26, 2025
CVE-2025-2276
4.3 MEDIUM

The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Mar 26, 2025
CVE-2025-30219
6.1 MEDIUM

RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk …

Mar 25, 2025
CVE-2025-30741
4.3 MEDIUM

Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if …

Mar 25, 2025
CVE-2024-55029
6.1 MEDIUM

NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

Mar 25, 2025
CVE-2024-31896
5.9 MEDIUM

IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Mar 25, 2025
CVE-2025-2312
5.9 MEDIUM

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong …

Mar 25, 2025
CVE-2025-26742
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for …

Mar 25, 2025
CVE-2024-55604
4.3 MEDIUM

Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of …

Mar 25, 2025
CVE-2025-29932
4.1 MEDIUM

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

Mar 25, 2025
CVE-2025-27633
6.1 MEDIUM

The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-side code injection that might be used to compromise the confidentiality …

Mar 25, 2025
CVE-2025-27632
6.1 MEDIUM

A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple …

Mar 25, 2025
CVE-2025-27631
6.5 MEDIUM

The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that …

Mar 25, 2025
CVE-2024-12169
6.5 MEDIUM

A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart …

Mar 25, 2025
CVE-2024-11499
4.9 MEDIUM

A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can …

Mar 25, 2025
CVE-2024-10037
4.4 MEDIUM

A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted …

Mar 25, 2025
CVE-2022-1804
5.5 MEDIUM

accountsservice no longer drops permissions when writting .pam_environment

Mar 25, 2025
CVE-2025-2109
5.8 MEDIUM

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, …

Mar 25, 2025
CVE-2025-2757
6.3 MEDIUM

A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of …

Mar 25, 2025
CVE-2025-2756
6.3 MEDIUM

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of …

Mar 25, 2025
CVE-2025-2635
6.1 MEDIUM

The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg() function without appropriate escaping on the …

Mar 25, 2025
CVE-2025-2542
6.4 MEDIUM

The Your Simple SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Mar 25, 2025
CVE-2024-53679
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to …

Mar 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.