CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2755
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection …

Mar 25, 2025
CVE-2025-2754
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection …

Mar 25, 2025
CVE-2025-2753
6.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file …

Mar 25, 2025
CVE-2025-2559
4.9 MEDIUM

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT …

Mar 25, 2025
CVE-2025-2510
5.5 MEDIUM

The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter in all versions up to, and including, 1.0 …

Mar 25, 2025
CVE-2024-13731
6.4 MEDIUM

The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert Box …

Mar 25, 2025
CVE-2024-13710
4.3 MEDIUM

The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is …

Mar 25, 2025
CVE-2025-2752
4.3 MEDIUM

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h …

Mar 25, 2025
CVE-2025-2751
4.3 MEDIUM

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file …

Mar 25, 2025
CVE-2025-2750
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp …

Mar 25, 2025
CVE-2025-2744
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component …

Mar 25, 2025
CVE-2025-2743
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the file /admin-api/mp/material/upload-temporary of …

Mar 25, 2025
CVE-2025-2742
5.4 MEDIUM

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload …

Mar 25, 2025
CVE-2025-2252
5.3 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Mar 25, 2025
CVE-2025-1320
4.3 MEDIUM

The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or …

Mar 25, 2025
CVE-2024-12623
6.4 MEDIUM

The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in all versions up to, and including, 0.10.6 …

Mar 25, 2025
CVE-2025-2224
5.3 MEDIUM

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a …

Mar 25, 2025
CVE-2025-27810
5.4 MEDIUM

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the …

Mar 25, 2025
CVE-2025-27809
5.4 MEDIUM

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client …

Mar 25, 2025
CVE-2025-1798
6.1 MEDIUM

The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting …

Mar 25, 2025
CVE-2025-0845
6.4 MEDIUM

The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient …

Mar 25, 2025
CVE-2024-9770
4.7 MEDIUM

The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL …

Mar 25, 2025
CVE-2024-13118
4.3 MEDIUM

The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Mar 25, 2025
CVE-2024-12682
6.1 MEDIUM

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-12109
4.1 MEDIUM

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, …

Mar 25, 2025
CVE-2024-11503
6.1 MEDIUM

The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 25, 2025
CVE-2024-11273
6.1 MEDIUM

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could …

Mar 25, 2025
CVE-2024-11272
6.1 MEDIUM

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could …

Mar 25, 2025
CVE-2024-10703
6.1 MEDIUM

The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users …

Mar 25, 2025
CVE-2024-10679
6.1 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users …

Mar 25, 2025
CVE-2024-10638
4.1 MEDIUM

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, …

Mar 25, 2025
CVE-2024-10566
6.1 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-10565
6.1 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-10472
5.9 MEDIUM

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 25, 2025
CVE-2024-10105
5.9 MEDIUM

The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor …

Mar 25, 2025
CVE-2025-2733
6.3 MEDIUM

A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13. This affects an unknown part of the file app/tool/python_execute.py of the …

Mar 25, 2025
CVE-2025-2717
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of …

Mar 25, 2025
CVE-2025-24513
4.8 MEDIUM

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory …

Mar 25, 2025
CVE-2025-2714
4.3 MEDIUM

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Mar 24, 2025
CVE-2025-2712
4.3 MEDIUM

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 24, 2025
CVE-2025-2711
4.3 MEDIUM

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop.jsp. The …

Mar 24, 2025
CVE-2025-2710
4.3 MEDIUM

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown processing of the file /menu.jsp. The manipulation …

Mar 24, 2025
CVE-2025-2709
4.3 MEDIUM

A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation …

Mar 24, 2025
CVE-2025-2708
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-api/infra/file/upload of the component …

Mar 24, 2025
CVE-2025-2748
6.1 MEDIUM

The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico …

Mar 24, 2025
CVE-2025-2707
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file …

Mar 24, 2025
CVE-2025-2706
6.3 MEDIUM

A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation …

Mar 24, 2025
CVE-2025-22223
5.3 MEDIUM

Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are …

Mar 24, 2025
CVE-2025-30208
5.3 MEDIUM

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files …

Mar 24, 2025
CVE-2025-29778
5.8 MEDIUM

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign …

Mar 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.