CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2384
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file …

Mar 17, 2025
CVE-2025-26127
5.0 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via …

Mar 17, 2025
CVE-2025-25621
4.3 MEDIUM

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.

Mar 17, 2025
CVE-2025-29788
6.5 MEDIUM

The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 …

Mar 17, 2025
CVE-2024-9055
4.2 MEDIUM

The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract …

Mar 17, 2025
CVE-2021-32584
5.3 MEDIUM

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to …

Mar 17, 2025
CVE-2021-26087
4.3 MEDIUM

An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface …

Mar 17, 2025
CVE-2021-22126
6.7 MEDIUM

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may …

Mar 17, 2025
CVE-2020-9295
4.7 MEDIUM

FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version …

Mar 17, 2025
CVE-2020-29010
5.0 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to …

Mar 17, 2025
CVE-2019-6697
5.3 MEDIUM

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP …

Mar 17, 2025
CVE-2019-15706
4.1 MEDIUM

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version …

Mar 17, 2025
CVE-2025-2374
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This issue affects some unknown processing of …

Mar 17, 2025
CVE-2025-2373
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This vulnerability affects unknown code of the file /check_availability.php. The …

Mar 17, 2025
CVE-2025-2368
6.3 MEDIUM

A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the …

Mar 17, 2025
CVE-2025-2367
6.3 MEDIUM

A vulnerability has been found in Oiwtech OIW-2431APGN-HP 2.5.3-B20131128 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formScript of the component …

Mar 17, 2025
CVE-2025-2365
6.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the …

Mar 17, 2025
CVE-2025-2363
6.3 MEDIUM

A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation …

Mar 17, 2025
CVE-2025-2361
4.3 MEDIUM

A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The …

Mar 17, 2025
CVE-2025-2358
6.3 MEDIUM

A vulnerability was found in Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System 1.0. It has been rated as critical. This issue affects some …

Mar 17, 2025
CVE-2025-2357
6.3 MEDIUM

A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS Decoder. The …

Mar 17, 2025
CVE-2025-30089
5.4 MEDIUM

gurk (aka gurk-rs) through 0.6.3 mishandles ANSI escape sequences.

Mar 17, 2025
CVE-2025-2354
4.3 MEDIUM

A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 17, 2025
CVE-2025-2350
6.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown …

Mar 16, 2025
CVE-2025-2348
4.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the …

Mar 16, 2025
CVE-2025-2347
6.3 MEDIUM

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component …

Mar 16, 2025
CVE-2025-2346
5.6 MEDIUM

A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown …

Mar 16, 2025
CVE-2025-2344
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this …

Mar 16, 2025
CVE-2025-2342
5.3 MEDIUM

A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the …

Mar 16, 2025
CVE-2025-2339
5.3 MEDIUM

A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs. The …

Mar 16, 2025
CVE-2025-2338
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulation leads …

Mar 16, 2025
CVE-2025-2337
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in tbeu matio 1.5.28. This issue affects the function Mat_VarPrint of the file src/mat.c. The …

Mar 16, 2025
CVE-2025-1621
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1620
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2025-1619
4.8 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Mar 16, 2025
CVE-2024-13602
4.8 MEDIUM

The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 16, 2025
CVE-2024-13126
4.6 MEDIUM

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

Mar 16, 2025
CVE-2025-24856
4.2 MEDIUM

An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading …

Mar 16, 2025
CVE-2024-58103
5.8 MEDIUM

Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.

Mar 16, 2025
CVE-2025-30077
6.2 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits.

Mar 16, 2025
CVE-2025-2334
5.4 MEDIUM

A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat …

Mar 15, 2025
CVE-2025-26940
6.3 MEDIUM

Path Traversal vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.

Mar 15, 2025
CVE-2025-26924
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Ohio Extra: from n/a through <= …

Mar 15, 2025
CVE-2025-26899
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce recapture-for-woocommerce allows Cross Site Request Forgery.This issue affects Recapture for …

Mar 15, 2025
CVE-2025-26895
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maennchen1.de m1.DownloadList m1downloadlist allows DOM-Based XSS.This issue affects m1.DownloadList: from n/a through <= …

Mar 15, 2025
CVE-2025-25225
6.5 MEDIUM

A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions.

Mar 15, 2025
CVE-2025-2323
4.3 MEDIUM

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of …

Mar 15, 2025
CVE-2025-2321
6.3 MEDIUM

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this issue is some unknown functionality of the file /api/mjkj-chat/cgform-api/addData/. The …

Mar 15, 2025
CVE-2025-2025
6.5 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Mar 15, 2025
CVE-2025-1530
4.3 MEDIUM

The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9. This is due to missing nonce …

Mar 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.