CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1057
4.3 MEDIUM

A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries …

Mar 15, 2025
CVE-2019-25222
4.9 MEDIUM

The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due …

Mar 15, 2025
CVE-2025-1773
6.1 MEDIUM

The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient …

Mar 15, 2025
CVE-2025-2267
6.5 MEDIUM

The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check …

Mar 15, 2025
CVE-2025-2164
6.1 MEDIUM

The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' parameters in all versions up to, and including, 0.8.2 …

Mar 15, 2025
CVE-2025-2163
6.1 MEDIUM

The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missing …

Mar 15, 2025
CVE-2025-1670
6.5 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, …

Mar 15, 2025
CVE-2025-1669
6.5 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' action in all versions up to, and including, …

Mar 15, 2025
CVE-2025-1668
4.3 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a missing capability check on the wpsp_DeleteUser() function …

Mar 15, 2025
CVE-2024-12336
6.5 MEDIUM

The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Mar 15, 2025
CVE-2025-2310
5.3 MEDIUM

A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation …

Mar 14, 2025
CVE-2025-2309
5.3 MEDIUM

A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__bit_copy of the component Type Conversion Logic. The …

Mar 14, 2025
CVE-2025-2308
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_decompress_one_byte of the component Scale-Offset Filter. The manipulation leads …

Mar 14, 2025
CVE-2025-29782
5.4 MEDIUM

WeGIA is Web manager for charitable institutions A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_tipo_docs_atendido.php` endpoint in versions of the WeGIA application …

Mar 14, 2025
CVE-2024-29409
5.5 MEDIUM

File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.

Mar 14, 2025
CVE-2024-12020
6.1 MEDIUM

There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a …

Mar 14, 2025
CVE-2025-27606
5.1 MEDIUM

Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user …

Mar 14, 2025
CVE-2025-1888
4.6 MEDIUM

The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within …

Mar 14, 2025
CVE-2024-55594
5.6 MEDIUM

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows …

Mar 14, 2025
CVE-2025-25873
5.5 MEDIUM

Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function

Mar 14, 2025
CVE-2025-25872
5.5 MEDIUM

An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

Mar 14, 2025
CVE-2024-40585
6.5 MEDIUM

An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and …

Mar 14, 2025
CVE-2023-48785
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on …

Mar 14, 2025
CVE-2023-33300
5.3 MEDIUM

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, …

Mar 14, 2025
CVE-2024-47573
6.5 MEDIUM

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 …

Mar 14, 2025
CVE-2024-45643
5.9 MEDIUM

IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.

Mar 14, 2025
CVE-2024-45638
4.1 MEDIUM

IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.

Mar 14, 2025
CVE-2024-40590
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to …

Mar 14, 2025
CVE-2025-29032
5.9 MEDIUM

Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.

Mar 14, 2025
CVE-2025-26626
6.5 MEDIUM

The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software package. Versions prior to 1.5.0 …

Mar 14, 2025
CVE-2024-13772
5.6 MEDIUM

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, …

Mar 14, 2025
CVE-2025-1507
5.3 MEDIUM

The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() …

Mar 14, 2025
CVE-2025-1526
6.4 MEDIUM

The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Display Widget (countdown feature) in all versions up …

Mar 14, 2025
CVE-2024-13407
4.3 MEDIUM

The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to insufficient …

Mar 14, 2025
CVE-2025-2289
4.3 MEDIUM

The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoints in …

Mar 14, 2025
CVE-2025-2166
6.1 MEDIUM

The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use …

Mar 14, 2025
CVE-2025-1528
4.3 MEDIUM

The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_meta_values' function …

Mar 14, 2025
CVE-2025-1285
5.3 MEDIUM

The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and …

Mar 14, 2025
CVE-2025-0955
5.3 MEDIUM

The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'vidorev_import_single_video' AJAX action in all versions …

Mar 14, 2025
CVE-2025-30022
6.8 MEDIUM

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.

Mar 14, 2025
CVE-2024-55060
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a …

Mar 13, 2025
CVE-2025-25363
6.5 MEDIUM

An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator …

Mar 13, 2025
CVE-2024-30143
4.3 MEDIUM

HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. …

Mar 13, 2025
CVE-2025-29773
5.8 MEDIUM

Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the …

Mar 13, 2025
CVE-2025-29768
4.4 MEDIUM

Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is …

Mar 13, 2025
CVE-2025-28011
6.1 MEDIUM

A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code …

Mar 13, 2025
CVE-2025-27103
6.5 MEDIUM

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users …

Mar 13, 2025
CVE-2025-24974
6.5 MEDIUM

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the …

Mar 13, 2025
CVE-2025-1767
6.5 MEDIUM

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the …

Mar 13, 2025
CVE-2024-9042
5.9 MEDIUM

This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed …

Mar 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.