CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-28908
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pipdig pipDisqus pipdisqus allows Stored XSS.This issue affects pipDisqus: from n/a through <= …

Mar 11, 2025
CVE-2025-28907
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rahul Arora WP Last Modified wp-last-modified allows Stored XSS.This issue affects WP Last …

Mar 11, 2025
CVE-2025-28906
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow wp-skitter-slideshow allows Stored XSS.This issue affects Skitter Slideshow: from …

Mar 11, 2025
CVE-2025-28902
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Benjamin Pick Contact Form 7 Select Box Editor Button contact-form-7-select-box-editor-button allows Cross Site Request Forgery.This issue affects Contact Form …

Mar 11, 2025
CVE-2025-28896
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akshar Soft Solutions AS English Admin as-english-admin allows Phishing.This issue affects AS English Admin: from n/a …

Mar 11, 2025
CVE-2025-28887
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Fastmover Plugins Last Updated Column plugins-last-updated-column allows Cross Site Request Forgery.This issue affects Plugins Last Updated Column: from n/a …

Mar 11, 2025
CVE-2025-28886
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in xjb REST API TO MiniProgram rest-api-to-miniprogram allows Cross Site Request Forgery.This issue affects REST API TO MiniProgram: from n/a …

Mar 11, 2025
CVE-2025-28884
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator wp-bulk-post-duplicator allows Cross Site Request Forgery.This issue affects WP Bulk Post Duplicator: from …

Mar 11, 2025
CVE-2025-28881
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in mg12 Mobile Themes wp-mobile-themes allows Cross Site Request Forgery.This issue affects Mobile Themes: from n/a through <= 1.1.1.

Mar 11, 2025
CVE-2025-28879
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aumsrini Bee Layer Slider bee-layer-slider allows Stored XSS.This issue affects Bee Layer Slider: …

Mar 11, 2025
CVE-2025-28878
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will Brubaker Awesome Surveys awesome-surveys allows Stored XSS.This issue affects Awesome Surveys: from …

Mar 11, 2025
CVE-2025-28876
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Skrill_Team Skrill Official official-skrill-woocommerce allows Cross Site Request Forgery.This issue affects Skrill Official: from n/a through <= 1.0.66.

Mar 11, 2025
CVE-2025-28875
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Stored XSS.This issue affects BP Email …

Mar 11, 2025
CVE-2025-28874
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Email …

Mar 11, 2025
CVE-2025-28872
5.3 MEDIUM

Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Block Spam By Math …

Mar 11, 2025
CVE-2025-28871
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Stored XSS.This issue affects Block …

Mar 11, 2025
CVE-2025-28870
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in amocrm amoCRM WebForm amocrm-webform allows DOM-Based XSS.This issue affects amoCRM WebForm: from n/a …

Mar 11, 2025
CVE-2025-28868
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe ziplist-recipe-plugin allows Cross Site Request Forgery.This issue affects ZipList Recipe: from n/a through <= 3.1.

Mar 11, 2025
CVE-2025-28867
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in stesvis Frontpage category filter frontpage-category-filter allows Cross Site Request Forgery.This issue affects Frontpage category filter: from n/a through <= …

Mar 11, 2025
CVE-2025-28866
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger login-logger allows Cross Site Request Forgery.This issue affects Login Logger: from n/a through <= 1.2.1.

Mar 11, 2025
CVE-2025-28864
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in planetstudio Builder for Contact Form 7 by Webconstruct cf7-builder allows Cross Site Request Forgery.This issue affects Builder for Contact …

Mar 11, 2025
CVE-2025-28863
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image delete-original-image allows Cross Site Request Forgery.This issue affects Delete Original Image: from n/a through …

Mar 11, 2025
CVE-2025-28862
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: …

Mar 11, 2025
CVE-2025-28859
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice maintenance-notice allows Cross Site Request Forgery.This issue affects Maintenance Notice: from n/a through <= 1.0.6.

Mar 11, 2025
CVE-2025-28856
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in dangrossman W3Counter Free Real-Time Web Stats blog-stats-by-w3counter allows Cross Site Request Forgery.This issue affects W3Counter Free Real-Time Web Stats: …

Mar 11, 2025
CVE-2025-27180
5.5 MEDIUM

Substance3D - Modeler versions 1.15.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Mar 11, 2025
CVE-2025-21170
5.5 MEDIUM

Substance3D - Modeler versions 1.15.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Mar 11, 2025
CVE-2025-27789
6.2 MEDIUM

Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing …

Mar 11, 2025
CVE-2025-25929
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of …

Mar 11, 2025
CVE-2025-25927
6.8 MEDIUM

A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.

Mar 11, 2025
CVE-2025-25925
4.8 MEDIUM

A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Mar 11, 2025
CVE-2025-23243
6.5 MEDIUM

NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data …

Mar 11, 2025
CVE-2025-27591
6.8 MEDIUM

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have …

Mar 11, 2025
CVE-2025-27179
5.5 MEDIUM

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Mar 11, 2025
CVE-2025-27176
5.5 MEDIUM

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Mar 11, 2025
CVE-2025-27170
5.5 MEDIUM

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit …

Mar 11, 2025
CVE-2025-27164
5.5 MEDIUM

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Mar 11, 2025
CVE-2025-27163
5.5 MEDIUM

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Mar 11, 2025
CVE-2025-24449
5.5 MEDIUM

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Mar 11, 2025
CVE-2025-24448
5.5 MEDIUM

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Mar 11, 2025
CVE-2025-24431
5.5 MEDIUM

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Mar 11, 2025
CVE-2021-37787
6.5 MEDIUM

The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request to the TinyMCE …

Mar 11, 2025
CVE-2025-24997
4.4 MEDIUM

Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.

Mar 11, 2025
CVE-2025-24996
6.5 MEDIUM

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Mar 11, 2025
CVE-2025-24992
5.5 MEDIUM

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.

Mar 11, 2025
CVE-2025-24991
5.5 MEDIUM KEV

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

Mar 11, 2025
CVE-2025-24988
6.6 MEDIUM

Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.

Mar 11, 2025
CVE-2025-24987
6.6 MEDIUM

Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.

Mar 11, 2025
CVE-2025-24986
6.5 MEDIUM

Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24984
4.6 MEDIUM KEV

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

Mar 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.