CVE Database

53069+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2147
5.3 MEDIUM

A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is …

Mar 10, 2025
CVE-2025-24387
4.8 MEDIUM

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS …

Mar 10, 2025
CVE-2025-27257
6.1 MEDIUM

Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature …

Mar 10, 2025
CVE-2025-27253
6.1 MEDIUM

A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker …

Mar 10, 2025
CVE-2025-2150
5.4 MEDIUM

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which …

Mar 10, 2025
CVE-2025-1926
4.3 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Mar 10, 2025
CVE-2025-2132
4.7 MEDIUM

A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/index.php/web/ajax_all_lists of the component Search. The …

Mar 9, 2025
CVE-2025-2129
5.6 MEDIUM

A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default …

Mar 9, 2025
CVE-2025-2127
4.3 MEDIUM

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the …

Mar 9, 2025
CVE-2025-2126
6.3 MEDIUM

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file …

Mar 9, 2025
CVE-2025-2125
4.3 MEDIUM

A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao/?companyId=1 of …

Mar 9, 2025
CVE-2025-27636
5.6 MEDIUM

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from …

Mar 9, 2025
CVE-2025-2121
6.3 MEDIUM

A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the component …

Mar 9, 2025
CVE-2025-2117
6.3 MEDIUM

A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. Affected by this issue is …

Mar 9, 2025
CVE-2025-2116
4.3 MEDIUM

A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic. Affected by this vulnerability …

Mar 9, 2025
CVE-2025-2115
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. …

Mar 9, 2025
CVE-2025-1382
6.1 MEDIUM

The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as …

Mar 9, 2025
CVE-2025-1362
4.3 MEDIUM

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which …

Mar 9, 2025
CVE-2023-52971
4.9 MEDIUM

MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.

Mar 8, 2025
CVE-2023-52970
4.9 MEDIUM

MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.

Mar 8, 2025
CVE-2023-52969
4.9 MEDIUM

MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may …

Mar 8, 2025
CVE-2023-52968
4.9 MEDIUM

MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed …

Mar 8, 2025
CVE-2025-2112
6.3 MEDIUM

A vulnerability was found in user-xiangpeng yaoqishan up to a47fec4a31cbd13698c592dfdc938c8824dd25e4. It has been declared as critical. Affected by this vulnerability is the function getMediaLisByFilter of …

Mar 8, 2025
CVE-2025-27840
6.8 MEDIUM

Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).

Mar 8, 2025
CVE-2024-13924
5.3 MEDIUM

The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the …

Mar 8, 2025
CVE-2024-10326
4.3 MEDIUM

The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets …

Mar 8, 2025
CVE-2025-1664
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in …

Mar 8, 2025
CVE-2024-13675
6.4 MEDIUM

The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Icon List" Block in all …

Mar 8, 2025
CVE-2024-13649
6.4 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions …

Mar 8, 2025
CVE-2025-1783
6.4 MEDIUM

The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versions up to, and including, 1.3.4 due …

Mar 8, 2025
CVE-2025-1325
6.3 MEDIUM

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the …

Mar 8, 2025
CVE-2025-1324
6.4 MEDIUM

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions …

Mar 8, 2025
CVE-2025-1322
4.3 MEDIUM

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via …

Mar 8, 2025
CVE-2025-1287
6.4 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Mar 8, 2025
CVE-2024-13816
5.4 MEDIUM

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, …

Mar 8, 2025
CVE-2024-10321
4.3 MEDIUM

The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 in …

Mar 8, 2025
CVE-2024-13844
4.9 MEDIUM

The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due …

Mar 8, 2025
CVE-2024-13826
5.4 MEDIUM

The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Mar 8, 2025
CVE-2024-13825
6.1 MEDIUM

The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 8, 2025
CVE-2024-12119
6.4 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter …

Mar 8, 2025
CVE-2024-12114
4.3 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Mar 8, 2025
CVE-2024-13640
5.9 MEDIUM

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 …

Mar 8, 2025
CVE-2025-1504
4.3 MEDIUM

The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2 via the 'pl_autocomplete' AJAX action due …

Mar 8, 2025
CVE-2025-1481
6.5 MEDIUM

The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in …

Mar 8, 2025
CVE-2024-13895
4.3 MEDIUM

The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due …

Mar 8, 2025
CVE-2024-13774
6.1 MEDIUM

The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. …

Mar 8, 2025
CVE-2024-12460
6.4 MEDIUM

The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'years-since' shortcode in all versions up to, …

Mar 8, 2025
CVE-2025-1261
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all …

Mar 8, 2025
CVE-2025-2096
6.3 MEDIUM

A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Mar 7, 2025
CVE-2025-2095
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Mar 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.