CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9458
4.8 MEDIUM

The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Mar 7, 2025
CVE-2024-13857
5.5 MEDIUM

The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Mar 7, 2025
CVE-2024-13805
6.4 MEDIUM

The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File …

Mar 7, 2025
CVE-2024-13635
4.3 MEDIUM

The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. …

Mar 7, 2025
CVE-2024-13552
4.3 MEDIUM

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Mar 7, 2025
CVE-2025-21843
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_dev_query() 'priorities_info' is uninitialized, and the uninitialized value is copied …

Mar 7, 2025
CVE-2025-21842
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to init user queue The destructor of a gtt …

Mar 7, 2025
CVE-2025-21841
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting amd_pstate_update_limits() takes a cpufreq_policy reference but doesn't decrement the refcount …

Mar 7, 2025
CVE-2025-21840
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/netlink: Prevent userspace segmentation fault by adjusting UAPI header The intel-lpmd tool [1], which uses …

Mar 7, 2025
CVE-2025-21839
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop Move the conditional …

Mar 7, 2025
CVE-2025-21838
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: flush gadget workqueue after device removal device_del() can lead to new work …

Mar 7, 2025
CVE-2025-21836
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it …

Mar 7, 2025
CVE-2025-21835
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, …

Mar 7, 2025
CVE-2024-13904
5.3 MEDIUM

The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' …

Mar 7, 2025
CVE-2024-13781
6.5 MEDIUM

The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due …

Mar 7, 2025
CVE-2024-13431
6.1 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter …

Mar 7, 2025
CVE-2024-12611
5.3 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and …

Mar 7, 2025
CVE-2024-12610
5.3 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' …

Mar 7, 2025
CVE-2024-12609
6.5 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, …

Mar 7, 2025
CVE-2024-12607
6.5 MEDIUM

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all …

Mar 7, 2025
CVE-2025-0863
6.4 MEDIUM

The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, …

Mar 7, 2025
CVE-2024-12576
5.5 MEDIUM

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU …

Mar 7, 2025
CVE-2024-12809
6.4 MEDIUM

The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due …

Mar 7, 2025
CVE-2025-27796
4.5 MEDIUM

ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.

Mar 7, 2025
CVE-2025-27795
4.3 MEDIUM

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

Mar 7, 2025
CVE-2025-2061
4.3 MEDIUM

A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Mar 7, 2025
CVE-2025-26708
4.2 MEDIUM

There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the …

Mar 7, 2025
CVE-2025-2054
4.7 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 7, 2025
CVE-2025-0748
4.3 MEDIUM

The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect …

Mar 7, 2025
CVE-2024-13526
4.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on …

Mar 7, 2025
CVE-2025-2053
6.3 MEDIUM

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Mar 7, 2025
CVE-2025-2052
6.3 MEDIUM

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /forgot-password.php. …

Mar 7, 2025
CVE-2025-2051
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-visitor.php. …

Mar 7, 2025
CVE-2025-1121
6.8 MEDIUM

Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code …

Mar 7, 2025
CVE-2025-2046
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 6, 2025
CVE-2025-2044
4.7 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 6, 2025
CVE-2025-2043
4.7 MEDIUM

A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component …

Mar 6, 2025
CVE-2025-2042
4.3 MEDIUM

A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. …

Mar 6, 2025
CVE-2025-2041
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file …

Mar 6, 2025
CVE-2024-57972
6.5 MEDIUM

The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause …

Mar 6, 2025
CVE-2025-2040
6.3 MEDIUM

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation …

Mar 6, 2025
CVE-2025-2039
4.7 MEDIUM

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/delete_members.php. The …

Mar 6, 2025
CVE-2025-2037
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Mar 6, 2025
CVE-2025-2036
6.3 MEDIUM

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation …

Mar 6, 2025
CVE-2025-27600
6.5 MEDIUM

FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP verification, an attacker can initiate an …

Mar 6, 2025
CVE-2025-27506
5.4 MEDIUM

NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId …

Mar 6, 2025
CVE-2025-26699
5.0 MEDIUM

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject …

Mar 6, 2025
CVE-2025-25294
5.3 MEDIUM

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to …

Mar 6, 2025
CVE-2025-25191
5.4 MEDIUM

Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before …

Mar 6, 2025
CVE-2025-2035
6.3 MEDIUM

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /customer_register.php. The …

Mar 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.