CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1383
4.3 MEDIUM

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2. This is due to …

Mar 6, 2025
CVE-2024-56196
6.3 MEDIUM

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version …

Mar 6, 2025
CVE-2024-56195
6.3 MEDIUM

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended …

Mar 6, 2025
CVE-2024-38311
6.3 MEDIUM

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through …

Mar 6, 2025
CVE-2024-56202
4.3 MEDIUM

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended …

Mar 6, 2025
CVE-2025-1672
5.5 MEDIUM

The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Mar 6, 2025
CVE-2024-13897
6.5 MEDIUM

The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the generate_json_page function in all …

Mar 6, 2025
CVE-2024-13868
6.1 MEDIUM

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it …

Mar 6, 2025
CVE-2025-20933
5.5 MEDIUM

Out-of-bounds read in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20932
5.5 MEDIUM

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20930
5.5 MEDIUM

Out-of-bounds read in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20928
5.5 MEDIUM

Out-of-bounds read in parsing wbmp image in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.

Mar 6, 2025
CVE-2025-20927
5.5 MEDIUM

Out-of-bounds read in parsing image data in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.

Mar 6, 2025
CVE-2025-20926
5.5 MEDIUM

Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' …

Mar 6, 2025
CVE-2025-20925
5.5 MEDIUM

Out-of-bounds read in applying binary of text data in Samsung Notes prior to version 4.4.26.71 allows local attackers to potentially read memory.

Mar 6, 2025
CVE-2025-20924
4.6 MEDIUM

Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across multiple user profiles.

Mar 6, 2025
CVE-2025-20923
4.0 MEDIUM

Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege.

Mar 6, 2025
CVE-2025-20922
5.5 MEDIUM

Out-of-bounds read in appending text paragraph in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20921
5.5 MEDIUM

Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20920
5.5 MEDIUM

Out-of-bounds read in action link data in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20919
5.5 MEDIUM

Out-of-bounds read in applying binary of video content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20918
5.5 MEDIUM

Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20917
5.5 MEDIUM

Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20916
5.5 MEDIUM

Out-of-bounds read in reading string of SPen in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20915
5.5 MEDIUM

Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20914
5.5 MEDIUM

Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20913
5.5 MEDIUM

Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

Mar 6, 2025
CVE-2025-20912
6.2 MEDIUM

Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.

Mar 6, 2025
CVE-2025-20911
4.4 MEDIUM

Improper access control in sem_wifi service prior to SMR Mar-2025 Release 1 allows privileged local attackers to update MAC address of Galaxy Watch.

Mar 6, 2025
CVE-2025-20910
6.2 MEDIUM

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

Mar 6, 2025
CVE-2025-20909
4.0 MEDIUM

Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.

Mar 6, 2025
CVE-2025-20908
6.5 MEDIUM

Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.

Mar 6, 2025
CVE-2025-1979
6.4 MEDIUM

Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in …

Mar 6, 2025
CVE-2025-27625
4.3 MEDIUM

In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by …

Mar 5, 2025
CVE-2025-27624
5.4 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of …

Mar 5, 2025
CVE-2025-27623
4.3 MEDIUM

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, …

Mar 5, 2025
CVE-2025-27622
4.3 MEDIUM

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, …

Mar 5, 2025
CVE-2025-25634
6.5 MEDIUM

A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to …

Mar 5, 2025
CVE-2024-48246
5.4 MEDIUM

Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.

Mar 5, 2025
CVE-2025-20208
4.6 MEDIUM

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) …

Mar 5, 2025
CVE-2025-27412
6.1 MEDIUM

REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected cross-site scripting (XSS) on the page of …

Mar 5, 2025
CVE-2025-27411
5.4 MEDIUM

REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5.18.3.

Mar 5, 2025
CVE-2025-24521
4.9 MEDIUM

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues …

Mar 5, 2025
CVE-2025-23416
4.9 MEDIUM

Path traversal may lead to arbitrary file deletion. The score without least privilege principle violation is as calculated below. In combination with other issues it …

Mar 5, 2025
CVE-2025-21095
4.9 MEDIUM

Path traversal may lead to arbitrary file download. The score without least privilege principle violation is as calculated below. In combination with other issues it …

Mar 5, 2025
CVE-2025-1463
4.3 MEDIUM

The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. This is due to improper …

Mar 5, 2025
CVE-2024-13423
5.3 MEDIUM

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions …

Mar 5, 2025
CVE-2024-12650
5.4 MEDIUM

An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a …

Mar 5, 2025
CVE-2024-11153
5.3 MEDIUM

The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure …

Mar 5, 2025
CVE-2025-0954
6.5 MEDIUM

The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the json_import() and json_export() functions in …

Mar 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.