CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27150
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from …

Mar 4, 2025
CVE-2025-26182
6.5 MEDIUM

An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file

Mar 4, 2025
CVE-2025-26091
4.6 MEDIUM

A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web …

Mar 4, 2025
CVE-2025-26320
6.5 MEDIUM

t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.

Mar 4, 2025
CVE-2025-27426
5.4 MEDIUM

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for …

Mar 4, 2025
CVE-2025-27425
4.3 MEDIUM

Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation …

Mar 4, 2025
CVE-2025-27424
4.3 MEDIUM

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox …

Mar 4, 2025
CVE-2025-1938
6.5 MEDIUM

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and …

Mar 4, 2025
CVE-2025-1935
4.3 MEDIUM

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in …

Mar 4, 2025
CVE-2025-1934
6.5 MEDIUM

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting …

Mar 4, 2025
CVE-2025-1925
5.3 MEDIUM

A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of …

Mar 4, 2025
CVE-2025-0958
5.4 MEDIUM

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9. This makes …

Mar 4, 2025
CVE-2025-0370
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, …

Mar 4, 2025
CVE-2025-26849
4.3 MEDIUM

There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain …

Mar 4, 2025
CVE-2025-0512
6.4 MEDIUM

The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and …

Mar 4, 2025
CVE-2025-0433
6.4 MEDIUM

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Mar 4, 2025
CVE-2024-9618
6.4 MEDIUM

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Mar 4, 2025
CVE-2024-13724
4.3 MEDIUM

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in …

Mar 4, 2025
CVE-2024-13682
4.3 MEDIUM

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 4, 2025
CVE-2025-27521
6.8 MEDIUM

Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58050
6.2 MEDIUM

Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58049
5.0 MEDIUM

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58048
6.7 MEDIUM

Multi-thread problem vulnerability in the package management module Impact: Successful exploitation of this vulnerability may affect availability.

Mar 4, 2025
CVE-2024-58047
5.0 MEDIUM

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-58046
6.2 MEDIUM

Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mar 4, 2025
CVE-2024-47262
5.3 MEDIUM

Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing …

Mar 4, 2025
CVE-2024-47260
6.5 MEDIUM

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for …

Mar 4, 2025
CVE-2024-13685
5.3 MEDIUM

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value …

Mar 4, 2025
CVE-2025-1906
4.7 MEDIUM

A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. …

Mar 4, 2025
CVE-2025-21098
5.5 MEDIUM

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.

Mar 4, 2025
CVE-2025-20042
5.5 MEDIUM

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.

Mar 4, 2025
CVE-2025-1321
6.5 MEDIUM

The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode in all versions up to, and including, …

Mar 4, 2025
CVE-2024-13686
4.3 MEDIUM

The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all …

Mar 4, 2025
CVE-2025-1899
6.5 MEDIUM

A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setPptpUserList. …

Mar 4, 2025
CVE-2025-1898
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affected is an unknown function of the file /goform/openSchedWifi. The manipulation of …

Mar 4, 2025
CVE-2025-1897
6.5 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. This issue affects some unknown processing of the file /goform/SetNetControlList. The …

Mar 4, 2025
CVE-2025-1896
6.5 MEDIUM

A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability affects unknown code of the file /goform/SetStaticRouteCfg. The manipulation of the argument …

Mar 4, 2025
CVE-2025-1895
6.5 MEDIUM

A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file /goform/setMacFilterCfg. The manipulation of the …

Mar 4, 2025
CVE-2025-1893
4.3 MEDIUM

A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the …

Mar 4, 2025
CVE-2025-1695
5.3 MEDIUM

In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase …

Mar 4, 2025
CVE-2025-27220
4.0 MEDIUM

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

Mar 4, 2025
CVE-2025-27219
5.8 MEDIUM

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method …

Mar 4, 2025
CVE-2025-1891
4.3 MEDIUM

A vulnerability was found in shishuocms 1.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The …

Mar 4, 2025
CVE-2025-1890
6.3 MEDIUM

A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of …

Mar 4, 2025
CVE-2024-55064
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, …

Mar 3, 2025
CVE-2025-1882
5.0 MEDIUM

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown …

Mar 3, 2025
CVE-2025-1881
4.3 MEDIUM

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been declared as problematic. Affected by this vulnerability is an unknown …

Mar 3, 2025
CVE-2024-5888
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a …

Mar 3, 2025
CVE-2024-51966
4.9 MEDIUM

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges …

Mar 3, 2025
CVE-2024-51963
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a …

Mar 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.