CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1820
6.3 MEDIUM

A vulnerability has been found in zj1983 zz up to 2024-8 and classified as critical. Affected by this vulnerability is the function getOaWid of the …

Mar 2, 2025
CVE-2025-1819
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Tenda AC7 1200M 15.03.06.44. Affected is the function TendaTelnet of the file /goform/telnet. The manipulation …

Mar 2, 2025
CVE-2025-1818
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file …

Mar 2, 2025
CVE-2022-49733
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC There is a small race window at snd_pcm_oss_sync() …

Mar 2, 2025
CVE-2025-1816
4.3 MEDIUM

A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component …

Mar 2, 2025
CVE-2025-1813
4.3 MEDIUM

A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manipulation leads to …

Mar 2, 2025
CVE-2025-1812
6.3 MEDIUM

A vulnerability classified as critical has been found in zj1983 zz up to 2024-08. Affected is the function GetUserOrg of the file com/futvan/z/framework/core/SuperZ.java. The manipulation …

Mar 2, 2025
CVE-2025-1810
4.3 MEDIUM

A vulnerability was found in Pixsoft Vivaz 6.0.11. It has been classified as problematic. Affected is an unknown function of the file /servlet?act=login&submit=1&evento=0&pixrnd=0125021817031859360231 of the …

Mar 2, 2025
CVE-2025-25724
4.0 MEDIUM

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other …

Mar 2, 2025
CVE-2025-1806
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this issue is some unknown functionality of the file …

Mar 2, 2025
CVE-2025-1800
6.3 MEDIUM

A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the …

Mar 1, 2025
CVE-2025-1799
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of …

Mar 1, 2025
CVE-2025-1797
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. …

Mar 1, 2025
CVE-2024-41778
5.3 MEDIUM

IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to …

Mar 1, 2025
CVE-2025-1791
6.3 MEDIUM

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation …

Mar 1, 2025
CVE-2025-1788
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in rizinorg rizin up to 0.8.0. This affects the function rz_utf8_encode in the library /librz/util/utf8.c. The …

Mar 1, 2025
CVE-2025-1491
6.4 MEDIUM

The WP Posts Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play_timeout’ parameter in all versions up to, and including, 1.3.7 …

Mar 1, 2025
CVE-2025-1404
5.3 MEDIUM

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Mar 1, 2025
CVE-2025-1786
5.3 MEDIUM

A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream_directory_free in the library …

Mar 1, 2025
CVE-2024-13546
4.3 MEDIUM

The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.1 via the 'get_image_description' function. This makes …

Mar 1, 2025
CVE-2025-1291
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icon’ parameter …

Mar 1, 2025
CVE-2024-13697
4.8 MEDIUM

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions …

Mar 1, 2025
CVE-2024-13806
6.5 MEDIUM

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to …

Mar 1, 2025
CVE-2025-1730
6.5 MEDIUM

The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This …

Mar 1, 2025
CVE-2025-1502
5.3 MEDIUM

The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'download_ip2location_redirection_backup' AJAX action in …

Mar 1, 2025
CVE-2025-1459
6.4 MEDIUM

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and …

Mar 1, 2025
CVE-2024-13901
4.4 MEDIUM

The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the …

Mar 1, 2025
CVE-2025-0820
6.4 MEDIUM

The Clicface Trombi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nom’ parameter in all versions up to, and including, 2.08 due …

Mar 1, 2025
CVE-2024-9217
6.1 MEDIUM

The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Mar 1, 2025
CVE-2024-9212
6.1 MEDIUM

The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Mar 1, 2025
CVE-2024-13750
6.5 MEDIUM

The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and …

Mar 1, 2025
CVE-2024-13746
6.5 MEDIUM

The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on the …

Mar 1, 2025
CVE-2024-13559
6.4 MEDIUM

The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wishlist_table' shortcode in all versions up to, and including, 3.2.9 …

Mar 1, 2025
CVE-2024-13518
4.3 MEDIUM

The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.12. This is due to missing …

Mar 1, 2025
CVE-2025-1780
4.3 MEDIUM

The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Mar 1, 2025
CVE-2024-13358
4.3 MEDIUM

The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Mar 1, 2025
CVE-2025-23118
6.4 MEDIUM

An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the …

Mar 1, 2025
CVE-2025-23117
6.8 MEDIUM

An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to …

Mar 1, 2025
CVE-2025-25478
6.5 MEDIUM

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web …

Feb 28, 2025
CVE-2025-25476
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious …

Feb 28, 2025
CVE-2025-26466
5.9 MEDIUM

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer …

Feb 28, 2025
CVE-2025-27413
6.5 MEDIUM

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an administrator to import raw data into the database, …

Feb 28, 2025
CVE-2025-27410
6.5 MEDIUM

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, …

Feb 28, 2025
CVE-2025-25429
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.

Feb 28, 2025
CVE-2025-27408
4.8 MEDIUM

Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifest employs a weak password hashing implementation that uses SHA3 without a salt. …

Feb 28, 2025
CVE-2025-25431
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.

Feb 28, 2025
CVE-2025-25430
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.

Feb 28, 2025
CVE-2025-24843
5.1 MEDIUM

Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.

Feb 28, 2025
CVE-2025-24318
6.8 MEDIUM

Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.

Feb 28, 2025
CVE-2025-24316
5.3 MEDIUM

The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality.

Feb 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.