CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57973
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. …

Feb 27, 2025
CVE-2024-57953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rtc: tps6594: Fix integer overflow on 32bit systems The problem is this multiply in tps6594_rtc_set_offset() …

Feb 27, 2025
CVE-2024-57423
6.1 MEDIUM

A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.

Feb 26, 2025
CVE-2024-50684
6.5 MEDIUM

SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted …

Feb 26, 2025
CVE-2025-1726
4.3 MEDIUM

There is a SQL injection issue in Esri ArcGIS Monitor versions 2023.0 through 2024.x on Windows and Linux that allows a remote, authenticated attacker with …

Feb 26, 2025
CVE-2025-20161
5.1 MEDIUM

A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow …

Feb 26, 2025
CVE-2025-20119
6.0 MEDIUM

A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause …

Feb 26, 2025
CVE-2025-20118
4.4 MEDIUM

A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an …

Feb 26, 2025
CVE-2025-20117
5.1 MEDIUM

A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of …

Feb 26, 2025
CVE-2025-20116
4.8 MEDIUM

A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. …

Feb 26, 2025
CVE-2025-0941
5.8 MEDIUM

MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain text within the system. This data is not available …

Feb 26, 2025
CVE-2025-25462
5.5 MEDIUM

A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via …

Feb 26, 2025
CVE-2024-46226
4.8 MEDIUM

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a …

Feb 26, 2025
CVE-2025-25827
6.8 MEDIUM

A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted …

Feb 26, 2025
CVE-2025-25818
5.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Feb 26, 2025
CVE-2025-25813
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.

Feb 26, 2025
CVE-2025-25802
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

Feb 26, 2025
CVE-2025-25800
5.3 MEDIUM

SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.

Feb 26, 2025
CVE-2025-25799
6.0 MEDIUM

SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.

Feb 26, 2025
CVE-2025-25797
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.

Feb 26, 2025
CVE-2025-25796
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.

Feb 26, 2025
CVE-2025-25794
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.

Feb 26, 2025
CVE-2025-25793
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.

Feb 26, 2025
CVE-2025-25792
4.4 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.

Feb 26, 2025
CVE-2025-25791
4.4 MEDIUM

An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.

Feb 26, 2025
CVE-2025-1249
5.3 MEDIUM

Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Events Manager: from n/a through …

Feb 26, 2025
CVE-2024-52925
6.8 MEDIUM

In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unlock Device feature for software encrypted …

Feb 26, 2025
CVE-2022-49732
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sock: redo the psock vs ULP protection check Commit 8a59f9d1e3d4 ("sock: Introduce sk->sk_prot->psock_update_sk_prot()") has moved …

Feb 26, 2025
CVE-2025-26925
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.

Feb 26, 2025
CVE-2025-0719
6.1 MEDIUM

IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript …

Feb 26, 2025
CVE-2025-1517
6.4 MEDIUM

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to …

Feb 26, 2025
CVE-2025-0731
6.5 MEDIUM

An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed …

Feb 26, 2025
CVE-2024-6810
4.4 MEDIUM

The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.1 due to insufficient input sanitization …

Feb 26, 2025
CVE-2024-13803
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in …

Feb 26, 2025
CVE-2024-13678
6.1 MEDIUM

The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13669
6.1 MEDIUM

The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13634
6.1 MEDIUM

The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 26, 2025
CVE-2024-13630
6.1 MEDIUM

The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13629
6.1 MEDIUM

The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 26, 2025
CVE-2024-13628
6.1 MEDIUM

The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 26, 2025
CVE-2024-13560
4.3 MEDIUM

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is …

Feb 26, 2025
CVE-2024-13113
5.9 MEDIUM

The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow …

Feb 26, 2025
CVE-2024-12737
6.1 MEDIUM

The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a parameter before outputting it back in …

Feb 26, 2025
CVE-2024-12434
5.3 MEDIUM

The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes …

Feb 26, 2025
CVE-2024-10563
5.4 MEDIUM

The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a …

Feb 26, 2025
CVE-2022-25773
4.3 MEDIUM

This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a …

Feb 26, 2025
CVE-2025-0236
5.3 MEDIUM

Out-of-bounds vulnerability in slope processing during curve rendering in Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic LIPSLX V4 …

Feb 26, 2025
CVE-2025-0235
5.3 MEDIUM

Out-of-bounds vulnerability due to improper memory release during image rendering in Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic …

Feb 26, 2025
CVE-2025-0234
5.3 MEDIUM

Out-of-bounds vulnerability in curve segmentation processing of Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic LIPSLX V4 Printer Driver.

Feb 26, 2025
CVE-2022-49731
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo() In an unlikely (and probably wrong?) case …

Feb 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.