CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-26308
6.5 MEDIUM

A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26307
6.5 MEDIUM

A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2025-26306
6.5 MEDIUM

A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via …

Feb 20, 2025
CVE-2023-51332
4.3 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of …

Feb 20, 2025
CVE-2023-51331
6.5 MEDIUM

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient …

Feb 20, 2025
CVE-2023-51330
5.4 MEDIUM

PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.

Feb 20, 2025
CVE-2023-51327
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2023-51326
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email …

Feb 20, 2025
CVE-2023-51325
5.4 MEDIUM

PHPJabbers Shared Asset Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

Feb 20, 2025
CVE-2023-51324
6.5 MEDIUM

PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to …

Feb 20, 2025
CVE-2023-51323
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of …

Feb 20, 2025
CVE-2023-51321
6.5 MEDIUM

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of …

Feb 20, 2025
CVE-2023-51320
5.3 MEDIUM

PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to …

Feb 20, 2025
CVE-2023-51318
5.4 MEDIUM

PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

Feb 20, 2025
CVE-2023-51317
6.5 MEDIUM

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

Feb 20, 2025
CVE-2023-51315
5.4 MEDIUM

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name" parameters.

Feb 20, 2025
CVE-2023-51312
5.4 MEDIUM

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter.

Feb 20, 2025
CVE-2023-51310
4.3 MEDIUM

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive …

Feb 20, 2025
CVE-2023-51309
4.3 MEDIUM

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of …

Feb 20, 2025
CVE-2023-51308
6.1 MEDIUM

PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

Feb 20, 2025
CVE-2023-51306
5.4 MEDIUM

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters.

Feb 20, 2025
CVE-2025-21106
5.5 MEDIUM

Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading …

Feb 20, 2025
CVE-2025-21105
6.6 MEDIUM

Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by …

Feb 20, 2025
CVE-2025-1043
6.4 MEDIUM

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Feb 20, 2025
CVE-2024-49779
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of …

Feb 20, 2025
CVE-2024-49344
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in …

Feb 20, 2025
CVE-2024-49337
5.4 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used …

Feb 20, 2025
CVE-2025-1483
5.3 MEDIUM

The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 20, 2025
CVE-2025-1328
6.4 MEDIUM

The Typed JS: A typewriter style animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘typespeed’ parameter in all versions up to, …

Feb 20, 2025
CVE-2025-0866
6.5 MEDIUM

The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 …

Feb 20, 2025
CVE-2024-6432
6.4 MEDIUM

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter within the plugin's shortcode Content Block …

Feb 20, 2025
CVE-2024-13855
4.3 MEDIUM

The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the …

Feb 20, 2025
CVE-2024-13849
5.5 MEDIUM

The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.0 due to insufficient input …

Feb 20, 2025
CVE-2024-13802
6.4 MEDIUM

The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_events' shortcode in all versions up to, and including, 1.3.1 …

Feb 20, 2025
CVE-2024-13748
4.4 MEDIUM

The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 …

Feb 20, 2025
CVE-2024-13520
5.3 MEDIUM

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing …

Feb 20, 2025
CVE-2025-1064
6.4 MEDIUM

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all …

Feb 20, 2025
CVE-2025-0897
6.4 MEDIUM

The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions …

Feb 20, 2025
CVE-2024-13155
6.4 MEDIUM

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up …

Feb 20, 2025
CVE-2025-27218
5.3 MEDIUM

Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

Feb 20, 2025
CVE-2024-13445
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and …

Feb 20, 2025
CVE-2024-49782
6.8 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit …

Feb 20, 2025
CVE-2024-49780
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to …

Feb 20, 2025
CVE-2024-49355
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing …

Feb 20, 2025
CVE-2024-43196
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof …

Feb 20, 2025
CVE-2025-24947
5.3 MEDIUM

A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a …

Feb 20, 2025
CVE-2025-24946
5.3 MEDIUM

The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attackers to cause a considerable CPU load …

Feb 20, 2025
CVE-2025-23020
5.3 MEDIUM

An issue was discovered in Kwik before 0.10.1. A hash collision vulnerability (in the hash table used to manage connections) allows remote attackers to cause …

Feb 20, 2025
CVE-2025-1223
6.1 MEDIUM

An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

Feb 20, 2025
CVE-2025-1222
6.1 MEDIUM

An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

Feb 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.