CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1339
6.3 MEDIUM

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of the file /cgi-bin/cstecgi.cgi. The …

Feb 16, 2025
CVE-2025-1336
4.3 MEDIUM

A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. Affected by this vulnerability is the function deleteimg_action in the library lib/admin/image_admin.php. The …

Feb 16, 2025
CVE-2025-1335
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9. Affected is the function deleteimg_action in the library lib/admin/file_admin.php. The manipulation of the …

Feb 16, 2025
CVE-2024-57970
4.0 MEDIUM

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a …

Feb 16, 2025
CVE-2024-13834
5.4 MEDIUM

The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-Side Request Forgery in all …

Feb 15, 2025
CVE-2025-0822
6.5 MEDIUM

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it …

Feb 15, 2025
CVE-2024-13500
6.5 MEDIUM

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL …

Feb 15, 2025
CVE-2024-13439
4.3 MEDIUM

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function …

Feb 15, 2025
CVE-2024-10581
4.3 MEDIUM

The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.9. This is due to missing …

Feb 15, 2025
CVE-2025-1005
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and …

Feb 15, 2025
CVE-2024-13752
6.5 MEDIUM

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss …

Feb 15, 2025
CVE-2025-22209
4.7 MEDIUM

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' …

Feb 15, 2025
CVE-2025-22208
4.7 MEDIUM

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' …

Feb 15, 2025
CVE-2025-0935
4.3 MEDIUM

The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in …

Feb 15, 2025
CVE-2024-13563
6.4 MEDIUM

The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password shortcode in all versions up to, and including, …

Feb 15, 2025
CVE-2024-13525
6.5 MEDIUM

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. …

Feb 15, 2025
CVE-2024-13306
4.3 MEDIUM

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high …

Feb 15, 2025
CVE-2024-13208
4.3 MEDIUM

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high …

Feb 15, 2025
CVE-2025-0996
5.4 MEDIUM

Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL …

Feb 15, 2025
CVE-2025-21401
4.5 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Feb 15, 2025
CVE-2024-10405
5.3 MEDIUM

Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade …

Feb 15, 2025
CVE-2022-28693
4.7 MEDIUM

Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

Feb 14, 2025
CVE-2025-25296
6.1 MEDIUM

Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` …

Feb 14, 2025
CVE-2025-25290
5.3 MEDIUM

@octokit/request sends parameterized requests to GitHub’s APIs with sensible defaults in browsers and Node. Starting in version 1.0.0 and prior to versions 9.2.1 and 8.4.1, …

Feb 14, 2025
CVE-2025-25289
5.3 MEDIUM

@octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) …

Feb 14, 2025
CVE-2025-25288
5.3 MEDIUM

@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, …

Feb 14, 2025
CVE-2025-25285
5.3 MEDIUM

@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)` …

Feb 14, 2025
CVE-2025-26158
5.6 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to …

Feb 14, 2025
CVE-2025-26157
5.9 MEDIUM

A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary …

Feb 14, 2025
CVE-2025-25993
5.1 MEDIUM

SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."

Feb 14, 2025
CVE-2025-25992
5.1 MEDIUM

SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.

Feb 14, 2025
CVE-2025-25991
5.1 MEDIUM

SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

Feb 14, 2025
CVE-2025-25990
6.1 MEDIUM

Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

Feb 14, 2025
CVE-2025-25988
4.8 MEDIUM

Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the …

Feb 14, 2025
CVE-2025-25204
6.3 MEDIUM

`gh` is GitHub’s official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain conditions, a bug in GitHub's Artifact Attestation …

Feb 14, 2025
CVE-2024-57790
5.4 MEDIUM

IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows physically …

Feb 14, 2025
CVE-2024-56463
4.8 MEDIUM

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus …

Feb 14, 2025
CVE-2024-57725
6.5 MEDIUM

An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet …

Feb 14, 2025
CVE-2025-25740
5.5 MEDIUM

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the PSK parameter in the SetQuickVPNSettings module.

Feb 14, 2025
CVE-2024-56477
6.5 MEDIUM

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL …

Feb 14, 2025
CVE-2024-52895
6.5 MEDIUM

IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A …

Feb 14, 2025
CVE-2025-1071
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This …

Feb 14, 2025
CVE-2025-0178
6.1 MEDIUM

Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the …

Feb 14, 2025
CVE-2025-24607
5.8 MEDIUM

Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through <= 8.71.

Feb 14, 2025
CVE-2025-24567
6.5 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through …

Feb 14, 2025
CVE-2025-23771
6.5 MEDIUM

Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress push-notification-for-post-and-buddypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Push Notification for …

Feb 14, 2025
CVE-2025-23766
6.5 MEDIUM

Missing Authorization vulnerability in ashamil OPSI Israel Domestic Shipments woo-ups-pickup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OPSI Israel Domestic Shipments: from …

Feb 14, 2025
CVE-2025-23534
6.5 MEDIUM

Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLingo: from n/a through <= 1.1.2.

Feb 14, 2025
CVE-2025-22702
6.3 MEDIUM

Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2.

Feb 14, 2025
CVE-2025-22698
6.3 MEDIUM

Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Suite: from n/a through <= …

Feb 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.