CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0821
6.5 MEDIUM

Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to …

Feb 14, 2025
CVE-2024-13791
4.9 MEDIUM

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it …

Feb 14, 2025
CVE-2024-13735
6.4 MEDIUM

The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions …

Feb 14, 2025
CVE-2025-26791
4.5 MEDIUM

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

Feb 14, 2025
CVE-2024-9601
6.5 MEDIUM

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up …

Feb 14, 2025
CVE-2024-57969
4.3 MEDIUM

app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

Feb 14, 2025
CVE-2024-7052
4.8 MEDIUM

The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin …

Feb 14, 2025
CVE-2024-13692
5.4 MEDIUM

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure …

Feb 14, 2025
CVE-2024-13641
5.9 MEDIUM

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive …

Feb 14, 2025
CVE-2024-13493
4.8 MEDIUM

The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Feb 14, 2025
CVE-2025-23406
5.3 MEDIUM

Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a …

Feb 14, 2025
CVE-2025-1053
4.9 MEDIUM

Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. …

Feb 14, 2025
CVE-2024-10404
5.5 MEDIUM

CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS …

Feb 14, 2025
CVE-2024-57782
6.8 MEDIUM

An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.

Feb 13, 2025
CVE-2024-56908
6.8 MEDIUM

In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in …

Feb 13, 2025
CVE-2024-54951
5.4 MEDIUM

Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU …

Feb 13, 2025
CVE-2024-53311
5.5 MEDIUM

A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that …

Feb 13, 2025
CVE-2024-53310
5.5 MEDIUM

A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed …

Feb 13, 2025
CVE-2024-53309
5.5 MEDIUM

A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" …

Feb 13, 2025
CVE-2024-37603
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG …

Feb 13, 2025
CVE-2024-37602
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple Car Play function …

Feb 13, 2025
CVE-2024-37601
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of …

Feb 13, 2025
CVE-2024-37600
6.8 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects …

Feb 13, 2025
CVE-2024-12054
5.4 MEDIUM

ZF Roll Stability Support Plus (RSSPlus) is vulnerable to an authentication bypass vulnerability targeting deterministic RSSPlus SecurityAccess service seeds, which may allow an attacker to …

Feb 13, 2025
CVE-2023-34404
4.9 MEDIUM

Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. …

Feb 13, 2025
CVE-2023-34403
4.9 MEDIUM

Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. …

Feb 13, 2025
CVE-2025-25195
4.3 MEDIUM

Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) demotes channels to being "inactive" after they have not received …

Feb 13, 2025
CVE-2025-23421
6.4 MEDIUM

An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by …

Feb 13, 2025
CVE-2025-23411
6.3 MEDIUM

mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick …

Feb 13, 2025
CVE-2025-20615
6.2 MEDIUM

The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to …

Feb 13, 2025
CVE-2025-24889
4.5 MEDIUM

The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to versions 0.14.1 …

Feb 13, 2025
CVE-2025-25900
4.9 MEDIUM

A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /userRpm/PPPoEv6CfgRpm.htm. This vulnerability allows attackers to cause a …

Feb 13, 2025
CVE-2025-25287
4.7 MEDIUM

Lakeus is a simple skin made for MediaWiki. Starting in version 1.0.8 and prior to versions 1.3.1+REL1.39, 1.3.1+REL1.42, and 1.4.0, Lakeus is vulnerable to store …

Feb 13, 2025
CVE-2025-0426
6.2 MEDIUM

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause …

Feb 13, 2025
CVE-2024-12012
5.7 MEDIUM

A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 …

Feb 13, 2025
CVE-2025-21701
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: avoid race between device unregistration and ethnl ops The following trace can be seen …

Feb 13, 2025
CVE-2025-26574
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moch Amir Google Drive WP Media google-drive-wp-media allows Stored XSS.This issue affects Google …

Feb 13, 2025
CVE-2025-26567
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in farjana55 Font Awesome WP font-awesome-wp allows DOM-Based XSS.This issue affects Font Awesome WP: …

Feb 13, 2025
CVE-2025-26561
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Yottie Lite yottie-lite allows Stored XSS.This issue affects Elfsight Yottie Lite: …

Feb 13, 2025
CVE-2025-26558
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Responsive aparat-responsive allows DOM-Based XSS.This issue affects Aparat Responsive: from n/a …

Feb 13, 2025
CVE-2025-26539
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petkivim Embed Google Map embed-google-map allows Stored XSS.This issue affects Embed Google Map: …

Feb 13, 2025
CVE-2025-26538
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi Embedder prezi-embedder allows Stored XSS.This issue affects Prezi Embedder: from …

Feb 13, 2025
CVE-2025-1271
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malicious JavaScript code into a URL. When a …

Feb 13, 2025
CVE-2024-13867
6.1 MEDIUM

The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, …

Feb 13, 2025
CVE-2024-3303
6.4 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from …

Feb 13, 2025
CVE-2024-13639
4.3 MEDIUM

The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the …

Feb 13, 2025
CVE-2025-0816
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious IPV6 packets are sent to the device.

Feb 13, 2025
CVE-2025-0815
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ICMPV6 packets are sent to the device.

Feb 13, 2025
CVE-2025-0814
5.3 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to …

Feb 13, 2025
CVE-2025-0661
4.3 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due …

Feb 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.