CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47265
6.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, …

Feb 13, 2025
CVE-2024-47264
4.9 MEDIUM

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and …

Feb 13, 2025
CVE-2024-13120
4.8 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some …

Feb 13, 2025
CVE-2024-13119
4.8 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some …

Feb 13, 2025
CVE-2024-12586
6.1 MEDIUM

The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 13, 2025
CVE-2024-10083
5.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated …

Feb 13, 2025
CVE-2025-0837
6.4 MEDIUM

The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.6 due to insufficient input sanitization …

Feb 13, 2025
CVE-2024-13229
4.3 MEDIUM

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a …

Feb 13, 2025
CVE-2024-13227
6.4 MEDIUM

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank …

Feb 13, 2025
CVE-2025-1198
4.2 MEDIUM

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that …

Feb 13, 2025
CVE-2024-13644
6.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and …

Feb 13, 2025
CVE-2024-8266
4.4 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger …

Feb 13, 2025
CVE-2025-20097
4.3 MEDIUM

Uncaught exception in OpenBMC Firmware for the Intel(R) Server M50FCP Family and Intel(R) Server D50DNP Family before version R01.02.0002 may allow an authenticated user to …

Feb 12, 2025
CVE-2025-1229
6.3 MEDIUM

A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected by this vulnerability is an unknown functionality of the file /read/?page=1&logfile=eee&match=. …

Feb 12, 2025
CVE-2025-1228
4.3 MEDIUM

A vulnerability classified as problematic has been found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected is an unknown function of the file /read/?page=1&logfile=LOG_Monitor of the …

Feb 12, 2025
CVE-2024-57605
5.4 MEDIUM

Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components.

Feb 12, 2025
CVE-2024-57603
6.3 MEDIUM

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.

Feb 12, 2025
CVE-2024-57601
6.1 MEDIUM

Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.

Feb 12, 2025
CVE-2024-56939
5.4 MEDIUM

LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.

Feb 12, 2025
CVE-2024-56938
5.4 MEDIUM

LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content class.

Feb 12, 2025
CVE-2024-51122
6.1 MEDIUM

Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote attacker to execute arbitrary code via the ST, L, O, OU, …

Feb 12, 2025
CVE-2024-47006
6.7 MEDIUM

Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may allow an authenticated user to …

Feb 12, 2025
CVE-2024-42492
6.7 MEDIUM

Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user …

Feb 12, 2025
CVE-2024-42419
6.7 MEDIUM

Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially enable escalation of privilege via …

Feb 12, 2025
CVE-2024-42410
6.5 MEDIUM

Improper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.

Feb 12, 2025
CVE-2024-42405
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Quartus(R) Prime Software before version 23.1.1 Patch 1.01std may allow an authenticated user to potentially enable escalation of privilege …

Feb 12, 2025
CVE-2024-41934
5.9 MEDIUM

Improper access control in some Intel(R) GPA software before version 2024.3 may allow an authenticated user to potentially enable denial of service via local access.

Feb 12, 2025
CVE-2024-41166
6.1 MEDIUM

Stack-based buffer overflow in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable …

Feb 12, 2025
CVE-2024-40887
6.1 MEDIUM

Race condition in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial …

Feb 12, 2025
CVE-2024-39813
6.7 MEDIUM

Uncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

Feb 12, 2025
CVE-2024-39797
6.5 MEDIUM

Improper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of …

Feb 12, 2025
CVE-2024-39779
4.7 MEDIUM

Stack-based buffer overflow in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of …

Feb 12, 2025
CVE-2024-39606
6.1 MEDIUM

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable …

Feb 12, 2025
CVE-2024-39372
6.7 MEDIUM

Uncontrolled search path for the Intel(R) XTU software for Windows before version 7.14.2.14 may allow an authenticated user to potentially enable escalation of privilege via …

Feb 12, 2025
CVE-2024-39365
6.7 MEDIUM

Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user …

Feb 12, 2025
CVE-2024-39355
6.5 MEDIUM

Improper handling of physical or environmental conditions in some Intel(R) Processors may allow an authenticated user to enable denial of service via local access.

Feb 12, 2025
CVE-2024-39284
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

Feb 12, 2025
CVE-2024-39279
6.5 MEDIUM

Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local …

Feb 12, 2025
CVE-2024-36293
6.5 MEDIUM

Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial …

Feb 12, 2025
CVE-2024-36291
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allow an authenticated user to potentially enable escalation of privilege via …

Feb 12, 2025
CVE-2024-36285
5.6 MEDIUM

Race condition in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an authenticated user to potentially enable denial …

Feb 12, 2025
CVE-2024-36283
6.7 MEDIUM

Uncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenticated user to potentially enable escalation of privilege via …

Feb 12, 2025
CVE-2024-36280
6.7 MEDIUM

Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authenticated user to potentially enable escalation of privilege …

Feb 12, 2025
CVE-2024-36274
6.5 MEDIUM

Out-of-bounds write in the Intel(R) 800 Series Ethernet Driver for Intel(R) Ethernet Adapter Complete Driver Pack before versions 29.1 may allow an unauthenticated user to …

Feb 12, 2025
CVE-2024-32942
6.7 MEDIUM

Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially enable escalation of privilege via …

Feb 12, 2025
CVE-2024-32938
6.7 MEDIUM

Uncontrolled search path for some Intel(R) MPI Library for Windows software before version 2021.13 may allow an authenticated user to potentially enable escalation of privilege …

Feb 12, 2025
CVE-2024-31157
5.3 MEDIUM

Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

Feb 12, 2025
CVE-2024-31153
5.0 MEDIUM

Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local …

Feb 12, 2025
CVE-2024-31068
5.3 MEDIUM

Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access.

Feb 12, 2025
CVE-2024-30211
6.0 MEDIUM

Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potentially enable escalation of privilege …

Feb 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.