CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1102
5.5 MEDIUM

A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2025-1101
5.3 MEDIUM

A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2024-57952
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "libfs: fix infinite directory reads for offset dir" The current directory offset allocator (based …

Feb 12, 2025
CVE-2025-1199
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been classified as critical. This affects an unknown part of the file …

Feb 12, 2025
CVE-2025-1197
6.3 MEDIUM

A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Feb 12, 2025
CVE-2024-10322
6.4 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, …

Feb 12, 2025
CVE-2025-1230
4.8 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This …

Feb 12, 2025
CVE-2025-1192
6.3 MEDIUM

A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. It has been classified as critical. Affected is an unknown function of the …

Feb 12, 2025
CVE-2025-1191
6.3 MEDIUM

A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file …

Feb 12, 2025
CVE-2025-1189
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0. This affects an unknown part of the file …

Feb 12, 2025
CVE-2025-0506
6.4 MEDIUM

The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the titleTag parameter in all versions …

Feb 12, 2025
CVE-2024-13459
6.4 MEDIUM

The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusedesk_newcase' shortcode in all versions up to, and including, 6.6.1 due …

Feb 12, 2025
CVE-2024-13456
6.4 MEDIUM

The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' shortcode in all versions up to, and including, …

Feb 12, 2025
CVE-2024-13437
4.3 MEDIUM

The Book a Room plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9. This is due to …

Feb 12, 2025
CVE-2025-1188
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of …

Feb 12, 2025
CVE-2025-1187
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Police FIR Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Feb 12, 2025
CVE-2024-13814
5.4 MEDIUM

The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 9.1.5. …

Feb 12, 2025
CVE-2025-1186
6.3 MEDIUM

A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects unknown code of the file /Control/Api/Api.php. …

Feb 12, 2025
CVE-2025-1185
6.3 MEDIUM

A vulnerability was found in pihome-shc PiHome 2.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?Ajax=GetModal_Sensor_Graph. The manipulation …

Feb 12, 2025
CVE-2024-13821
5.3 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due …

Feb 12, 2025
CVE-2024-13794
5.3 MEDIUM

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, …

Feb 12, 2025
CVE-2023-49780
6.1 MEDIUM

Cross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on the web browser of the user who accessed …

Feb 12, 2025
CVE-2025-1184
6.3 MEDIUM

A vulnerability was found in pihome-shc PiHome 1.77 and classified as critical. Affected by this issue is some unknown functionality of the file /ajax.php?Ajax=GetModal_MQTTEdit. The …

Feb 12, 2025
CVE-2025-1183
6.3 MEDIUM

A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 12, 2025
CVE-2024-13601
4.3 MEDIUM

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Feb 12, 2025
CVE-2024-13374
4.3 MEDIUM

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions …

Feb 12, 2025
CVE-2024-13769
6.4 MEDIUM

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a …

Feb 12, 2025
CVE-2024-13665
6.4 MEDIUM

The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 …

Feb 12, 2025
CVE-2024-13658
6.4 MEDIUM

The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and …

Feb 12, 2025
CVE-2024-12164
4.3 MEDIUM

The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Feb 12, 2025
CVE-2024-11746
6.4 MEDIUM

The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 12, 2025
CVE-2025-0808
4.3 MEDIUM

The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to …

Feb 12, 2025
CVE-2024-13749
6.1 MEDIUM

The StaffList plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing or …

Feb 12, 2025
CVE-2024-13701
6.4 MEDIUM

The Liveticker (by stklcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'liveticker' shortcode in all versions up to, and including, …

Feb 12, 2025
CVE-2024-13554
5.3 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Feb 12, 2025
CVE-2024-13541
4.3 MEDIUM

The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Feb 12, 2025
CVE-2024-13539
5.3 MEDIUM

The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. This is due the /vendor/aura/payload-interface/phpunit.php …

Feb 12, 2025
CVE-2024-29172
5.9 MEDIUM

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading …

Feb 12, 2025
CVE-2024-29171
5.9 MEDIUM

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this …

Feb 12, 2025
CVE-2024-53880
4.9 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability in the model loading API, where a user could cause an integer overflow or wraparound error by loading …

Feb 12, 2025
CVE-2024-0145
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPEG2000 file. A …

Feb 12, 2025
CVE-2024-0144
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a buffer overflow issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2024-0143
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2024-21971
5.5 MEDIUM

Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, resulting in an …

Feb 12, 2025
CVE-2024-0142
6.8 MEDIUM

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted JPEG2000 file. A successful …

Feb 12, 2025
CVE-2023-20508
5.0 MEDIUM

Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, …

Feb 12, 2025
CVE-2020-3432
5.6 MEDIUM

A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content …

Feb 12, 2025
CVE-2024-54916
6.8 MEDIUM

An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the …

Feb 11, 2025
CVE-2024-54772
5.4 MEDIUM

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available …

Feb 11, 2025
CVE-2024-44336
5.3 MEDIUM

An issue in AnkiDroid Android Application v2.17.6 allows attackers to retrieve internal files from the /data/data/com.ichi2.anki/ directory and save it into publicly available storage.

Feb 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.