CVE Database

46519+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2118
7.3 HIGH

A vulnerability was found in Quantico Tecnologia PRMV 6.48. It has been classified as critical. This affects an unknown part of the file /admin/login.php of …

Mar 9, 2025
CVE-2025-2113
7.3 HIGH

A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been rated as critical. Affected by this issue is some unknown …

Mar 9, 2025
CVE-2024-11640
8.8 HIGH

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is …

Mar 8, 2025
CVE-2025-1323
7.5 HIGH

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, …

Mar 8, 2025
CVE-2024-13359
8.1 HIGH

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function …

Mar 8, 2025
CVE-2024-13882
8.8 HIGH

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file …

Mar 8, 2025
CVE-2024-13908
7.2 HIGH

The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all …

Mar 8, 2025
CVE-2024-11087
8.1 HIGH

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, …

Mar 8, 2025
CVE-2024-13890
7.2 HIGH

The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to …

Mar 8, 2025
CVE-2024-13835
7.2 HIGH

The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.4. This is due …

Mar 8, 2025
CVE-2025-2097
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The …

Mar 7, 2025
CVE-2025-27822
7.5 HIGH

An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. The module …

Mar 7, 2025
CVE-2025-2024
7.8 HIGH

Trimble SketchUp SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble …

Mar 7, 2025
CVE-2025-27607
8.8 HIGH

Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE …

Mar 7, 2025
CVE-2025-27604
7.5 HIGH

XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest …

Mar 7, 2025
CVE-2025-0162
7.1 HIGH

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker …

Mar 7, 2025
CVE-2024-53700
7.2 HIGH

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute …

Mar 7, 2025
CVE-2024-53699
7.2 HIGH

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Mar 7, 2025
CVE-2024-53697
7.2 HIGH

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Mar 7, 2025
CVE-2024-53693
7.1 HIGH

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Mar 7, 2025
CVE-2024-50394
8.8 HIGH

An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the …

Mar 7, 2025
CVE-2024-38638
7.2 HIGH

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Mar 7, 2025
CVE-2025-2088
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. Affected is an unknown function of the file …

Mar 7, 2025
CVE-2024-13668
7.1 HIGH

The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Mar 7, 2025
CVE-2025-0959
8.8 HIGH

The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up …

Mar 7, 2025
CVE-2024-9658
8.8 HIGH

The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. …

Mar 7, 2025
CVE-2024-12036
7.5 HIGH

The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This …

Mar 7, 2025
CVE-2024-12035
8.8 HIGH

The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions …

Mar 7, 2025
CVE-2024-10804
7.5 HIGH

The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via …

Mar 7, 2025
CVE-2025-26331
7.8 HIGH

Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local …

Mar 7, 2025
CVE-2025-1309
8.8 HIGH

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to …

Mar 7, 2025
CVE-2024-13906
7.2 HIGH

The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Mar 7, 2025
CVE-2024-12837
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.

Mar 7, 2025
CVE-2024-13655
8.1 HIGH

The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of …

Mar 7, 2025
CVE-2024-13320
7.5 HIGH

The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up …

Mar 7, 2025
CVE-2025-2067
7.3 HIGH

A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search.php. …

Mar 7, 2025
CVE-2025-2066
7.3 HIGH

A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /updateAgent.php. …

Mar 7, 2025
CVE-2025-2065
7.3 HIGH

A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. …

Mar 7, 2025
CVE-2025-2064
7.3 HIGH

A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0. Affected by this issue is some unknown functionality …

Mar 7, 2025
CVE-2025-2063
7.3 HIGH

A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mar 7, 2025
CVE-2025-2062
7.3 HIGH

A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The …

Mar 7, 2025
CVE-2025-2060
7.3 HIGH

A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as critical. This affects an unknown part of the file …

Mar 7, 2025
CVE-2025-2059
7.3 HIGH

A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 7, 2025
CVE-2025-2058
7.3 HIGH

A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 7, 2025
CVE-2025-2057
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/about-us.php. …

Mar 7, 2025
CVE-2025-0749
8.1 HIGH

The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being …

Mar 7, 2025
CVE-2025-2050
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3. Affected by this vulnerability is an unknown …

Mar 7, 2025
CVE-2025-27598
7.5 HIGH

ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using …

Mar 6, 2025
CVE-2025-2038
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Mar 6, 2025
CVE-2025-25497
8.1 HIGH

An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to …

Mar 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.