CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22602
6.5 MEDIUM

Discourse is an open source platform for community discussion. In affected versions an attacker can execute arbitrary JavaScript on users' browsers by posting a malicious …

Feb 4, 2025
CVE-2024-56328
6.5 MEDIUM

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by posting a maliciously crafted onebox url. …

Feb 4, 2025
CVE-2024-45657
5.0 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.

Feb 4, 2025
CVE-2024-43187
5.9 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed …

Feb 4, 2025
CVE-2024-40700
6.1 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript …

Feb 4, 2025
CVE-2024-35138
6.5 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Feb 4, 2025
CVE-2025-24967
5.4 MEDIUM

reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker …

Feb 4, 2025
CVE-2025-24966
5.4 MEDIUM

reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers to inject …

Feb 4, 2025
CVE-2025-24963
5.9 MEDIUM

Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. …

Feb 4, 2025
CVE-2025-0630
6.5 MEDIUM

Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged …

Feb 4, 2025
CVE-2025-25039
4.7 MEDIUM

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the …

Feb 4, 2025
CVE-2025-24373
6.5 MEDIUM

woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerability allows unauthorized …

Feb 4, 2025
CVE-2025-0451
6.3 MEDIUM

Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Feb 4, 2025
CVE-2025-0445
5.4 MEDIUM

Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 4, 2025
CVE-2025-0444
6.3 MEDIUM

Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 4, 2025
CVE-2024-48019
5.4 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application administrators can …

Feb 4, 2025
CVE-2025-23060
6.6 MEDIUM

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to …

Feb 4, 2025
CVE-2025-23059
6.8 MEDIUM

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows …

Feb 4, 2025
CVE-2024-45659
5.3 MEDIUM

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Feb 4, 2025
CVE-2025-22730
6.5 MEDIUM

Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ksher: from n/a through <= 1.1.2.

Feb 4, 2025
CVE-2025-22697
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Reflected XSS.This issue affects Responsive Blocks: from n/a …

Feb 4, 2025
CVE-2025-22696
5.4 MEDIUM

Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Document Block – Upload & Embed Docs: from n/a through …

Feb 4, 2025
CVE-2025-22675
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Alert Box Block – Display notice/alerts in the front end alert-box-block allows …

Feb 4, 2025
CVE-2025-22674
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Product Blocks for WooCommerce product-blocks-for-woocommerce allows Stored XSS.This issue affects Product …

Feb 4, 2025
CVE-2025-22664
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from …

Feb 4, 2025
CVE-2025-22662
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Stored XSS.This issue affects SendPulse Email …

Feb 4, 2025
CVE-2025-22653
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv Music Press Pro music-press-pro allows Stored XSS.This issue affects Music Press Pro: …

Feb 4, 2025
CVE-2025-22643
4.3 MEDIUM

Missing Authorization vulnerability in famethemes OnePress onepress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OnePress: from n/a through <= 2.3.11.

Feb 4, 2025
CVE-2025-22642
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites Dynamic Conditions dynamicconditions allows Stored XSS.This issue affects Dynamic Conditions: from n/a …

Feb 4, 2025
CVE-2025-22641
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prem Tiwari FM Notification Bar fm-notification-bar allows Stored XSS.This issue affects FM Notification …

Feb 4, 2025
CVE-2025-22206
4.7 MEDIUM

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' …

Feb 4, 2025
CVE-2025-0825
5.3 MEDIUM

cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF …

Feb 4, 2025
CVE-2025-1019
4.3 MEDIUM

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This …

Feb 4, 2025
CVE-2025-1018
5.3 MEDIUM

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. …

Feb 4, 2025
CVE-2025-1015
5.4 MEDIUM

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a …

Feb 4, 2025
CVE-2025-1013
6.5 MEDIUM

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. …

Feb 4, 2025
CVE-2025-0510
6.5 MEDIUM

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This …

Feb 4, 2025
CVE-2024-11623
4.8 MEDIUM

Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed …

Feb 4, 2025
CVE-2024-13699
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter in all versions up to, and including, …

Feb 4, 2025
CVE-2025-24860
5.4 MEDIUM

Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or …

Feb 4, 2025
CVE-2024-27137
5.3 MEDIUM

In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry …

Feb 4, 2025
CVE-2024-13733
6.4 MEDIUM

The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's skt-blocks/post-carousel block in all versions …

Feb 4, 2025
CVE-2024-13529
6.5 MEDIUM

The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Feb 4, 2025
CVE-2024-13510
6.1 MEDIUM

The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or …

Feb 4, 2025
CVE-2024-13356
6.5 MEDIUM

The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This …

Feb 4, 2025
CVE-2024-13403
6.4 MEDIUM

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Feb 4, 2025
CVE-2025-20907
6.0 MEDIUM

Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.

Feb 4, 2025
CVE-2025-20906
5.5 MEDIUM

Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.

Feb 4, 2025
CVE-2025-20905
6.3 MEDIUM

Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.

Feb 4, 2025
CVE-2025-20904
6.3 MEDIUM

Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.

Feb 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.