CVE Database

46519+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1858
7.3 HIGH

A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of …

Mar 3, 2025
CVE-2025-1857
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. …

Mar 3, 2025
CVE-2025-1856
7.3 HIGH

A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mar 3, 2025
CVE-2025-1723
8.1 HIGH

Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only …

Mar 3, 2025
CVE-2025-1853
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component …

Mar 3, 2025
CVE-2025-1852
8.8 HIGH

A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation …

Mar 3, 2025
CVE-2025-1851
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC7 up to 15.03.06.44. This affects the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The …

Mar 3, 2025
CVE-2025-1850
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by this issue is some unknown functionality of …

Mar 3, 2025
CVE-2025-20645
7.8 HIGH

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Mar 3, 2025
CVE-2025-25951
7.5 HIGH

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive …

Mar 3, 2025
CVE-2025-25950
8.1 HIGH

Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, …

Mar 3, 2025
CVE-2025-1841
7.3 HIGH

A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the file /CDGServer3/logManagement/ClientSortLog.jsp. The manipulation of the …

Mar 3, 2025
CVE-2025-1840
7.3 HIGH

A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Mar 3, 2025
CVE-2025-1815
7.3 HIGH

A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The …

Mar 2, 2025
CVE-2025-1814
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is some unknown functionality of the file …

Mar 2, 2025
CVE-2025-1811
7.3 HIGH

A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been declared as critical. Affected by this vulnerability is an unknown …

Mar 2, 2025
CVE-2025-1809
7.3 HIGH

A vulnerability was found in Pixsoft Sol up to 7.6.6c and classified as critical. This issue affects some unknown processing of the file /pix_projetos/servlet?act=login&submit=1&evento=0&pixrnd=0125021816444195731041 of …

Mar 2, 2025
CVE-2025-1808
7.3 HIGH

A vulnerability has been found in Pixsoft E-Saphira 1.7.24 and classified as critical. This vulnerability affects unknown code of the file /servlet?act=login&tipo=1 of the component …

Mar 2, 2025
CVE-2025-1804
7.0 HIGH

A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in …

Mar 1, 2025
CVE-2024-13833
7.2 HIGH

The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization …

Mar 1, 2025
CVE-2024-13910
7.2 HIGH

The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation …

Mar 1, 2025
CVE-2024-13611
7.5 HIGH

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Mar 1, 2025
CVE-2024-13911
7.2 HIGH

The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Mar 1, 2025
CVE-2024-12544
8.8 HIGH

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary …

Mar 1, 2025
CVE-2024-13373
8.1 HIGH

The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.1. This is due …

Mar 1, 2025
CVE-2024-13568
7.5 HIGH

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Mar 1, 2025
CVE-2025-23119
7.5 HIGH

An Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a malicious actor with access to …

Mar 1, 2025
CVE-2025-25723
8.4 HIGH

Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.

Feb 28, 2025
CVE-2025-25635
8.0 HIGH

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of …

Feb 28, 2025
CVE-2025-25610
8.0 HIGH

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of …

Feb 28, 2025
CVE-2025-25609
8.0 HIGH

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of …

Feb 28, 2025
CVE-2025-25428
8.0 HIGH

TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Feb 28, 2025
CVE-2025-0160
8.1 HIGH

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 …

Feb 28, 2025
CVE-2025-24849
7.1 HIGH

Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.

Feb 28, 2025
CVE-2025-20060
7.5 HIGH

An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

Feb 28, 2025
CVE-2025-26326
8.8 HIGH

A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain …

Feb 28, 2025
CVE-2025-1319
7.2 HIGH

The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up …

Feb 28, 2025
CVE-2025-1570
8.1 HIGH

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up …

Feb 28, 2025
CVE-2024-9195
8.8 HIGH

The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …

Feb 28, 2025
CVE-2024-13831
7.2 HIGH

The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted …

Feb 28, 2025
CVE-2025-1513
7.2 HIGH

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is …

Feb 28, 2025
CVE-2025-0975
8.8 HIGH

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of …

Feb 28, 2025
CVE-2025-25729
7.5 HIGH

An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via …

Feb 28, 2025
CVE-2025-25477
8.1 HIGH

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in …

Feb 28, 2025
CVE-2025-1687
8.8 HIGH

The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation …

Feb 28, 2025
CVE-2025-1682
8.8 HIGH

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' …

Feb 28, 2025
CVE-2024-12811
8.8 HIGH

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it possible …

Feb 28, 2025
CVE-2025-26264
8.8 HIGH

GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated …

Feb 27, 2025
CVE-2024-38291
8.8 HIGH

In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.

Feb 27, 2025
CVE-2024-41340
8.4 HIGH

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to …

Feb 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.