CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57175
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.

Feb 3, 2025
CVE-2024-54840
4.2 MEDIUM

PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header …

Feb 3, 2025
CVE-2024-53943
6.1 MEDIUM

An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to XSS via the 2.4 GHz and 5 GHz name parameters, …

Feb 3, 2025
CVE-2024-53942
4.8 MEDIUM

An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to command injection via the 2.4 GHz and 5 GHz name …

Feb 3, 2025
CVE-2024-36437
6.5 MEDIUM

The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user …

Feb 3, 2025
CVE-2024-55456
6.5 MEDIUM

lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell

Feb 3, 2025
CVE-2024-38417
6.1 MEDIUM

Information disclosure while processing IO control commands.

Feb 3, 2025
CVE-2024-38416
6.1 MEDIUM

Information disclosure during audio playback.

Feb 3, 2025
CVE-2024-38414
6.1 MEDIUM

Information disclosure while processing information on firmware image during core initialization.

Feb 3, 2025
CVE-2024-38413
6.6 MEDIUM

Memory corruption while processing frame packets.

Feb 3, 2025
CVE-2024-38412
6.6 MEDIUM

Memory corruption while invoking IOCTL calls from user-space to kernel-space to handle session errors.

Feb 3, 2025
CVE-2024-38411
6.6 MEDIUM

Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.

Feb 3, 2025
CVE-2025-24697
6.5 MEDIUM

Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery awesome-responsive-photo-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Gallery – …

Feb 3, 2025
CVE-2025-24643
6.5 MEDIUM

Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPGuppy: from n/a through <= 1.1.0.

Feb 3, 2025
CVE-2025-24642
6.5 MEDIUM

Missing Authorization vulnerability in theme funda Setup Default Featured Image setup-default-feature-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Setup Default Featured Image: …

Feb 3, 2025
CVE-2025-24639
6.5 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Greys Korea for WooCommerce korea-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Korea for WooCommerce: from …

Feb 3, 2025
CVE-2025-24605
4.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through …

Feb 3, 2025
CVE-2025-23747
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nitesh Awesome Timeline awesome-timeline allows Stored XSS.This issue affects Awesome Timeline: from n/a …

Feb 3, 2025
CVE-2025-23581
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Demo User DZS demo-user-dzs-showcase-your-admin-safely allows Stored XSS.This issue affects Demo User DZS: …

Feb 3, 2025
CVE-2025-23561
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robertkay MLL Audio Player MP3 Ajax music-let-loose-mp3-audio-player allows Stored XSS.This issue affects MLL …

Feb 3, 2025
CVE-2025-23527
6.5 MEDIUM

Missing Authorization vulnerability in hemnathmouli WC Wallet wc-wallet allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WC Wallet: from n/a through <= 2.2.0.

Feb 3, 2025
CVE-2025-22701
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-essential-for-elementor.This issue affects Traveler Layout Essential For Elementor: from n/a through < 1.4.

Feb 3, 2025
CVE-2025-22695
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support nirweb-support.This issue affects Nirweb support: from n/a through <= 3.0.3.

Feb 3, 2025
CVE-2025-22694
4.3 MEDIUM

Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerce.This issue affects Hide Shipping Method For WooCommerce: from n/a through <= 1.5.1.

Feb 3, 2025
CVE-2025-22686
5.3 MEDIUM

Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Google Sheets Connector: from …

Feb 3, 2025
CVE-2025-22683
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper NotificationX notificationx allows Stored XSS.This issue affects NotificationX: from n/a through <= …

Feb 3, 2025
CVE-2025-22681
4.3 MEDIUM

Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Cloner: from n/a through <= 1.0.1.

Feb 3, 2025
CVE-2025-22677
4.8 MEDIUM

Missing Authorization vulnerability in UIUX Lab Uix Shortcodes uix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uix Shortcodes: from n/a through <= …

Feb 3, 2025
CVE-2025-22292
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Felipe Peixoto Powerful Auto Chat powers-triggers-of-woo-to-chat allows Stored XSS.This issue affects Powerful Auto …

Feb 3, 2025
CVE-2025-22260
4.3 MEDIUM

Missing Authorization vulnerability in Marcus (aka @msykes) Meta Tag Manager meta-tag-manager.This issue affects Meta Tag Manager: from n/a through <= 3.1.

Feb 3, 2025
CVE-2024-50500
4.3 MEDIUM

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and …

Feb 3, 2025
CVE-2024-57522
6.4 MEDIUM

SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the …

Feb 3, 2025
CVE-2024-6790
6.1 MEDIUM

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th …

Feb 3, 2025
CVE-2024-13347
6.8 MEDIUM

The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

Feb 3, 2025
CVE-2024-57966
5.0 MEDIUM

libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

Feb 3, 2025
CVE-2025-25063
4.4 MEDIUM

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure …

Feb 3, 2025
CVE-2025-25062
4.4 MEDIUM

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor …

Feb 3, 2025
CVE-2025-20642
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20641
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20640
4.3 MEDIUM

In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an …

Feb 3, 2025
CVE-2025-20639
6.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Feb 3, 2025
CVE-2025-20638
4.3 MEDIUM

In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker …

Feb 3, 2025
CVE-2025-20636
6.7 MEDIUM

In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Feb 3, 2025
CVE-2025-20635
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2024-20147
5.3 MEDIUM

In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional …

Feb 3, 2025
CVE-2024-20142
6.6 MEDIUM

In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2024-20141
6.6 MEDIUM

In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Feb 3, 2025
CVE-2025-0974
5.0 MEDIUM

A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can …

Feb 3, 2025
CVE-2025-0973
5.4 MEDIUM

A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The …

Feb 3, 2025
CVE-2025-0970
4.3 MEDIUM

A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.