CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0967
6.3 MEDIUM

A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/add_chatroom.php. The manipulation …

Feb 2, 2025
CVE-2024-0131
4.4 MEDIUM

NVIDIA GPU kernel driver for Windows and Linux contains a vulnerability where a potential user-mode attacker could read a buffer with an incorrect length. A …

Feb 2, 2025
CVE-2025-0950
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file staffview.php. The …

Feb 1, 2025
CVE-2025-0949
6.3 MEDIUM

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file partview.php. The …

Feb 1, 2025
CVE-2025-0948
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file incview.php. The …

Feb 1, 2025
CVE-2025-0947
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Tailoring Management System 1.0. Affected by this issue is some unknown functionality of …

Feb 1, 2025
CVE-2025-0946
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file templatedelete.php. …

Feb 1, 2025
CVE-2025-0945
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file typedelete.php. The manipulation …

Feb 1, 2025
CVE-2025-0944
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Feb 1, 2025
CVE-2024-13775
5.4 MEDIUM

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', …

Feb 1, 2025
CVE-2024-13612
6.4 MEDIUM

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Feb 1, 2025
CVE-2025-0943
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file deldoc.php. …

Feb 1, 2025
CVE-2024-13429
4.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Feb 1, 2025
CVE-2024-13428
5.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Feb 1, 2025
CVE-2024-13425
4.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Feb 1, 2025
CVE-2024-13372
5.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Feb 1, 2025
CVE-2024-13371
5.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending …

Feb 1, 2025
CVE-2024-12825
5.4 MEDIUM

The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX …

Feb 1, 2025
CVE-2025-23091
5.9 MEDIUM

An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application …

Feb 1, 2025
CVE-2025-0939
6.3 MEDIUM

The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in …

Feb 1, 2025
CVE-2024-13341
6.5 MEDIUM

The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, …

Feb 1, 2025
CVE-2024-11829
6.4 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Feb 1, 2025
CVE-2025-0365
6.5 MEDIUM

The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. …

Feb 1, 2025
CVE-2024-13099
5.4 MEDIUM

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Feb 1, 2025
CVE-2024-13098
5.4 MEDIUM

The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 1, 2025
CVE-2024-13097
5.4 MEDIUM

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Feb 1, 2025
CVE-2024-13096
4.6 MEDIUM

The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Feb 1, 2025
CVE-2024-12768
5.4 MEDIUM

The Responsive iframe WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where …

Feb 1, 2025
CVE-2024-12041
5.3 MEDIUM

The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and …

Feb 1, 2025
CVE-2024-13651
4.3 MEDIUM

The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 1, 2025
CVE-2024-13547
6.4 MEDIUM

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and …

Feb 1, 2025
CVE-2024-12620
5.3 MEDIUM

The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Feb 1, 2025
CVE-2024-12184
5.3 MEDIUM

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() …

Feb 1, 2025
CVE-2024-11780
6.4 MEDIUM

The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultblock' shortcode in all versions up to, and including, …

Feb 1, 2025
CVE-2024-57435
6.5 MEDIUM

In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurring in all subsequent …

Jan 31, 2025
CVE-2024-53354
6.5 MEDIUM

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) …

Jan 31, 2025
CVE-2025-0934
6.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment 1.0. It has been classified as problematic. This affects an unknown part of the file /parse/_call_job_search_ajax.php. The …

Jan 31, 2025
CVE-2025-23001
6.1 MEDIUM

A Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can …

Jan 31, 2025
CVE-2024-49349
6.1 MEDIUM

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed …

Jan 31, 2025
CVE-2024-49339
6.4 MEDIUM

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed …

Jan 31, 2025
CVE-2024-42671
6.1 MEDIUM

A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to …

Jan 31, 2025
CVE-2025-22994
6.1 MEDIUM

O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings.

Jan 31, 2025
CVE-2024-49807
6.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to …

Jan 31, 2025
CVE-2024-47116
5.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to …

Jan 31, 2025
CVE-2024-47103
4.8 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to …

Jan 31, 2025
CVE-2024-45089
4.3 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information …

Jan 31, 2025
CVE-2024-40696
4.8 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to …

Jan 31, 2025
CVE-2024-11741
4.3 MEDIUM

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with …

Jan 31, 2025
CVE-2023-38739
4.3 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Jan 31, 2025
CVE-2025-0930
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in TeamCal Neo, version 3.8.2. This allows an attacker to execute malicious JavaScript code, after injecting code via the ‘abs’ parameter …

Jan 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.