CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24831
6.6 MEDIUM

Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-24830
6.3 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-24829
6.3 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-24828
6.3 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-24827
6.3 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

Jan 31, 2025
CVE-2025-21683
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_sk_select_reuseport() memory leak As pointed out in the original comment, lookup in sockmap …

Jan 31, 2025
CVE-2025-21682
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is …

Jan 31, 2025
CVE-2025-21681
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix lockup on tx to unregistering netdev with carrier Commit in a fixes tag …

Jan 31, 2025
CVE-2025-21679
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: add the missing error handling inside get_canonical_dev_path Inside function get_canonical_dev_path(), we call d_path() to …

Jan 31, 2025
CVE-2025-21678
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gtp: Destroy device along with udp socket's netns dismantle. gtp_newlink() links the device to a …

Jan 31, 2025
CVE-2025-21677
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pfcp: Destroy device along with udp socket's netns dismantle. pfcp_newlink() links the device to a …

Jan 31, 2025
CVE-2025-21676
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: fec: handle page_pool_dev_alloc_pages error The fec_enet_update_cbd function calls page_pool_dev_alloc_pages but did not handle the …

Jan 31, 2025
CVE-2025-21675
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clear port select structure when fail to create Clear the port select structure on …

Jan 31, 2025
CVE-2025-21674
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel Attempt to enable IPsec packet offload …

Jan 31, 2025
CVE-2025-21673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd …

Jan 31, 2025
CVE-2025-21672
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: afs: Fix merge preference rule failure condition syzbot reported a lock held when returning to …

Jan 31, 2025
CVE-2025-21670
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock/bpf: return early if transport is not assigned Some of the core functions can only …

Jan 31, 2025
CVE-2025-21669
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been de-assigned or assigned …

Jan 31, 2025
CVE-2025-21668
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: add missing loop break condition Currently imx8mp_blk_ctrl_remove() will continue the for loop until …

Jan 31, 2025
CVE-2025-21667
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iomap: avoid avoid truncating 64-bit offset to 32 bits on 32-bit kernels, iomap_write_delalloc_scan() was inadvertently …

Jan 31, 2025
CVE-2025-21666
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports have shown how we sometimes call vsock_*_has_data() when …

Jan 31, 2025
CVE-2025-21665
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: filemap: avoid truncating 64-bit offset to 32 bits On 32-bit kernels, folio_seek_hole_data() was inadvertently truncating …

Jan 31, 2025
CVE-2024-57948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mac802154: check local interfaces before deleting sdata list syzkaller reported a corrupted list in ieee802154_if_remove. …

Jan 31, 2025
CVE-2024-13662
6.4 MEDIUM

The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_objects_image_grid' shortcode in all versions up to, and …

Jan 31, 2025
CVE-2024-12415
6.5 MEDIUM

The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due …

Jan 31, 2025
CVE-2024-12267
5.3 MEDIUM

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file …

Jan 31, 2025
CVE-2024-12037
6.4 MEDIUM

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Jan 31, 2025
CVE-2025-24597
6.5 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Retrieve Embedded Sensitive Data.This …

Jan 31, 2025
CVE-2025-23987
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codegearthemes Designer designer allows DOM-Based XSS.This issue affects Designer: from n/a through <= …

Jan 31, 2025
CVE-2025-23985
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in brainvireinfo Dynamic URL SEO dynamic-url-seo allows Cross Site Request Forgery.This issue affects Dynamic URL SEO: from n/a through <= …

Jan 31, 2025
CVE-2025-22757
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Stored XSS.This issue affects CodeBard Help Desk: …

Jan 31, 2025
CVE-2025-22720
5.8 MEDIUM

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from …

Jan 31, 2025
CVE-2025-22265
6.5 MEDIUM

Missing Authorization vulnerability in mgplugin EMI Calculator emi-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EMI Calculator: from n/a through <= 1.1.

Jan 31, 2025
CVE-2024-44055
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshine Modules: from n/a through < 3.3.8.

Jan 31, 2025
CVE-2024-13566
6.4 MEDIUM

The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 0.2.6 due …

Jan 31, 2025
CVE-2024-13157
6.4 MEDIUM

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS …

Jan 31, 2025
CVE-2024-53007
6.4 MEDIUM

Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authenticated user via an API call.

Jan 31, 2025
CVE-2024-13530
4.3 MEDIUM

The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in …

Jan 31, 2025
CVE-2024-13623
5.9 MEDIUM

The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via the 'uploads' …

Jan 31, 2025
CVE-2025-22216
5.4 MEDIUM

A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use …

Jan 31, 2025
CVE-2024-13717
4.3 MEDIUM

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Jan 31, 2025
CVE-2024-13424
4.3 MEDIUM

The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint …

Jan 31, 2025
CVE-2024-13415
4.3 MEDIUM

The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check …

Jan 31, 2025
CVE-2024-13226
6.1 MEDIUM

The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Jan 31, 2025
CVE-2024-13225
6.1 MEDIUM

The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Jan 31, 2025
CVE-2024-13224
6.1 MEDIUM

The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading …

Jan 31, 2025
CVE-2024-13223
6.1 MEDIUM

The Tabulate WordPress plugin through 2.10.3 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site …

Jan 31, 2025
CVE-2024-13222
6.1 MEDIUM

The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13221
6.1 MEDIUM

The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13220
6.1 MEDIUM

The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in …

Jan 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.