CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23849
5.4 MEDIUM

Missing Authorization vulnerability in bpiwowar PAPERCITE papercite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PAPERCITE: from n/a through <= 0.5.18.

Jan 27, 2025
CVE-2025-23669
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nurul Amin WP Smart Tooltip wp-smart-tool-tip allows Stored XSS.This issue affects WP Smart …

Jan 27, 2025
CVE-2025-23656
6.5 MEDIUM

Missing Authorization vulnerability in Saul Morales Pacheco Donate visa donate-visa allows Stored XSS.This issue affects Donate visa: from n/a through <= 1.0.0.

Jan 27, 2025
CVE-2025-23529
6.5 MEDIUM

Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Minterpress: from n/a through <= 1.0.5.

Jan 27, 2025
CVE-2025-24754
4.3 MEDIUM

Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0.

Jan 27, 2025
CVE-2025-24584
4.3 MEDIUM

Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Store Kit Elementor …

Jan 27, 2025
CVE-2025-24533
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Cross Site Request Forgery.This issue affects Responsive Slider by MetaSlider: from n/a …

Jan 27, 2025
CVE-2024-55931
6.5 MEDIUM

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised. The patch for this …

Jan 27, 2025
CVE-2025-0696
5.3 MEDIUM

A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library …

Jan 27, 2025
CVE-2025-0695
5.3 MEDIUM

An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the …

Jan 27, 2025
CVE-2024-12345
4.4 MEDIUM

A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknown functionality of the file /gbo.aspx of the …

Jan 27, 2025
CVE-2025-24814
5.5 MEDIUM

Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or …

Jan 27, 2025
CVE-2024-52012
5.4 MEDIUM

Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in …

Jan 27, 2025
CVE-2025-24390
6.8 MEDIUM

A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. This …

Jan 27, 2025
CVE-2025-24389
6.3 MEDIUM

Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system …

Jan 27, 2025
CVE-2024-43445
5.4 MEDIUM

A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this …

Jan 27, 2025
CVE-2024-13117
6.5 MEDIUM

The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded

Jan 27, 2025
CVE-2024-13095
4.8 MEDIUM

The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to …

Jan 27, 2025
CVE-2024-12774
6.5 MEDIUM

The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins …

Jan 27, 2025
CVE-2024-12436
4.3 MEDIUM

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Jan 27, 2025
CVE-2024-12280
4.3 MEDIUM

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make …

Jan 27, 2025
CVE-2024-28771
4.8 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers …

Jan 27, 2025
CVE-2024-28770
4.8 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers …

Jan 27, 2025
CVE-2023-46187
5.4 MEDIUM

IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Jan 27, 2025
CVE-2025-0722
4.7 MEDIUM

A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image …

Jan 27, 2025
CVE-2025-0721
4.3 MEDIUM

A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.php. The manipulation of the …

Jan 27, 2025
CVE-2017-20196
6.3 MEDIUM

A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affects an unknown part of the file /notice-edit.php. …

Jan 26, 2025
CVE-2023-50946
6.5 MEDIUM

IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken …

Jan 26, 2025
CVE-2023-50945
6.2 MEDIUM

IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.

Jan 26, 2025
CVE-2023-38009
4.2 MEDIUM

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.

Jan 26, 2025
CVE-2024-31906
6.2 MEDIUM

IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.

Jan 26, 2025
CVE-2024-13505
5.5 MEDIUM

The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due …

Jan 26, 2025
CVE-2024-12334
6.1 MEDIUM

The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up …

Jan 26, 2025
CVE-2024-11090
5.3 MEDIUM

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the …

Jan 26, 2025
CVE-2024-10705
5.4 MEDIUM

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via …

Jan 26, 2025
CVE-2024-10636
6.1 MEDIUM

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, …

Jan 26, 2025
CVE-2024-35150
5.3 MEDIUM

IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an …

Jan 25, 2025
CVE-2024-35148
6.3 MEDIUM

IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …

Jan 25, 2025
CVE-2024-35145
6.1 MEDIUM

IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in …

Jan 25, 2025
CVE-2024-35144
5.3 MEDIUM

IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against …

Jan 25, 2025
CVE-2024-35134
5.3 MEDIUM

IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. …

Jan 25, 2025
CVE-2024-35114
5.3 MEDIUM

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.

Jan 25, 2025
CVE-2024-35113
4.3 MEDIUM

IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through a directory listing.

Jan 25, 2025
CVE-2024-35112
5.4 MEDIUM

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the …

Jan 25, 2025
CVE-2024-35111
4.3 MEDIUM

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the …

Jan 25, 2025
CVE-2023-38716
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system that could aid in …

Jan 25, 2025
CVE-2023-38714
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the …

Jan 25, 2025
CVE-2023-38713
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the …

Jan 25, 2025
CVE-2023-38271
4.3 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to …

Jan 25, 2025
CVE-2023-38013
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HTTP …

Jan 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.