CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13444
6.1 MEDIUM

The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or …

Jan 21, 2025
CVE-2024-13230
5.3 MEDIUM

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter …

Jan 21, 2025
CVE-2024-11226
6.4 MEDIUM

The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and …

Jan 21, 2025
CVE-2025-23184
5.9 MEDIUM

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances …

Jan 21, 2025
CVE-2024-6466
5.3 MEDIUM

NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.

Jan 21, 2025
CVE-2024-13404
6.1 MEDIUM

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due …

Jan 21, 2025
CVE-2024-12104
5.3 MEDIUM

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability …

Jan 21, 2025
CVE-2024-12005
6.1 MEDIUM

The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or …

Jan 21, 2025
CVE-2025-0371
6.4 MEDIUM

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient …

Jan 21, 2025
CVE-2025-23086
6.1 MEDIUM

On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site …

Jan 21, 2025
CVE-2024-13536
5.3 MEDIUM

The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the …

Jan 21, 2025
CVE-2024-45091
6.2 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read …

Jan 21, 2025
CVE-2025-24014
4.2 MEDIUM

Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim …

Jan 20, 2025
CVE-2024-13454
5.3 MEDIUM

Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL …

Jan 20, 2025
CVE-2024-22349
4.0 MEDIUM

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another …

Jan 20, 2025
CVE-2024-22348
5.3 MEDIUM

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out …

Jan 20, 2025
CVE-2024-22347
5.9 MEDIUM

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt …

Jan 20, 2025
CVE-2025-23221
5.4 MEDIUM

Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. This vulnerability allows a user to maneuver the Webfinger …

Jan 20, 2025
CVE-2025-24013
5.3 MEDIUM

CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential attacker can construct …

Jan 20, 2025
CVE-2025-24010
6.5 MEDIUM

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due …

Jan 20, 2025
CVE-2025-23044
6.8 MEDIUM

PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This …

Jan 20, 2025
CVE-2025-22620
5.0 MEDIUM

gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask …

Jan 20, 2025
CVE-2025-22131
6.1 MEDIUM

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a …

Jan 20, 2025
CVE-2024-45647
5.6 MEDIUM

IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the …

Jan 20, 2025
CVE-2025-21655
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but …

Jan 20, 2025
CVE-2024-13176
4.1 MEDIUM

Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in …

Jan 20, 2025
CVE-2023-52923
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: adapt set backend to use GC transaction API Use the GC transaction API …

Jan 20, 2025
CVE-2025-0584
5.3 MEDIUM

The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.

Jan 20, 2025
CVE-2025-0582
4.7 MEDIUM

A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the file /add-pig.php. The …

Jan 20, 2025
CVE-2025-0580
5.6 MEDIUM

A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 20, 2025
CVE-2024-13524
4.5 MEDIUM

A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected by this vulnerability is an unknown …

Jan 20, 2025
CVE-2025-0583
6.1 MEDIUM

The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Jan 20, 2025
CVE-2025-0576
4.3 MEDIUM

A vulnerability was found in Mobotix M15 4.3.4.83 and classified as problematic. This issue affects some unknown processing of the file /control/player?center&eventlist&pda&dummy_for_reload=1736177631&p_evt. The manipulation of …

Jan 20, 2025
CVE-2024-57927
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfs: Fix oops in nfs_netfs_init_request() when copying to cache When netfslib wants to copy some …

Jan 19, 2025
CVE-2024-57924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles Encoding file handles is usually performed …

Jan 19, 2025
CVE-2024-57923
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: zlib: fix avail_in bytes for s390 zlib HW compression path Since the input data …

Jan 19, 2025
CVE-2024-57922
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add check for granularity in dml ceil/floor helpers [Why] Wrapper functions for dcn_bw_ceil2() and …

Jan 19, 2025
CVE-2024-57921
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add a lock when accessing the buddy trim function When running YouTube videos and …

Jan 19, 2025
CVE-2024-57919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix divide error in DM plane scale calcs dm_get_plane_scale doesn't take into account plane …

Jan 19, 2025
CVE-2024-57918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix page fault due to max surface definition mismatch DC driver is using two …

Jan 19, 2025
CVE-2024-57916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: Resolve kernel panic during GPIO IRQ handling Resolve kernel panic caused by …

Jan 19, 2025
CVE-2024-57914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci: fix NULL pointer issue on shared irq case The tcpci_irq() may meet …

Jan 19, 2025
CVE-2024-57913
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Remove WARN_ON in functionfs_bind This commit addresses an issue related to below …

Jan 19, 2025
CVE-2025-21654
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ovl: support encoding fid from inode with no alias Dmitry Safonov reported that a WARN_ON() …

Jan 19, 2025
CVE-2025-21653
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute syzbot found that TCA_FLOW_RSHIFT attribute was not validated. Right shitfing …

Jan 19, 2025
CVE-2025-21651
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: don't auto enable misc vector Currently, there is a time window between misc …

Jan 19, 2025
CVE-2025-21649
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when 1588 is sent on HIP08 devices Currently, HIP08 devices …

Jan 19, 2025
CVE-2025-21648
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: clamp maximum hashtable size to INT_MAX Use INT_MAX as maximum size for the …

Jan 19, 2025
CVE-2025-21646
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: afs: Fix the maximum cell name length The kafs filesystem limits the maximum length of …

Jan 19, 2025
CVE-2025-21645
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042 actually enabled it Wakeup for IRQ1 should be …

Jan 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.