CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21644
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix tlb invalidation when wedging If GuC fails to load, the driver wedges, but …

Jan 19, 2025
CVE-2025-21643
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix kernel async DIO Netfslib needs to be able to handle kernel-initiated asynchronous DIO …

Jan 19, 2025
CVE-2025-21642
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: sysctl: sched: avoid using current->nsproxy Using the 'net' structure via 'current' is not recommended …

Jan 19, 2025
CVE-2025-21641
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: sysctl: blackhole timeout: avoid using current->nsproxy As mentioned in the previous commit, using the …

Jan 19, 2025
CVE-2025-21640
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21639
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: rto_min/max: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21638
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: auth_enable: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21637
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: udp_port: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21636
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: plpmtud_probe_interval: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21635
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21634
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: remove kernfs active break A warning was found: WARNING: CPU: 10 PID: 3486953 at …

Jan 19, 2025
CVE-2025-21632
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Ensure shadow stack is active before "getting" registers The x86 shadow stack support has …

Jan 19, 2025
CVE-2025-0567
4.5 MEDIUM

A vulnerability classified as problematic was found in Epic Games Launcher up to 17.2.1. This vulnerability affects unknown code in the library profapi.dll of the …

Jan 19, 2025
CVE-2024-8722
5.5 MEDIUM

The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all …

Jan 19, 2025
CVE-2024-45654
4.3 MEDIUM

IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.

Jan 19, 2025
CVE-2024-45653
4.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used …

Jan 19, 2025
CVE-2024-45652
6.5 MEDIUM

IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request …

Jan 19, 2025
CVE-2025-0563
6.3 MEDIUM

A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been classified as critical. Affected is an unknown function of the file /dash/update.php. The manipulation …

Jan 19, 2025
CVE-2025-0562
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/health_status_entry.php. The …

Jan 19, 2025
CVE-2025-0561
6.3 MEDIUM

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-pig.php. The …

Jan 19, 2025
CVE-2024-49824
6.5 MEDIUM

IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through …

Jan 18, 2025
CVE-2024-49354
5.3 MEDIUM

IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.

Jan 18, 2025
CVE-2024-47106
5.3 MEDIUM

IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information from improper access restrictions that could aid in …

Jan 18, 2025
CVE-2024-51448
6.7 MEDIUM

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install …

Jan 18, 2025
CVE-2024-49338
4.4 MEDIUM

IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.

Jan 18, 2025
CVE-2025-0558
6.3 MEDIUM

A vulnerability classified as critical was found in TDuckCloud tduck-platform up to 4.0. This vulnerability affects the function QueryProThemeRequest of the file src/main/java/com/tduck/cloud/form/request/QueryProThemeRequest.java. The manipulation …

Jan 18, 2025
CVE-2025-0557
4.3 MEDIUM

A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part …

Jan 18, 2025
CVE-2024-13392
6.4 MEDIUM

The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode …

Jan 18, 2025
CVE-2025-0515
4.3 MEDIUM

The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can …

Jan 18, 2025
CVE-2025-0369
6.4 MEDIUM

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to …

Jan 18, 2025
CVE-2024-13519
4.4 MEDIUM

The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, …

Jan 18, 2025
CVE-2024-13517
4.4 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in …

Jan 18, 2025
CVE-2024-13433
6.4 MEDIUM

The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' shortcode in all versions up to, and including, …

Jan 18, 2025
CVE-2024-13432
6.1 MEDIUM

The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or …

Jan 18, 2025
CVE-2024-13393
6.4 MEDIUM

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_videos' shortcode in …

Jan 18, 2025
CVE-2024-13391
6.4 MEDIUM

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' …

Jan 18, 2025
CVE-2024-13385
6.4 MEDIUM

The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ssm' shortcode in all versions up to, and …

Jan 18, 2025
CVE-2024-13317
4.3 MEDIUM

The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due …

Jan 18, 2025
CVE-2024-12696
6.4 MEDIUM

The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videowhisper_picture_upload_guest shortcode in …

Jan 18, 2025
CVE-2024-12385
6.1 MEDIUM

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing …

Jan 18, 2025
CVE-2025-0554
4.4 MEDIUM

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value in version <= 4.1.25 due to insufficient …

Jan 18, 2025
CVE-2025-0318
5.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all …

Jan 18, 2025
CVE-2024-9020
5.4 MEDIUM

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jan 18, 2025
CVE-2024-13516
6.1 MEDIUM

The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, …

Jan 18, 2025
CVE-2024-13515
6.1 MEDIUM

The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'path' parameter in …

Jan 18, 2025
CVE-2024-12071
5.3 MEDIUM

The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data …

Jan 18, 2025
CVE-2024-11923
5.5 MEDIUM

Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior …

Jan 18, 2025
CVE-2018-9406
5.5 MEDIUM

In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privilege …

Jan 18, 2025
CVE-2018-9405
6.7 MEDIUM

In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Jan 18, 2025
CVE-2018-9447
5.5 MEDIUM

In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to …

Jan 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.