CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0392
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. Affected is the function datagridGraph of the …

Jan 11, 2025
CVE-2025-0391
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This issue affects the function saveOrUpdate …

Jan 11, 2025
CVE-2025-0390
5.3 MEDIUM

A vulnerability classified as critical was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This vulnerability affects unknown code of the file /wmOmNoticeHController.do. …

Jan 11, 2025
CVE-2024-12527
6.4 MEDIUM

The Perfect Portal Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'perfect_portal_intake_form' shortcode in all versions up to, and including, …

Jan 11, 2025
CVE-2024-12520
6.4 MEDIUM

The Dominion – Domain Checker for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dominion_shortcodes_domain_search_6' shortcode in all versions up …

Jan 11, 2025
CVE-2024-12519
6.4 MEDIUM

The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_refresh' shortcode in all versions up to, and including, …

Jan 11, 2025
CVE-2024-12412
6.1 MEDIUM

The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored …

Jan 11, 2025
CVE-2024-12407
6.1 MEDIUM

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pushnotificationid' parameter in all versions up to, …

Jan 11, 2025
CVE-2024-12116
4.3 MEDIUM

The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via …

Jan 11, 2025
CVE-2024-11915
4.3 MEDIUM

The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.0 via the Popup block due …

Jan 11, 2025
CVE-2024-11892
6.4 MEDIUM

The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_slider' shortcode in all versions up to, and including, …

Jan 11, 2025
CVE-2024-11874
6.4 MEDIUM

The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordion' shortcode in all versions up to, and including, …

Jan 11, 2025
CVE-2024-11758
6.4 MEDIUM

The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 2.9 …

Jan 11, 2025
CVE-2024-11386
6.4 MEDIUM

The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsmartform' shortcode in all versions up to, and including, 1.1.0 …

Jan 11, 2025
CVE-2024-42173
4.8 MEDIUM

HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force …

Jan 11, 2025
CVE-2024-42172
5.3 MEDIUM

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. …

Jan 11, 2025
CVE-2024-42171
6.4 MEDIUM

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's …

Jan 11, 2025
CVE-2024-42170
6.8 MEDIUM

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's …

Jan 11, 2025
CVE-2024-12587
6.1 MEDIUM

The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 11, 2025
CVE-2025-23109
6.5 MEDIUM

Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in …

Jan 11, 2025
CVE-2025-23108
4.3 MEDIUM

Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the …

Jan 11, 2025
CVE-2024-12304
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link …

Jan 11, 2025
CVE-2025-0106
5.3 MEDIUM

A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.

Jan 11, 2025
CVE-2025-0104
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition …

Jan 11, 2025
CVE-2024-12505
6.4 MEDIUM

The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in all versions up to, and including, 5.0.2 due …

Jan 11, 2025
CVE-2024-12472
4.3 MEDIUM

The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() function due to …

Jan 11, 2025
CVE-2024-12204
5.4 MEDIUM

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access due to …

Jan 11, 2025
CVE-2024-11327
6.1 MEDIUM

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Jan 11, 2025
CVE-2025-23112
6.1 MEDIUM

An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name …

Jan 10, 2025
CVE-2025-23111
4.7 MEDIUM

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. …

Jan 10, 2025
CVE-2025-23110
6.1 MEDIUM

An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an upload of a CSV …

Jan 10, 2025
CVE-2024-9133
6.6 MEDIUM

A user with administrator privileges is able to retrieve authentication tokens

Jan 10, 2025
CVE-2024-7142
4.6 MEDIUM

On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. …

Jan 10, 2025
CVE-2024-47518
6.4 MEDIUM

Specially constructed queries targeting ETM could discover active remote access sessions

Jan 10, 2025
CVE-2024-47517
6.8 MEDIUM

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

Jan 10, 2025
CVE-2024-7095
4.3 MEDIUM

On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the …

Jan 10, 2025
CVE-2024-5872
6.5 MEDIUM

On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane …

Jan 10, 2025
CVE-2024-54998
5.4 MEDIUM

MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.

Jan 10, 2025
CVE-2024-54997
5.4 MEDIUM

MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.

Jan 10, 2025
CVE-2024-54994
6.5 MEDIUM

MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.

Jan 10, 2025
CVE-2024-6437
5.8 MEDIUM

On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP …

Jan 10, 2025
CVE-2024-33299
4.7 MEDIUM

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the …

Jan 10, 2025
CVE-2024-33298
6.1 MEDIUM

Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint …

Jan 10, 2025
CVE-2024-33297
4.7 MEDIUM

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add …

Jan 10, 2025
CVE-2025-23079
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - ArticleFeedbackv5 extension allows Cross-Site Scripting (XSS).This issue …

Jan 10, 2025
CVE-2024-54910
4.7 MEDIUM

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

Jan 10, 2025
CVE-2025-23078
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue …

Jan 10, 2025
CVE-2024-57222
6.3 MEDIUM

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

Jan 10, 2025
CVE-2024-54687
6.1 MEDIUM

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

Jan 10, 2025
CVE-2024-57214
6.3 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

Jan 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.