CVE Database

58655+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25431
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.

Feb 28, 2025
CVE-2025-25430
4.8 MEDIUM

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.

Feb 28, 2025
CVE-2025-24843
5.1 MEDIUM

Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.

Feb 28, 2025
CVE-2025-24318
6.8 MEDIUM

Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.

Feb 28, 2025
CVE-2025-24316
5.3 MEDIUM

The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality.

Feb 28, 2025
CVE-2025-23405
5.3 MEDIUM

Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).

Feb 28, 2025
CVE-2025-20049
5.8 MEDIUM

The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.

Feb 28, 2025
CVE-2025-0985
5.5 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local …

Feb 28, 2025
CVE-2024-54175
5.5 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an …

Feb 28, 2025
CVE-2025-26263
5.1 MEDIUM

GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to improper memory handling in …

Feb 28, 2025
CVE-2025-26047
5.1 MEDIUM

Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.

Feb 28, 2025
CVE-2025-25461
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a malicious XSS …

Feb 28, 2025
CVE-2024-44754
6.8 MEDIUM

Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut …

Feb 28, 2025
CVE-2025-25916
5.4 MEDIUM

wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.

Feb 28, 2025
CVE-2025-1776
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to execute arbitrary code via the ‘query’ parameter in /app-google-custom-search/searchResults. …

Feb 28, 2025
CVE-2025-1749
4.7 MEDIUM

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending …

Feb 28, 2025
CVE-2025-1748
4.7 MEDIUM

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending …

Feb 28, 2025
CVE-2025-1747
4.7 MEDIUM

HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending …

Feb 28, 2025
CVE-2025-1746
6.1 MEDIUM

Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the …

Feb 28, 2025
CVE-2025-1300
6.1 MEDIUM

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open …

Feb 28, 2025
CVE-2024-10860
4.3 MEDIUM

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data due to a missing capability check …

Feb 28, 2025
CVE-2025-22492
6.3 MEDIUM

The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative …

Feb 28, 2025
CVE-2025-22491
6.7 MEDIUM

The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript …

Feb 28, 2025
CVE-2025-1662
6.4 MEDIUM

The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.0 via the 'url_media_uploader_url_upload' action. …

Feb 28, 2025
CVE-2025-1560
6.4 MEDIUM

The WOW Entrance Effects (WEE!) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wee' shortcode in all versions up to, and …

Feb 28, 2025
CVE-2024-9019
6.4 MEDIUM

The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's secupress_check_ban_ips_form shortcode in all versions up to, …

Feb 28, 2025
CVE-2024-13851
5.5 MEDIUM

The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.7.4.2 due to insufficient input sanitization …

Feb 28, 2025
CVE-2024-13832
4.3 MEDIUM

The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' …

Feb 28, 2025
CVE-2024-13716
4.3 MEDIUM

The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_settings_callback() function in all …

Feb 28, 2025
CVE-2024-13638
5.9 MEDIUM

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' …

Feb 28, 2025
CVE-2024-13469
6.4 MEDIUM

The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and including, …

Feb 28, 2025
CVE-2025-1572
6.5 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up …

Feb 28, 2025
CVE-2025-1571
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all …

Feb 28, 2025
CVE-2025-1405
6.4 MEDIUM

The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_products shortcode in all versions up to, and including, …

Feb 28, 2025
CVE-2025-0764
6.5 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class …

Feb 28, 2025
CVE-2025-1511
6.1 MEDIUM

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the …

Feb 28, 2025
CVE-2025-1506
4.3 MEDIUM

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0. …

Feb 28, 2025
CVE-2024-12820
6.4 MEDIUM

The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' shortcode in all versions up to, and including, …

Feb 28, 2025
CVE-2025-1757
6.4 MEDIUM

The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pfhub_portfolio' and 'pfhub_portfolio_portfolio' shortcodes in all …

Feb 28, 2025
CVE-2025-1505
6.1 MEDIUM

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, …

Feb 28, 2025
CVE-2025-0801
4.3 MEDIUM

The RateMyAgent Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing …

Feb 28, 2025
CVE-2024-13796
5.3 MEDIUM

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 …

Feb 28, 2025
CVE-2025-23225
6.5 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the …

Feb 28, 2025
CVE-2025-0823
6.5 MEDIUM

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could …

Feb 28, 2025
CVE-2024-56340
6.5 MEDIUM

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal …

Feb 28, 2025
CVE-2024-54173
4.7 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local …

Feb 28, 2025
CVE-2025-25728
6.5 MEDIUM

Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers …

Feb 28, 2025
CVE-2025-25727
6.2 MEDIUM

Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.

Feb 28, 2025
CVE-2025-1681
5.4 MEDIUM

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename …

Feb 28, 2025
CVE-2025-24832
5.5 MEDIUM

Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM …

Feb 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.