CVE Database

58777+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13627
4.7 MEDIUM

The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 17, 2025
CVE-2024-13608
4.7 MEDIUM

The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform …

Feb 17, 2025
CVE-2024-13603
6.1 MEDIUM

The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site …

Feb 17, 2025
CVE-2025-1374
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /search.php. …

Feb 17, 2025
CVE-2025-26700
5.2 MEDIUM

Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an …

Feb 17, 2025
CVE-2025-1372
5.3 MEDIUM

A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file …

Feb 17, 2025
CVE-2025-1370
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the function sprintf …

Feb 17, 2025
CVE-2025-1369
4.5 MEDIUM

A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerability is an unknown functionality of the component …

Feb 17, 2025
CVE-2025-1367
5.3 MEDIUM

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. This affects the function sprintf of the component …

Feb 17, 2025
CVE-2025-1366
5.3 MEDIUM

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the …

Feb 17, 2025
CVE-2025-1365
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component …

Feb 17, 2025
CVE-2025-26779
4.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fahad Mahmood Keep Backup Daily keep-backup-daily allows Path Traversal.This issue affects Keep …

Feb 16, 2025
CVE-2025-26767
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= …

Feb 16, 2025
CVE-2025-26766
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka leyka allows Stored XSS.This issue affects Leyka: from n/a through <= …

Feb 16, 2025
CVE-2025-26765
5.4 MEDIUM

Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Distance Based Shipping Calculator: from …

Feb 16, 2025
CVE-2025-26761
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows DOM-Based XSS.This issue affects Easy Elementor Addons: …

Feb 16, 2025
CVE-2025-23975
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cheesefather Botnet Attack Blocker botnet-attack-blocker allows Stored XSS.This issue affects Botnet Attack Blocker: …

Feb 16, 2025
CVE-2025-22689
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Levan Tarbor Forex Calculators fx-calculators allows Stored XSS.This issue affects Forex Calculators: from …

Feb 16, 2025
CVE-2025-22676
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in upcasted AWS S3 for WordPress Plugin – Upcasted upcasted-s3-offload allows Stored XSS.This issue …

Feb 16, 2025
CVE-2025-22291
5.3 MEDIUM

Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quotes-worldwide-express-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight …

Feb 16, 2025
CVE-2025-22289
6.5 MEDIUM

Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Unishippers Edition ltl-freight-quotes-unishippers-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes …

Feb 16, 2025
CVE-2025-1364
5.3 MEDIUM

A vulnerability has been found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this vulnerability is the function passPrompt of …

Feb 16, 2025
CVE-2025-1359
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SIAM Industria de Automação e Monitoramento SIAM 2.0. This issue affects some unknown processing …

Feb 16, 2025
CVE-2025-1358
4.3 MEDIUM

A vulnerability classified as problematic was found in Pix Software Vivaz 6.0.10. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The …

Feb 16, 2025
CVE-2025-1357
4.3 MEDIUM

A vulnerability classified as problematic has been found in Seventh D-Guard up to 20250206. This affects an unknown part of the component HTTP GET Request …

Feb 16, 2025
CVE-2025-1356
6.3 MEDIUM

A vulnerability was found in needyamin Library Card System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Feb 16, 2025
CVE-2025-1352
5.0 MEDIUM

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the …

Feb 16, 2025
CVE-2025-1339
6.3 MEDIUM

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of the file /cgi-bin/cstecgi.cgi. The …

Feb 16, 2025
CVE-2025-1336
4.3 MEDIUM

A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. Affected by this vulnerability is the function deleteimg_action in the library lib/admin/image_admin.php. The …

Feb 16, 2025
CVE-2025-1335
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9. Affected is the function deleteimg_action in the library lib/admin/file_admin.php. The manipulation of the …

Feb 16, 2025
CVE-2024-57970
4.0 MEDIUM

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a …

Feb 16, 2025
CVE-2024-13834
5.4 MEDIUM

The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-Side Request Forgery in all …

Feb 15, 2025
CVE-2025-0822
6.5 MEDIUM

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it …

Feb 15, 2025
CVE-2024-13500
6.5 MEDIUM

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL …

Feb 15, 2025
CVE-2024-13439
4.3 MEDIUM

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function …

Feb 15, 2025
CVE-2024-10581
4.3 MEDIUM

The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.9. This is due to missing …

Feb 15, 2025
CVE-2025-1005
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and …

Feb 15, 2025
CVE-2024-13752
6.5 MEDIUM

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss …

Feb 15, 2025
CVE-2025-22209
4.7 MEDIUM

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' …

Feb 15, 2025
CVE-2025-22208
4.7 MEDIUM

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' …

Feb 15, 2025
CVE-2025-0935
4.3 MEDIUM

The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in …

Feb 15, 2025
CVE-2024-13563
6.4 MEDIUM

The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password shortcode in all versions up to, and including, …

Feb 15, 2025
CVE-2024-13525
6.5 MEDIUM

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. …

Feb 15, 2025
CVE-2024-13306
4.3 MEDIUM

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high …

Feb 15, 2025
CVE-2024-13208
4.3 MEDIUM

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high …

Feb 15, 2025
CVE-2025-0996
5.4 MEDIUM

Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL …

Feb 15, 2025
CVE-2025-21401
4.5 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Feb 15, 2025
CVE-2024-10405
5.3 MEDIUM

Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade …

Feb 15, 2025
CVE-2022-28693
4.7 MEDIUM

Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

Feb 14, 2025
CVE-2025-25296
6.1 MEDIUM

Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` …

Feb 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.