CVE Database

58777+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25290
5.3 MEDIUM

@octokit/request sends parameterized requests to GitHub’s APIs with sensible defaults in browsers and Node. Starting in version 1.0.0 and prior to versions 9.2.1 and 8.4.1, …

Feb 14, 2025
CVE-2025-25289
5.3 MEDIUM

@octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) …

Feb 14, 2025
CVE-2025-25288
5.3 MEDIUM

@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, …

Feb 14, 2025
CVE-2025-25285
5.3 MEDIUM

@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)` …

Feb 14, 2025
CVE-2025-26158
5.6 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to …

Feb 14, 2025
CVE-2025-26157
5.9 MEDIUM

A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary …

Feb 14, 2025
CVE-2025-25993
5.1 MEDIUM

SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."

Feb 14, 2025
CVE-2025-25992
5.1 MEDIUM

SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.

Feb 14, 2025
CVE-2025-25991
5.1 MEDIUM

SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

Feb 14, 2025
CVE-2025-25990
6.1 MEDIUM

Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

Feb 14, 2025
CVE-2025-25988
4.8 MEDIUM

Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the …

Feb 14, 2025
CVE-2025-25204
6.3 MEDIUM

`gh` is GitHub’s official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain conditions, a bug in GitHub's Artifact Attestation …

Feb 14, 2025
CVE-2024-57790
5.4 MEDIUM

IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows physically …

Feb 14, 2025
CVE-2024-56463
4.8 MEDIUM

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus …

Feb 14, 2025
CVE-2024-57725
6.5 MEDIUM

An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet …

Feb 14, 2025
CVE-2025-25740
5.5 MEDIUM

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the PSK parameter in the SetQuickVPNSettings module.

Feb 14, 2025
CVE-2024-56477
6.5 MEDIUM

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL …

Feb 14, 2025
CVE-2024-52895
6.5 MEDIUM

IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A …

Feb 14, 2025
CVE-2025-1071
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This …

Feb 14, 2025
CVE-2025-0178
6.1 MEDIUM

Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the …

Feb 14, 2025
CVE-2025-24607
5.8 MEDIUM

Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through <= 8.71.

Feb 14, 2025
CVE-2025-24567
6.5 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through …

Feb 14, 2025
CVE-2025-23771
6.5 MEDIUM

Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress push-notification-for-post-and-buddypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Push Notification for …

Feb 14, 2025
CVE-2025-23766
6.5 MEDIUM

Missing Authorization vulnerability in ashamil OPSI Israel Domestic Shipments woo-ups-pickup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OPSI Israel Domestic Shipments: from …

Feb 14, 2025
CVE-2025-23534
6.5 MEDIUM

Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLingo: from n/a through <= 1.1.2.

Feb 14, 2025
CVE-2025-22702
6.3 MEDIUM

Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2.

Feb 14, 2025
CVE-2025-22698
6.3 MEDIUM

Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Suite: from n/a through <= …

Feb 14, 2025
CVE-2025-0821
6.5 MEDIUM

Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to …

Feb 14, 2025
CVE-2024-13791
4.9 MEDIUM

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it …

Feb 14, 2025
CVE-2024-13735
6.4 MEDIUM

The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions …

Feb 14, 2025
CVE-2025-26791
4.5 MEDIUM

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

Feb 14, 2025
CVE-2024-9601
6.5 MEDIUM

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up …

Feb 14, 2025
CVE-2024-57969
4.3 MEDIUM

app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

Feb 14, 2025
CVE-2024-7052
4.8 MEDIUM

The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin …

Feb 14, 2025
CVE-2024-13692
5.4 MEDIUM

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure …

Feb 14, 2025
CVE-2024-13641
5.9 MEDIUM

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive …

Feb 14, 2025
CVE-2024-13493
4.8 MEDIUM

The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Feb 14, 2025
CVE-2025-23406
5.3 MEDIUM

Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a …

Feb 14, 2025
CVE-2025-1053
4.9 MEDIUM

Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. …

Feb 14, 2025
CVE-2024-10404
5.5 MEDIUM

CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS …

Feb 14, 2025
CVE-2024-57782
6.8 MEDIUM

An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.

Feb 13, 2025
CVE-2024-56908
6.8 MEDIUM

In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in …

Feb 13, 2025
CVE-2024-54951
5.4 MEDIUM

Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU …

Feb 13, 2025
CVE-2024-53311
5.5 MEDIUM

A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that …

Feb 13, 2025
CVE-2024-53310
5.5 MEDIUM

A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed …

Feb 13, 2025
CVE-2024-53309
5.5 MEDIUM

A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" …

Feb 13, 2025
CVE-2024-37603
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG …

Feb 13, 2025
CVE-2024-37602
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple Car Play function …

Feb 13, 2025
CVE-2024-37601
4.6 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of …

Feb 13, 2025
CVE-2024-37600
6.8 MEDIUM

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects …

Feb 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.