CVE Database

58777+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10539
5.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft Informatin Systems Uyumsoft ERP allows XSS Using Invalid Characters, Reflected …

Jan 23, 2025
CVE-2024-13422
6.1 MEDIUM

The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions …

Jan 23, 2025
CVE-2024-13389
6.4 MEDIUM

The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email' shortcode in all versions up to, and including, 1.3.4 due …

Jan 23, 2025
CVE-2024-13340
6.4 MEDIUM

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdf_results_by_ajax' shortcode in all versions …

Jan 23, 2025
CVE-2024-13236
6.5 MEDIUM

The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient …

Jan 23, 2025
CVE-2024-12504
6.4 MEDIUM

The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Jan 23, 2025
CVE-2024-12118
6.4 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all …

Jan 23, 2025
CVE-2025-0648
4.9 MEDIUM

Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of …

Jan 23, 2025
CVE-2025-0619
4.9 MEDIUM

Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords

Jan 23, 2025
CVE-2024-43708
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of …

Jan 23, 2025
CVE-2024-12043
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored …

Jan 23, 2025
CVE-2024-13511
4.3 MEDIUM

The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its …

Jan 23, 2025
CVE-2024-53299
6.5 MEDIUM

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server …

Jan 23, 2025
CVE-2024-52972
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot. This can …

Jan 23, 2025
CVE-2025-24530
6.4 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database …

Jan 23, 2025
CVE-2025-24529
6.4 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.

Jan 23, 2025
CVE-2024-43710
4.3 MEDIUM

A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to …

Jan 23, 2025
CVE-2024-42187
5.3 MEDIUM

BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local repository which is vulnerable …

Jan 23, 2025
CVE-2023-50309
6.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Jan 23, 2025
CVE-2023-32340
4.6 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Jan 23, 2025
CVE-2024-57724
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.

Jan 23, 2025
CVE-2024-57723
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.

Jan 23, 2025
CVE-2024-57721
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.

Jan 23, 2025
CVE-2024-57720
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.

Jan 23, 2025
CVE-2024-57719
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.

Jan 23, 2025
CVE-2024-12477
6.4 MEDIUM

The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due …

Jan 22, 2025
CVE-2024-56923
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute …

Jan 22, 2025
CVE-2024-56914
5.7 MEDIUM

D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.

Jan 22, 2025
CVE-2025-23047
6.5 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure for …

Jan 22, 2025
CVE-2025-24403
4.3 MEDIUM

A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials …

Jan 22, 2025
CVE-2025-24402
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using …

Jan 22, 2025
CVE-2025-24401
6.8 MEDIUM

Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically …

Jan 22, 2025
CVE-2025-24400
4.3 MEDIUM

Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create …

Jan 22, 2025
CVE-2025-24397
4.3 MEDIUM

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) …

Jan 22, 2025
CVE-2025-23028
5.3 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, …

Jan 22, 2025
CVE-2025-20128
5.3 MEDIUM

A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of …

Jan 22, 2025
CVE-2024-51457
4.4 MEDIUM

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user …

Jan 22, 2025
CVE-2025-23992
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion allows Stored XSS.This issue affects Toocheke Companion: from n/a …

Jan 22, 2025
CVE-2024-55488
6.5 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This …

Jan 22, 2025
CVE-2024-42013
6.4 MEDIUM

In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attacker with Windows administrative or debugging privileges can patch …

Jan 22, 2025
CVE-2024-42012
5.7 MEDIUM

GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext …

Jan 22, 2025
CVE-2024-10929
5.1 MEDIUM

In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of …

Jan 22, 2025
CVE-2025-24027
6.2 MEDIUM

ps_contactinfo, a PrestaShop module for displaying store contact information, has a cross-site scripting (XSS) vulnerability in versions up to and including 3.3.2. This can not …

Jan 22, 2025
CVE-2025-23684
4.3 MEDIUM

Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Debug Tool: from n/a through <= …

Jan 22, 2025
CVE-2025-23562
5.8 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-viewer allows Path Traversal.This issue affects XLSXviewer: from n/a through …

Jan 22, 2025
CVE-2025-23486
6.5 MEDIUM

Missing Authorization vulnerability in tamlyn Database Sync database-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database Sync: from n/a through <= 0.5.1.

Jan 22, 2025
CVE-2025-22980
6.7 MEDIUM

A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.

Jan 22, 2025
CVE-2025-0604
5.4 MEDIUM

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate …

Jan 22, 2025
CVE-2024-24432
5.3 MEDIUM

A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

Jan 22, 2025
CVE-2023-37012
5.3 MEDIUM

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may …

Jan 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.