Vulnerability & Exploit Database

Try Surface Command Get a continuous 360° view of your attack surface

A curated repository of vetted computer software exploits and exploitable vulnerabilities.

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review. The exploits are all included in the Metasploit framework. Our vulnerability and exploit database is updated frequently and contains the most recent security research.

Results 4,021 - 4,040 of 254,041 in total
security-advisory-0112
Published: March 11, 2025 | Severity: 8
vulnerability
Explore
Oracle Linux: CVE-2025-24201: ELSA-2025-2863: webkit2gtk3 security update (IMPORTANT) (Multiple Advisories)
Published: March 11, 2025 | Severity: 8
vulnerability
Explore
WordPress Plugin: finale-woocommerce-sales-countdown-timer-discount: CVE-2024-12589: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published: March 11, 2025 | Severity: 5
vulnerability
Explore
WordPress Plugin: event-post: CVE-2025-26923: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published: March 11, 2025 | Severity: 7
vulnerability
Explore
Apache Tomcat: Important: Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet - (CVE-2025-24813)
Published: March 11, 2025 | Severity: 9
vulnerability
Explore
WordPress Plugin: plugins-last-updated-column: CVE-2025-28887: Cross-Site Request Forgery (CSRF)
Published: March 11, 2025 | Severity: 5
vulnerability
Explore
WordPress Plugin: accounting-for-woocommerce: CVE-2025-26929: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published: March 11, 2025 | Severity: 6
vulnerability
Explore
WordPress Plugin: form-maker: CVE-2024-10560: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published: March 11, 2025 | Severity: 5
vulnerability
Explore
SUSE: CVE-2025-2174: SUSE Linux Security Advisory
Published: March 11, 2025 | Severity: 5
vulnerability
Explore
WordPress Plugin: maintenance-notice: CVE-2025-28859: Cross-Site Request Forgery (CSRF)
Published: March 11, 2025 | Severity: 5
vulnerability
Explore
SUSE: CVE-2025-2176: SUSE Linux Security Advisory
Published: March 11, 2025 | Severity: 8
vulnerability
Explore
WordPress Plugin: woolentor-addons: CVE-2025-1527: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published: March 11, 2025 | Severity: 5
vulnerability
Explore
WordPress Plugin: lana-downloads-manager: CVE-2025-2048: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Published: March 11, 2025 | Severity: 3
vulnerability
Explore
Ubuntu: USN-7367-1 (CVE-2025-2176): zvbi vulnerabilities
Published: March 11, 2025 | Severity: 8
vulnerability
Explore
Ubuntu: USN-7367-1 (CVE-2025-2174): zvbi vulnerabilities
Published: March 11, 2025 | Severity: 5
vulnerability
Explore
Ubuntu: USN-7367-1 (CVE-2025-2173): zvbi vulnerabilities
Published: March 11, 2025 | Severity: 5
vulnerability
Explore
Ubuntu: (Multiple Advisories) (CVE-2025-27363): FreeType vulnerability
Published: March 11, 2025 | Severity: 7
vulnerability
Explore
Ubuntu: USN-7367-1 (CVE-2025-2175): zvbi vulnerabilities
Published: March 11, 2025 | Severity: 4
vulnerability
Explore
Red Hat: CVE-2025-27363: freetype: OOB write when attempting to parse font subglyph structures related to TrueType GX and variable font files (Multiple Advisories)
Published: March 11, 2025 | Severity: 8
vulnerability
Explore
Debian: CVE-2025-2174: zvbi -- security update
Published: March 11, 2025 | Severity: 5
vulnerability
Explore