CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-28960
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in regibaer Evangelische Termine evangtermine allows Reflected XSS.This issue affects Evangelische Termine: from n/a …

Jun 27, 2025
CVE-2025-28956
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphobby Backwp backwp allows Reflected XSS.This issue affects Backwp: from n/a through <= …

Jun 27, 2025
CVE-2025-28947
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme MBStore - Digital WooCommerce WordPress Theme mbstore allows …

Jun 27, 2025
CVE-2025-28946
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme PrintXtore bw-printxtore allows PHP Local File Inclusion.This issue …

Jun 27, 2025
CVE-2025-27361
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thhake Photo Express for Google photo-express-for-google allows Reflected XSS.This issue affects Photo Express …

Jun 27, 2025
CVE-2025-25173
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FasterThemes FastBook fastbook-responsive-appointment-booking-and-scheduling-system allows Stored XSS.This issue affects FastBook: from n/a through <= …

Jun 27, 2025
CVE-2025-25171
8.8 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authentication Abuse.This issue affects WP SmartPay: from n/a through …

Jun 27, 2025
CVE-2025-24774
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce wpcrm allows Reflected …

Jun 27, 2025
CVE-2025-24769
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Zenny bw-zenny allows PHP Local File Inclusion.This issue …

Jun 27, 2025
CVE-2025-24765
7.7 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RobMarsh Image Shadow image-shadow allows Path Traversal.This issue affects Image Shadow: from …

Jun 27, 2025
CVE-2025-24760
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Sofass sofass allows PHP Local File Inclusion.This issue …

Jun 27, 2025
CVE-2025-23973
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugudlabs SpecFit-Virtual Try On Woocommerce try-on-for-woocommerce allows Stored XSS.This issue affects SpecFit-Virtual Try …

Jun 27, 2025
CVE-2025-23967
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought Together for WooCommerce gg-bought-together allows SQL Injection.This issue …

Jun 27, 2025
CVE-2023-25998
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme …

Jun 27, 2025
CVE-2025-6761
7.3 HIGH

A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobilePopHtml of …

Jun 27, 2025
CVE-2025-5398
6.4 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of …

Jun 27, 2025
CVE-2025-2940
7.2 HIGH

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 …

Jun 27, 2025
CVE-2024-12827
9.8 CRITICAL

The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and …

Jun 27, 2025
CVE-2025-6689
6.4 MEDIUM

The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3raccessibilitysuite shortcode in all versions up to, and including, …

Jun 27, 2025
CVE-2025-6688
9.8 CRITICAL

The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying …

Jun 27, 2025
CVE-2025-6550
6.4 MEDIUM

The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ parameter in all versions up to, and including, …

Jun 27, 2025
CVE-2025-5940
6.4 MEDIUM

The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter in all versions …

Jun 27, 2025
CVE-2025-5936
4.3 MEDIUM

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing …

Jun 27, 2025
CVE-2025-5306
9.8 CRITICAL

Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778

Jun 27, 2025
CVE-2025-4587
6.4 MEDIUM

The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-testing-for-wp/ab-test-block' block in all versions up to, and …

Jun 27, 2025
CVE-2025-5526
4.3 MEDIUM

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another …

Jun 27, 2025
CVE-2025-5194
4.8 MEDIUM

The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting them back in a page/post …

Jun 27, 2025
CVE-2025-5093
5.4 MEDIUM

The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back …

Jun 27, 2025
CVE-2025-5035
5.4 MEDIUM

The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with …

Jun 27, 2025
CVE-2025-41418
5.3 MEDIUM

Buffer Overflow vulnerability exists in multiple versions of TB-eye network recorders and AHD recorders. The CGI process may be terminated abnormally by processing a specially …

Jun 27, 2025
CVE-2025-36529
7.2 HIGH

An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited, an arbitrary OS command …

Jun 27, 2025
CVE-2025-6753
6.3 MEDIUM

A vulnerability was found in huija bicycleSharingServer 1.0 and classified as critical. This issue affects the function selectAdminByNameLike of the file AdminController.java. The manipulation leads …

Jun 27, 2025
CVE-2025-6488
6.4 MEDIUM

The isMobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ parameter in all versions up to, and including, 1.1.1 due to …

Jun 27, 2025
CVE-2025-45737
6.5 MEDIUM

An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL commands to the NeacSafe64.sys …

Jun 27, 2025
CVE-2025-6752
8.8 HIGH

A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critical. This vulnerability affects the function SetDefaultConnectionService …

Jun 27, 2025
CVE-2025-6751
8.8 HIGH

A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the function set_device_language of the file portal.cgi of …

Jun 27, 2025
CVE-2025-53166

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53165

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53164

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53163

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53162

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53161

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53160

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53159

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53158

Rejected reason: Not used

Jun 27, 2025
CVE-2025-53157

Rejected reason: Not used

Jun 27, 2025
CVE-2025-6750
3.3 LOW

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. Affected by this issue is the function H5O__mtime_new_encode of the file src/H5Omtime.c. …

Jun 27, 2025
CVE-2025-47824
2.0 LOW

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.

Jun 27, 2025
CVE-2025-47823
2.2 LOW

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.

Jun 27, 2025
CVE-2025-47822
6.4 MEDIUM

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.

Jun 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.