CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5238
6.4 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.5.0 …

Jun 14, 2025
CVE-2025-4667
6.4 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and …

Jun 14, 2025
CVE-2025-6070
6.5 MEDIUM

The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This …

Jun 14, 2025
CVE-2025-6065
9.1 CRITICAL

The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task …

Jun 14, 2025
CVE-2025-6064
6.1 MEDIUM

The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to …

Jun 14, 2025
CVE-2025-6063
6.1 MEDIUM

The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing …

Jun 14, 2025
CVE-2025-6062
4.3 MEDIUM

The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due …

Jun 14, 2025
CVE-2025-6061
6.4 MEDIUM

The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcode in all versions up to, and including, …

Jun 14, 2025
CVE-2025-6055
6.1 MEDIUM

The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to …

Jun 14, 2025
CVE-2025-6040
6.1 MEDIUM

The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing …

Jun 14, 2025
CVE-2025-5589
6.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 …

Jun 14, 2025
CVE-2025-5336
6.4 MEDIUM

The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 …

Jun 14, 2025
CVE-2025-4592
4.3 MEDIUM

The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 14, 2025
CVE-2025-4216
6.4 MEDIUM

The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and …

Jun 14, 2025
CVE-2025-4200
8.1 HIGH

The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Jun 14, 2025
CVE-2025-4187
5.9 MEDIUM

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 …

Jun 14, 2025
CVE-2025-5487
7.2 HIGH

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the …

Jun 14, 2025
CVE-2025-3234
7.2 HIGH

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up …

Jun 14, 2025
CVE-2025-6059
4.3 MEDIUM

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing …

Jun 14, 2025
CVE-2025-50150

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50149

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50148

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50147

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50146

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50145

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50144

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50143

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50142

Rejected reason: Not used

Jun 14, 2025
CVE-2025-33108
8.5 HIGH

IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to …

Jun 14, 2025
CVE-2025-25215
8.8 HIGH

An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted …

Jun 13, 2025
CVE-2025-24919
8.1 HIGH

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially …

Jun 13, 2025
CVE-2025-6083
4.3 MEDIUM

In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search …

Jun 13, 2025
CVE-2025-49598

conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feedstock setup script is vulnerable due to the unsafe …

Jun 13, 2025
CVE-2025-25050
8.8 HIGH

An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially …

Jun 13, 2025
CVE-2025-24922
8.8 HIGH

A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially …

Jun 13, 2025
CVE-2025-24311
8.4 HIGH

An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted …

Jun 13, 2025
CVE-2025-49597
3.9 LOW

handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export library. Prior to 1.4.3, goodby-csv could be used as part of a …

Jun 13, 2025
CVE-2025-49596

The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution …

Jun 13, 2025
CVE-2025-49587
8.0 HIGH

XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits …

Jun 13, 2025
CVE-2025-49586
8.8 HIGH

XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all …

Jun 13, 2025
CVE-2025-49585
8.0 HIGH

XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right …

Jun 13, 2025
CVE-2025-49584
7.5 HIGH

XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.0-rc-1, the title of every single page whose …

Jun 13, 2025
CVE-2025-49583
3.5 LOW

XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and …

Jun 13, 2025
CVE-2025-49582
8.0 HIGH

XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer …

Jun 13, 2025
CVE-2025-6052
3.7 LOW

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with …

Jun 13, 2025
CVE-2025-6035
6.1 MEDIUM

A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image …

Jun 13, 2025
CVE-2025-49581
8.8 HIGH

XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) …

Jun 13, 2025
CVE-2025-49580
8.0 HIGH

XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain …

Jun 13, 2025
CVE-2025-48920
7.3 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.

Jun 13, 2025
CVE-2025-48919
5.0 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 …

Jun 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.