CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13317
5.3 MEDIUM

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the …

Nov 22, 2025
CVE-2025-12877
5.3 MEDIUM

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability …

Nov 22, 2025
CVE-2025-12752
5.3 MEDIUM

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is …

Nov 22, 2025
CVE-2025-11186
6.4 MEDIUM

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookies_accepted shortcode in all …

Nov 22, 2025
CVE-2025-12889
5.4 MEDIUM

With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.

Nov 22, 2025
CVE-2025-65947

thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resource leaks when querying thread …

Nov 21, 2025
CVE-2025-65946
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was …

Nov 21, 2025
CVE-2025-12888
7.5 HIGH

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. …

Nov 21, 2025
CVE-2025-12678

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 21, 2025
CVE-2025-11936
5.3 MEDIUM

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by …

Nov 21, 2025
CVE-2025-11934
2.7 LOW

Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm …

Nov 21, 2025
CVE-2025-11933
6.5 MEDIUM

Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially …

Nov 21, 2025
CVE-2025-11932
4.3 MEDIUM

The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder

Nov 21, 2025
CVE-2025-11931
8.2 HIGH

Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used …

Nov 21, 2025
CVE-2025-65111
5.3 MEDIUM

SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: …

Nov 21, 2025
CVE-2025-65109

Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users …

Nov 21, 2025
CVE-2025-65108
10.0 CRITICAL

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that …

Nov 21, 2025
CVE-2025-65107
6.5 MEDIUM

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO …

Nov 21, 2025
CVE-2025-65106

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in …

Nov 21, 2025
CVE-2025-65102

PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the …

Nov 21, 2025
CVE-2025-65092

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the ESP32-P4 uses its hardware JPEG decoder, the …

Nov 21, 2025
CVE-2025-43374
4.3 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS …

Nov 21, 2025
CVE-2025-31266
4.3 MEDIUM

A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. …

Nov 21, 2025
CVE-2025-31248
5.5 MEDIUM

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma …

Nov 21, 2025
CVE-2025-31216
2.4 LOW

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to …

Nov 21, 2025
CVE-2025-11935
7.5 HIGH

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue …

Nov 21, 2025
CVE-2025-0504
5.4 MEDIUM

Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role …

Nov 21, 2025
CVE-2025-11087
8.8 HIGH

The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.0.1. This is …

Nov 21, 2025
CVE-2025-36149
6.3 MEDIUM

IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.

Nov 21, 2025
CVE-2025-13524
5.7 MEDIUM

Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to …

Nov 21, 2025
CVE-2025-64767
9.1 CRITICAL

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API …

Nov 21, 2025
CVE-2025-64169
4.9 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to before 4.12.0, fim_alert() implementation does not …

Nov 21, 2025
CVE-2025-62626

Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting …

Nov 21, 2025
CVE-2025-62609
7.5 HIGH

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious …

Nov 21, 2025
CVE-2025-62608
9.1 CRITICAL

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing …

Nov 21, 2025
CVE-2025-54866
5.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on …

Nov 21, 2025
CVE-2025-48502
5.5 MEDIUM

Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.

Nov 21, 2025
CVE-2025-30201
7.7 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows …

Nov 21, 2025
CVE-2025-29934
5.3 MEDIUM

A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss …

Nov 21, 2025
CVE-2025-64483

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain …

Nov 21, 2025
CVE-2025-13132
7.4 HIGH

This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) appearing. Without this notification, users could potentially be …

Nov 21, 2025
CVE-2025-13470
7.5 HIGH

In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session Key (PKESK) packets to be left uninitialized except …

Nov 21, 2025
CVE-2025-12973
7.2 HIGH

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file …

Nov 21, 2025
CVE-2025-12747
5.3 MEDIUM

The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being …

Nov 21, 2025
CVE-2025-41115
10.0 CRITICAL

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated …

Nov 21, 2025
CVE-2025-13432
4.3 MEDIUM

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration …

Nov 21, 2025
CVE-2025-13357
7.4 HIGH

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If …

Nov 21, 2025
CVE-2025-11127
9.8 CRITICAL

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, …

Nov 21, 2025
CVE-2025-66115
6.6 MEDIUM

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This …

Nov 21, 2025
CVE-2025-66114
5.3 MEDIUM

Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variations-shop-category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Show Variations …

Nov 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.