CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40210

In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" I've found that …

Nov 21, 2025
CVE-2025-40209

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak of qgroup_list in btrfs_add_qgroup_relation When btrfs_add_qgroup_relation() is called with invalid qgroup …

Nov 21, 2025
CVE-2025-13138
7.5 HIGH

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, …

Nov 21, 2025
CVE-2025-12964
6.4 MEDIUM

The Magical Products Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpdpr_title_tag' and 'mpdpr_subtitle_tag' parameters in the MPD Pricing Table widget …

Nov 21, 2025
CVE-2025-12750
4.9 MEDIUM

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection via the 'term' parameter in all versions up to, …

Nov 21, 2025
CVE-2025-12160
7.2 HIGH

The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' parameter in all versions up to, and including, 6.6 …

Nov 21, 2025
CVE-2025-12066
4.4 MEDIUM

The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.0.2 …

Nov 21, 2025
CVE-2025-13156
8.8 HIGH

The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

Nov 21, 2025
CVE-2025-13149
4.3 MEDIUM

The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized modification of data due …

Nov 21, 2025
CVE-2025-13141
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions …

Nov 21, 2025
CVE-2025-12039
5.3 MEDIUM

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to …

Nov 21, 2025
CVE-2025-11973
4.9 MEDIUM

The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the __kds_flag functionality that imports …

Nov 21, 2025
CVE-2025-11826
6.4 MEDIUM

The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'social-networks' shortcode in all versions up …

Nov 21, 2025
CVE-2025-11808
6.4 MEDIUM

The Shortcode for Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'streetview' shortcode in all versions up to, and …

Nov 21, 2025
CVE-2025-11803
6.4 MEDIUM

The WPSite Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attribute in the wpsite_y shortcode and the 'before' attribute …

Nov 21, 2025
CVE-2025-13322
8.1 HIGH

The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and …

Nov 21, 2025
CVE-2025-13159
7.1 HIGH

The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all …

Nov 21, 2025
CVE-2025-13142
4.3 MEDIUM

The Custom Post Type plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to …

Nov 21, 2025
CVE-2025-13135
6.4 MEDIUM

The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotelrunner' shortcode in all versions up to, and including, …

Nov 21, 2025
CVE-2025-13134
6.1 MEDIUM

The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or …

Nov 21, 2025
CVE-2025-12894
5.3 MEDIUM

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Nov 21, 2025
CVE-2025-12881
5.4 MEDIUM

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 …

Nov 21, 2025
CVE-2025-12746
6.1 MEDIUM

The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 1.0.0 due to …

Nov 21, 2025
CVE-2025-12661
6.4 MEDIUM

The Pollcaster Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the 'pollcaster' shortcode in all versions up to, …

Nov 21, 2025
CVE-2025-12660
6.4 MEDIUM

The Padlet Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'key' parameter in the 'wallwisher' shortcode in all versions up to, …

Nov 21, 2025
CVE-2025-12170
5.3 MEDIUM

The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_ajax_nopriv_checkbox_clean_log' AJAX endpoint in all …

Nov 21, 2025
CVE-2025-12138
8.8 HIGH

The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and …

Nov 21, 2025
CVE-2025-12135
7.2 HIGH

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to …

Nov 21, 2025
CVE-2025-12086
4.3 MEDIUM

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 …

Nov 21, 2025
CVE-2025-11985
8.8 HIGH

The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check …

Nov 21, 2025
CVE-2025-11885
6.1 MEDIUM

The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parameter in all versions up to, and including, 1.3.0 …

Nov 21, 2025
CVE-2025-11815
4.3 MEDIUM

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 21, 2025
CVE-2025-11802
6.4 MEDIUM

The Bulma Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' shortcode attribute in the bulma-notification shortcode in all versions up …

Nov 21, 2025
CVE-2025-11801
6.4 MEDIUM

The AudioTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' shortcode attribute of the 'audiotube' shortcode in all versions up to, …

Nov 21, 2025
CVE-2025-11800
6.4 MEDIUM

The Surbma | MiniCRM Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the 'minicrm' shortcode in all …

Nov 21, 2025
CVE-2025-11799
6.4 MEDIUM

The Affiliate AI Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'asin' shortcode attribute in the affiai_img shortcode in all versions …

Nov 21, 2025
CVE-2025-11773
4.3 MEDIUM

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 21, 2025
CVE-2025-11771
5.3 MEDIUM

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to …

Nov 21, 2025
CVE-2025-11770
6.4 MEDIUM

The BrightTALK WordPress Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attribute in the brighttalk-time shortcode in all versions …

Nov 21, 2025
CVE-2025-11768
6.4 MEDIUM

The Islamic Phrases plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phrases' shortcode attribute in all versions up to, and including, 2.12.2015. …

Nov 21, 2025
CVE-2025-11767
6.4 MEDIUM

The Tips Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tip' shortcode in all versions up to, and including, 0.2.1. This …

Nov 21, 2025
CVE-2025-11765
6.4 MEDIUM

The Stock Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_height' and 'image_width' shortcode attributes in all versions up to, and …

Nov 21, 2025
CVE-2025-11764
6.4 MEDIUM

The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the [notification] shortcode in all versions up to, …

Nov 21, 2025
CVE-2025-11763
6.4 MEDIUM

The Display Pages Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column_count' parameter in the [display-pages] shortcode in all versions up …

Nov 21, 2025
CVE-2025-11456
9.8 CRITICAL

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Nov 21, 2025
CVE-2025-11003
6.4 MEDIUM

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 21, 2025
CVE-2025-10938
6.5 MEDIUM

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing …

Nov 21, 2025
CVE-2025-64695
7.8 HIGH

Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of …

Nov 21, 2025
CVE-2025-64299
2.7 LOW

LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes.

Nov 21, 2025
CVE-2025-62687
6.5 MEDIUM

Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed.

Nov 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.