CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10703

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data …

Nov 19, 2025
CVE-2025-10702

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data …

Nov 19, 2025
CVE-2025-63243
4.6 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.1 (01). The sle_sSenha parameter to the loginAlterarSenha.asp file. An …

Nov 19, 2025
CVE-2025-63219
7.5 HIGH

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. …

Nov 19, 2025
CVE-2025-63218
9.8 CRITICAL

The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi …

Nov 19, 2025
CVE-2025-11963
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities allows Reflected XSS.This issue …

Nov 19, 2025
CVE-2025-0421
4.7 MEDIUM

Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allows iFrame Overlay.This issue affects Shopside: through 05022025.

Nov 19, 2025
CVE-2024-8528

Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload due to a specific GET parameter …

Nov 19, 2025
CVE-2024-8527

Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user …

Nov 19, 2025
CVE-2025-12592

Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.

Nov 19, 2025
CVE-2025-10437
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System …

Nov 19, 2025
CVE-2025-64408
6.3 MEDIUM

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality …

Nov 19, 2025
CVE-2025-13395
7.3 HIGH

A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted element is the function Login of the file /function.php. The manipulation …

Nov 19, 2025
CVE-2025-12472

An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git directory deletion, leading to arbitrary command …

Nov 19, 2025
CVE-2025-58412
4.7 MEDIUM

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0, FortiADC 7.6.0 through 7.6.3, FortiADC 7.4 all …

Nov 19, 2025
CVE-2025-11230
7.5 HIGH

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

Nov 19, 2025
CVE-2025-0351

Rejected reason: Voluntarily withdrawn

Nov 19, 2025
CVE-2025-11446
6.5 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 …

Nov 19, 2025
CVE-2025-13206
7.2 HIGH

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up …

Nov 19, 2025
CVE-2025-13035
8.0 HIGH

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the …

Nov 19, 2025
CVE-2025-12484
7.2 HIGH

The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Nov 19, 2025
CVE-2025-13085
4.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta Disclosure in versions up to and including …

Nov 19, 2025
CVE-2025-12535
5.3 MEDIUM

The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the …

Nov 19, 2025
CVE-2025-12056

Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.

Nov 19, 2025
CVE-2025-11243

Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allocation via network.

Nov 19, 2025
CVE-2025-13145
7.2 HIGH

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …

Nov 19, 2025
CVE-2025-13054
6.4 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 19, 2025
CVE-2025-12878
6.4 MEDIUM

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up …

Nov 19, 2025
CVE-2025-12842
5.3 MEDIUM

The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 …

Nov 19, 2025
CVE-2025-12822
4.3 MEDIUM

The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Nov 19, 2025
CVE-2025-12814
5.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect capability check on the siteseo_reset_settings function …

Nov 19, 2025
CVE-2025-12751
4.3 MEDIUM

The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'reset_settings' …

Nov 19, 2025
CVE-2025-12710
6.4 MEDIUM

The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shortcode in all versions up to, and including, 3.6.1 …

Nov 19, 2025
CVE-2025-12646
7.5 HIGH

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to …

Nov 19, 2025
CVE-2025-12359
5.4 MEDIUM

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' …

Nov 19, 2025
CVE-2025-12174
6.5 MEDIUM

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Nov 19, 2025
CVE-2025-12057
9.8 CRITICAL

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied …

Nov 19, 2025
CVE-2025-12426
5.3 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the …

Nov 19, 2025
CVE-2025-12349
5.3 MEDIUM

The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This …

Nov 19, 2025
CVE-2025-6251
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 …

Nov 19, 2025
CVE-2025-65941

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65940

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65939

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65938

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65937

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65936

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65935

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65934

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65933

Rejected reason: Not used

Nov 19, 2025
CVE-2025-13051

When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with …

Nov 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.