CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-63892
6.8 MEDIUM

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms …

Nov 18, 2025
CVE-2025-63883
5.4 MEDIUM

A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client-side JavaScript reads attacker-controlled input (for example, values derived from the URL or …

Nov 18, 2025
CVE-2025-59117
4.8 MEDIUM

Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu/admin/content/pages/edit/. This vulnerability can be exploited by a privileged …

Nov 18, 2025
CVE-2025-59116
5.3 MEDIUM

Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow an attacker to determine if the …

Nov 18, 2025
CVE-2025-59115
5.4 MEDIUM

Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation. Malicious attacker can inject arbitrary …

Nov 18, 2025
CVE-2025-59114
6.5 MEDIUM

Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft special website, which when visited by the victim, will …

Nov 18, 2025
CVE-2025-59113
7.5 HIGH

Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows …

Nov 18, 2025
CVE-2025-59112
6.5 MEDIUM

Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft special website, which when visited by the victim, will …

Nov 18, 2025
CVE-2025-59111
6.5 MEDIUM

Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET request which allows privileged users to delete …

Nov 18, 2025
CVE-2025-59110
6.5 MEDIUM

Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechanism can be bypassed by using CSRF token of other …

Nov 18, 2025
CVE-2025-55179
5.4 MEDIUM

Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have …

Nov 18, 2025
CVE-2025-13349
3.5 LOW

A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown processing of the file /grades.php of the component …

Nov 18, 2025
CVE-2025-13347
6.3 MEDIUM

A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the …

Nov 18, 2025
CVE-2025-13346
6.3 MEDIUM

A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the file /ajax.php?action=save_station. Performing manipulation of the argument …

Nov 18, 2025
CVE-2025-12545
5.3 MEDIUM

The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Information Exposure in all …

Nov 18, 2025
CVE-2025-12376
6.4 MEDIUM

The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, …

Nov 18, 2025
CVE-2025-10158
4.3 MEDIUM

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via …

Nov 18, 2025
CVE-2025-6670
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin …

Nov 18, 2025
CVE-2025-41350
5.4 MEDIUM

Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack …

Nov 18, 2025
CVE-2025-41349
5.4 MEDIUM

Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack …

Nov 18, 2025
CVE-2025-41348
9.8 CRITICAL

SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete databases by sendng a POST …

Nov 18, 2025
CVE-2025-13345
6.3 MEDIUM

A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_ticket. …

Nov 18, 2025
CVE-2025-13344
7.3 HIGH

A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=login. This …

Nov 18, 2025
CVE-2025-13343
3.5 LOW

A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function of the file /editQuestion.php. The manipulation of the …

Nov 18, 2025
CVE-2025-41737
7.5 HIGH

Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.

Nov 18, 2025
CVE-2025-41736
8.8 HIGH

A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in …

Nov 18, 2025
CVE-2025-41735
8.8 HIGH

A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.

Nov 18, 2025
CVE-2025-41734
9.8 CRITICAL

An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.

Nov 18, 2025
CVE-2025-41733
9.8 CRITICAL

The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to …

Nov 18, 2025
CVE-2025-41347
9.8 CRITICAL

Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending …

Nov 18, 2025
CVE-2025-11427
5.8 MEDIUM

The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and …

Nov 18, 2025
CVE-2025-4212
7.2 HIGH

The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, …

Nov 18, 2025
CVE-2025-41346
9.8 CRITICAL

Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning …

Nov 18, 2025
CVE-2025-13196
5.4 MEDIUM

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in …

Nov 18, 2025
CVE-2025-13133
6.6 MEDIUM

The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' …

Nov 18, 2025
CVE-2025-13069
8.8 HIGH

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This …

Nov 18, 2025
CVE-2025-12955
7.5 HIGH

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due …

Nov 18, 2025
CVE-2025-12691
6.4 MEDIUM

The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox functionality in …

Nov 18, 2025
CVE-2025-12639
4.3 MEDIUM

The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, …

Nov 18, 2025
CVE-2025-12481
4.3 MEDIUM

The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the …

Nov 18, 2025
CVE-2025-12457
6.4 MEDIUM

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, …

Nov 18, 2025
CVE-2025-12392
5.3 MEDIUM

The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_optin_optout' …

Nov 18, 2025
CVE-2025-12391
5.3 MEDIUM

The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout() function in …

Nov 18, 2025
CVE-2025-12088
6.4 MEDIUM

The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in all versions up to, and including, …

Nov 18, 2025
CVE-2025-12079
6.1 MEDIUM

The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.7.4 due …

Nov 18, 2025
CVE-2025-11734
5.4 MEDIUM

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modification due to missing …

Nov 18, 2025
CVE-2025-9625
4.3 MEDIUM

The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to …

Nov 18, 2025
CVE-2025-8609
6.4 MEDIUM

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion Block's attributes in all versions up to, …

Nov 18, 2025
CVE-2025-8605
6.4 MEDIUM

The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in …

Nov 18, 2025
CVE-2025-40549
9.1 CRITICAL

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute …

Nov 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.