CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-41106
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41105
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41104
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41103
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-10161
7.3 HIGH

Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on Untrusted Inputs in a Security Decision vulnerability in Turkguven Software Technologies Inc. …

Nov 11, 2025
CVE-2025-41102
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41101
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-11960
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Software High Technology Systems Inc. KVKNET allows Reflected XSS.This issue …

Nov 11, 2025
CVE-2025-7633
7.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.

Nov 11, 2025
CVE-2025-7632
7.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.

Nov 11, 2025
CVE-2025-7430
7.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.

Nov 11, 2025
CVE-2025-12953
4.3 MEDIUM

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 11, 2025
CVE-2025-12846
8.8 HIGH

The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to …

Nov 11, 2025
CVE-2025-12788
5.3 MEDIUM

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions …

Nov 11, 2025
CVE-2025-12787
5.3 MEDIUM

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, …

Nov 11, 2025
CVE-2025-12539
10.0 CRITICAL

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due …

Nov 11, 2025
CVE-2017-20210
9.8 CRITICAL

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.

Nov 11, 2025
CVE-2025-9524
4.3 MEDIUM

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited …

Nov 11, 2025
CVE-2025-9055
6.4 MEDIUM

The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can only be …

Nov 11, 2025
CVE-2025-8998
3.1 LOW

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw …

Nov 11, 2025
CVE-2025-7429
7.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.

Nov 11, 2025
CVE-2025-5317
5.5 MEDIUM

An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass …

Nov 11, 2025
CVE-2025-10714
8.4 HIGH

AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can …

Nov 11, 2025
CVE-2025-8108
6.7 MEDIUM

An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if …

Nov 11, 2025
CVE-2025-6779
6.7 MEDIUM

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if …

Nov 11, 2025
CVE-2025-6571
6.0 MEDIUM

A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.

Nov 11, 2025
CVE-2025-6298
6.7 MEDIUM

ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis …

Nov 11, 2025
CVE-2025-5718
6.8 MEDIUM

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to …

Nov 11, 2025
CVE-2025-5454
6.4 MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be …

Nov 11, 2025
CVE-2025-5452
6.6 MEDIUM

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious …

Nov 11, 2025
CVE-2025-4645
6.7 MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device …

Nov 11, 2025
CVE-2025-11855
7.5 HIGH

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin …

Nov 11, 2025
CVE-2025-11307
8.8 HIGH

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users …

Nov 11, 2025
CVE-2025-11237
5.3 MEDIUM

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, …

Nov 11, 2025
CVE-2025-12880
5.4 MEDIUM

The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 11, 2025
CVE-2025-12813
9.8 CRITICAL

The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' …

Nov 11, 2025
CVE-2025-12754
6.4 MEDIUM

The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost' shortcode in all versions up to, and …

Nov 11, 2025
CVE-2025-12753
6.4 MEDIUM

The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in all versions up to, and including, 1.0. This …

Nov 11, 2025
CVE-2025-12711
6.4 MEDIUM

The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google shortcode in all versions up to, and including, …

Nov 11, 2025
CVE-2025-12672
6.4 MEDIUM

The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the 'flickrshow' shortcode in all versions up to, …

Nov 11, 2025
CVE-2025-12671
6.4 MEDIUM

The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, …

Nov 11, 2025
CVE-2025-12668
6.4 MEDIUM

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12667
6.4 MEDIUM

The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'gist' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12665
4.3 MEDIUM

The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Nov 11, 2025
CVE-2025-12663
6.4 MEDIUM

The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the 'jeba_forkit' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12662
6.4 MEDIUM

The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the 'map' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12658
6.4 MEDIUM

The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' parameter in the 'preload_progress_bar' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12652
6.4 MEDIUM

The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter in the ungapped-form shortcode in all versions up to, …

Nov 11, 2025
CVE-2025-12651
6.4 MEDIUM

The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img_src', and 'class' parameters in the livephotos_photo shortcode …

Nov 11, 2025
CVE-2025-12644
6.4 MEDIUM

The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nonaki' shortcode in …

Nov 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.