CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12197
7.5 HIGH

The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient …

Nov 5, 2025
CVE-2025-11162
6.4 MEDIUM

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in …

Nov 5, 2025
CVE-2025-64455

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64454

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64453

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64452

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64451

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64450

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64449

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64448

Rejected reason: Not used

Nov 5, 2025
CVE-2025-12580
6.1 MEDIUM

The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in all versions up to, and including, 1.1.8 …

Nov 5, 2025
CVE-2025-11835
5.3 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Nov 5, 2025
CVE-2025-8871
5.6 MEDIUM

The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted …

Nov 5, 2025
CVE-2025-12582
4.3 MEDIUM

The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'features_revert_option AJAX endpoint in all …

Nov 5, 2025
CVE-2025-12735
9.8 CRITICAL

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, …

Nov 5, 2025
CVE-2025-64110
7.5 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive …

Nov 5, 2025
CVE-2025-64109
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta allowed an attacker to …

Nov 5, 2025
CVE-2025-64108
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to …

Nov 4, 2025
CVE-2025-64107
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path …

Nov 4, 2025
CVE-2025-64106
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables …

Nov 4, 2025
CVE-2025-62722
5.4 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) …

Nov 4, 2025
CVE-2025-59596
6.5 MEDIUM

CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy …

Nov 4, 2025
CVE-2025-59595
7.5 HIGH

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet …

Nov 4, 2025
CVE-2025-62721
6.5 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement …

Nov 4, 2025
CVE-2025-62720
6.5 MEDIUM

LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from …

Nov 4, 2025
CVE-2025-62719
4.3 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and …

Nov 4, 2025
CVE-2025-62715
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Scripting (XSS) vulnerability in ClipBucket’s Collection tags feature. …

Nov 4, 2025
CVE-2025-62520
4.3 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access …

Nov 4, 2025
CVE-2025-62507
8.8 HIGH

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple …

Nov 4, 2025
CVE-2025-62369
7.2 HIGH

Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability …

Nov 4, 2025
CVE-2025-56230
7.5 HIGH

Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.

Nov 4, 2025
CVE-2025-54526
7.8 HIGH

Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an attacker to execute …

Nov 4, 2025
CVE-2025-54496
7.8 HIGH

A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute arbitrary code.

Nov 4, 2025
CVE-2025-55155
5.4 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail …

Nov 4, 2025
CVE-2025-54335
6.5 MEDIUM

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU …

Nov 4, 2025
CVE-2025-52910
9.8 CRITICAL

An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 1480, 2400. A Use-After-Free leads to …

Nov 4, 2025
CVE-2025-48884
6.1 MEDIUM

Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette's Document Type is vulnerable to Cross-site Scripting. This …

Nov 4, 2025
CVE-2025-48076
5.4 MEDIUM

Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert …

Nov 4, 2025
CVE-2025-47776
9.1 CRITICAL

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===) comparison in the authentication …

Nov 4, 2025
CVE-2025-32786
7.5 HIGH

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Versions 1.5.0 and below are vulnerable to SQL Injection. …

Nov 4, 2025
CVE-2025-27374
5.3 MEDIUM

An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, …

Nov 4, 2025
CVE-2024-56426
7.5 HIGH

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, …

Nov 4, 2025
CVE-2025-61431
6.1 MEDIUM

A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary …

Nov 4, 2025
CVE-2025-54327
6.5 MEDIUM

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validation in the …

Nov 4, 2025
CVE-2025-49494
7.5 HIGH

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 5123. Mishandling of an …

Nov 4, 2025
CVE-2025-33176
6.2 MEDIUM

NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adjacent network. A successful …

Nov 4, 2025
CVE-2025-23358
8.2 HIGH

NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue. A successful exploit of …

Nov 4, 2025
CVE-2025-64322
5.3 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.

Nov 4, 2025
CVE-2025-64321
5.3 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before …

Nov 4, 2025
CVE-2025-64320
6.5 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.

Nov 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.