CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12689
6.5 MEDIUM

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to …

Dec 17, 2025
CVE-2025-66924
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or …

Dec 17, 2025
CVE-2025-65855
6.6 MEDIUM

The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update …

Dec 17, 2025
CVE-2024-29370
5.3 MEDIUM

In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token …

Dec 17, 2025
CVE-2025-62190
4.3 MEDIUM

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget …

Dec 17, 2025
CVE-2025-14095
6.8 MEDIUM

A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user with physical access to the analyzer, the …

Dec 17, 2025
CVE-2025-14347
6.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. OBS (Student Affairs Information System)0 allows Reflected XSS.This …

Dec 17, 2025
CVE-2025-14399
4.3 MEDIUM

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 17, 2025
CVE-2025-12496
4.9 MEDIUM

The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This …

Dec 17, 2025
CVE-2025-14817
6.5 MEDIUM

The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission control and can be accessed by third-party apps which can construct intents to directly open adb debugging …

Dec 17, 2025
CVE-2025-14061
5.3 MEDIUM

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable …

Dec 17, 2025
CVE-2025-13750
4.3 MEDIUM

The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Dec 17, 2025
CVE-2025-14154
6.1 MEDIUM

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via guest display …

Dec 17, 2025
CVE-2025-64700
4.3 MEDIUM

Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logged in, the user may be tricked …

Dec 17, 2025
CVE-2025-14385
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 10.2.3 …

Dec 17, 2025
CVE-2025-13880
6.5 MEDIUM

The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) plugin for WordPress is vulnerable …

Dec 17, 2025
CVE-2025-13861
6.1 MEDIUM

The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.0 …

Dec 17, 2025
CVE-2025-14304
6.8 MEDIUM

Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated …

Dec 17, 2025
CVE-2025-13977
6.4 MEDIUM

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in …

Dec 17, 2025
CVE-2025-14303
6.8 MEDIUM

Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable …

Dec 17, 2025
CVE-2025-14302
6.8 MEDIUM

Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable …

Dec 17, 2025
CVE-2025-11369
4.3 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a …

Dec 17, 2025
CVE-2025-11009
5.1 MEDIUM

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows …

Dec 17, 2025
CVE-2025-34288
6.7 MEDIUM

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A …

Dec 16, 2025
CVE-2025-64520
6.5 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API …

Dec 16, 2025
CVE-2025-14466
5.3 MEDIUM

A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with network access to send …

Dec 16, 2025
CVE-2025-8872
6.5 MEDIUM

On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may …

Dec 16, 2025
CVE-2025-13532
6.2 MEDIUM

Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This …

Dec 16, 2025
CVE-2025-68150
6.5 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the …

Dec 16, 2025
CVE-2025-68146
6.3 MEDIUM

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate …

Dec 16, 2025
CVE-2025-65592
6.1 MEDIUM

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields …

Dec 16, 2025
CVE-2025-65591
5.4 MEDIUM

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.

Dec 16, 2025
CVE-2025-65590
5.4 MEDIUM

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area.

Dec 16, 2025
CVE-2025-68142
5.3 MEDIUM

PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption …

Dec 16, 2025
CVE-2025-65589
6.1 MEDIUM

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.

Dec 16, 2025
CVE-2025-65581
5.3 MEDIUM

An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in …

Dec 16, 2025
CVE-2025-46296
5.4 MEDIUM

An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and …

Dec 16, 2025
CVE-2025-46294
5.3 MEDIUM

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. …

Dec 16, 2025
CVE-2025-62862
4.6 MEDIUM

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM …

Dec 16, 2025
CVE-2025-59935
6.5 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an …

Dec 16, 2025
CVE-2025-29231
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a …

Dec 16, 2025
CVE-2023-53903
5.4 MEDIUM

WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG …

Dec 16, 2025
CVE-2023-53902
6.5 MEDIUM

WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET …

Dec 16, 2025
CVE-2023-53901
5.4 MEDIUM

WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a …

Dec 16, 2025
CVE-2023-53898
5.4 MEDIUM

Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application …

Dec 16, 2025
CVE-2023-53897
5.4 MEDIUM

Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments …

Dec 16, 2025
CVE-2025-68269
5.4 MEDIUM

In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH

Dec 16, 2025
CVE-2025-68268
5.4 MEDIUM

In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page

Dec 16, 2025
CVE-2025-68267
6.5 MEDIUM

In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

Dec 16, 2025
CVE-2025-68166
5.4 MEDIUM

In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab

Dec 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.