CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-65431
5.4 MEDIUM

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may …

Dec 15, 2025
CVE-2025-65430
5.4 MEDIUM

An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was …

Dec 15, 2025
CVE-2025-66388
6.5 MEDIUM

A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing …

Dec 15, 2025
CVE-2025-37732
5.4 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the …

Dec 15, 2025
CVE-2025-37731
6.8 MEDIUM

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a …

Dec 15, 2025
CVE-2025-14714
6.5 MEDIUM

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user …

Dec 15, 2025
CVE-2025-11670
6.4 MEDIUM

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as …

Dec 15, 2025
CVE-2025-14021
4.3 MEDIUM

The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious …

Dec 15, 2025
CVE-2025-14020
5.4 MEDIUM

LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not …

Dec 15, 2025
CVE-2025-11363
5.3 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.

Dec 15, 2025
CVE-2025-67906
5.4 MEDIUM

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

Dec 15, 2025
CVE-2025-14703
5.3 MEDIUM

A vulnerability has been found in Shiguangwu sgwbox N3 2.0.25. The affected element is an unknown function of the file /fsnotify of the component POST …

Dec 15, 2025
CVE-2025-14702
4.4 MEDIUM

A flaw has been found in Smartbit CommV Smartschool App up to 10.4.4. Impacted is an unknown function of the component be.smartschool.mobile.SplashActivity. Executing manipulation can …

Dec 15, 2025
CVE-2025-13740
6.4 MEDIUM

The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweight-accordion` shortcode in all versions up to, and including, 1.5.20 …

Dec 15, 2025
CVE-2025-14699
5.3 MEDIUM

A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp.app. Such manipulation leads …

Dec 15, 2025
CVE-2025-14698
4.4 MEDIUM

A weakness has been identified in atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. This affects an unknown part of the component gallery.photogallery.pictures.vault.album. This …

Dec 15, 2025
CVE-2025-14696
5.3 MEDIUM

A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the …

Dec 15, 2025
CVE-2025-14695
6.3 MEDIUM

A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing …

Dec 15, 2025
CVE-2025-14694
4.7 MEDIUM

A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/postil/readAllPostil. Performing a manipulation of the argument …

Dec 15, 2025
CVE-2025-14693
6.2 MEDIUM

A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads to …

Dec 15, 2025
CVE-2025-67901
5.3 MEDIUM

openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEGV by specifying a length …

Dec 15, 2025
CVE-2025-14692
4.3 MEDIUM

A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes …

Dec 15, 2025
CVE-2025-14691
4.3 MEDIUM

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in …

Dec 14, 2025
CVE-2025-67898
4.5 MEDIUM

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an …

Dec 14, 2025
CVE-2025-13281
5.8 MEDIUM

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary …

Dec 14, 2025
CVE-2025-14674
6.3 MEDIUM

A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java. The manipulation results …

Dec 14, 2025
CVE-2025-14660
5.6 MEDIUM

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the …

Dec 14, 2025
CVE-2025-14648
4.7 MEDIUM

A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/catalog_add.php. Such manipulation …

Dec 14, 2025
CVE-2025-12696
5.3 MEDIUM

The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset …

Dec 14, 2025
CVE-2025-12537
6.4 MEDIUM

The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.14.3. This is due …

Dec 14, 2025
CVE-2025-67897
5.3 MEDIUM

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash …

Dec 14, 2025
CVE-2025-14642
4.7 MEDIUM

A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument …

Dec 14, 2025
CVE-2025-14641
4.7 MEDIUM

A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the …

Dec 14, 2025
CVE-2025-9873
6.4 MEDIUM

The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.5 due to insufficient input …

Dec 13, 2025
CVE-2025-9856
6.4 MEDIUM

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode …

Dec 13, 2025
CVE-2025-9488
6.4 MEDIUM

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due …

Dec 13, 2025
CVE-2025-9207
5.3 MEDIUM

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the …

Dec 13, 2025
CVE-2025-9116
5.8 MEDIUM

The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Dec 13, 2025
CVE-2025-8780
6.4 MEDIUM

The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero Header and Pricing Table widgets in all versions …

Dec 13, 2025
CVE-2025-8779
6.4 MEDIUM

The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Team and Countdown widgets in all …

Dec 13, 2025
CVE-2025-8687
6.4 MEDIUM

The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image Comparison widgets in all versions up to, …

Dec 13, 2025
CVE-2025-8617
6.4 MEDIUM

The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_quick_view shortcode in all versions up to, and …

Dec 13, 2025
CVE-2025-8199
6.4 MEDIUM

The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee widget in all versions up to, and including, 2.4.3 …

Dec 13, 2025
CVE-2025-8195
6.4 MEDIUM

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison and Subscribe widgets in all versions up …

Dec 13, 2025
CVE-2025-7960
6.4 MEDIUM

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets …

Dec 13, 2025
CVE-2025-7058
6.4 MEDIUM

The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.1.9 due to …

Dec 13, 2025
CVE-2025-36750
5.4 MEDIUM

ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page …

Dec 13, 2025
CVE-2025-36748
5.4 MEDIUM

ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication …

Dec 13, 2025
CVE-2025-14617
5.3 MEDIUM

A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown function of the component org.jw.jwlibrary.mobile.activity.SiloContainer. …

Dec 13, 2025
CVE-2025-14607
6.3 MEDIUM

A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicomByteString of the file dcmdata/libsrc/dcbytstr.cc of the component …

Dec 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.