CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13966
6.4 MEDIUM

The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' parameter of the [paypal-shortcode] shortcode in all versions up …

Dec 12, 2025
CVE-2025-13963
6.4 MEDIUM

The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_convert' shortcode in all versions up to, and including, …

Dec 12, 2025
CVE-2025-13962
6.4 MEDIUM

The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shortcode in all versions up to, and including, 1.5 …

Dec 12, 2025
CVE-2025-13961
6.4 MEDIUM

The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' shortcode in all versions up to, and including, 1.1 …

Dec 12, 2025
CVE-2025-13960
6.4 MEDIUM

The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in all versions up to, and including, 1.3 due …

Dec 12, 2025
CVE-2025-13906
6.4 MEDIUM

The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in all versions up to, and including, 0.2.2 …

Dec 12, 2025
CVE-2025-13904
6.4 MEDIUM

The WPGancio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gancio-event' shortcode in all versions up to, and including, 1.12 due …

Dec 12, 2025
CVE-2025-13889
6.4 MEDIUM

The Simple Nivo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode parameter in all versions up to, and including, …

Dec 12, 2025
CVE-2025-13885
6.4 MEDIUM

The Zenost Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' and 'target' parameters in the `button` shortcode in all versions …

Dec 12, 2025
CVE-2025-13884
6.4 MEDIUM

The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter in the `bg-hide-email-address` shortcode in all versions up …

Dec 12, 2025
CVE-2025-13866
6.4 MEDIUM

The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flow_flow_social_auth AJAX …

Dec 12, 2025
CVE-2025-13850
6.4 MEDIUM

The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'map_type' parameter in all versions up to, and including, …

Dec 12, 2025
CVE-2025-13846
6.4 MEDIUM

The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 3.0.2 …

Dec 12, 2025
CVE-2025-13843
6.4 MEDIUM

The VigLink SpotLight By ShortCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'float' parameter of the 'spotlight' shortcode in all versions …

Dec 12, 2025
CVE-2025-13840
6.4 MEDIUM

The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter of the 'bukazu_search' shortcode in all versions up …

Dec 12, 2025
CVE-2025-13747
6.4 MEDIUM

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, …

Dec 12, 2025
CVE-2025-13440
5.3 MEDIUM

The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to …

Dec 12, 2025
CVE-2025-13408
4.3 MEDIUM

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Dec 12, 2025
CVE-2025-13366
4.3 MEDIUM

The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing …

Dec 12, 2025
CVE-2025-13363
4.3 MEDIUM

The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing …

Dec 12, 2025
CVE-2025-13320
6.8 MEDIUM

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to …

Dec 12, 2025
CVE-2025-13314
5.3 MEDIUM

The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable to unauthorized modification of data in all …

Dec 12, 2025
CVE-2025-12883
5.3 MEDIUM

The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2.2. This is due …

Dec 12, 2025
CVE-2025-12834
6.1 MEDIUM

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failure_message' parameter in versions up to, …

Dec 12, 2025
CVE-2025-12830
6.4 MEDIUM

The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in all versions up to, and including, 1.5.5 …

Dec 12, 2025
CVE-2025-12783
4.3 MEDIUM

The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveBrandsSettings function …

Dec 12, 2025
CVE-2025-12650
6.4 MEDIUM

The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter in the postlist shortcode in all versions up …

Dec 12, 2025
CVE-2025-13839
6.4 MEDIUM

The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' shortcode in all versions up to, and …

Dec 12, 2025
CVE-2025-13670
6.7 MEDIUM

The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability

Dec 12, 2025
CVE-2025-13669
6.7 MEDIUM

Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 …

Dec 12, 2025
CVE-2025-13665
6.7 MEDIUM

The System Console Utility for Windows is vulnerable to a DLL planting vulnerability

Dec 12, 2025
CVE-2025-13052
5.9 MEDIUM

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who …

Dec 12, 2025
CVE-2025-67780
4.2 MEDIUM

SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2. The cross-origin policy can …

Dec 11, 2025
CVE-2025-66452
6.1 MEDIUM

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing errors; SyntaxError from express.json() includes …

Dec 11, 2025
CVE-2025-66451
6.5 MEDIUM

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modify the …

Dec 11, 2025
CVE-2025-66450
5.4 MEDIUM

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the iconURL parameter of the POST …

Dec 11, 2025
CVE-2025-34504
6.1 MEDIUM

KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs …

Dec 11, 2025
CVE-2025-13668
6.7 MEDIUM

A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.

Dec 11, 2025
CVE-2024-58297
5.4 MEDIUM

PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows attackers to inject malicious scripts. Attackers can insert a payload …

Dec 11, 2025
CVE-2024-58289
5.4 MEDIUM

Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads …

Dec 11, 2025
CVE-2025-64702
5.3 MEDIUM

quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HTTP/3 client and …

Dec 11, 2025
CVE-2025-55816
6.1 MEDIUM

HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.

Dec 11, 2025
CVE-2025-14293
6.5 MEDIUM

The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. …

Dec 11, 2025
CVE-2025-13664
6.7 MEDIUM

A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege.

Dec 11, 2025
CVE-2025-13663
6.7 MEDIUM

Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation …

Dec 11, 2025
CVE-2025-55183
5.3 MEDIUM

An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: …

Dec 11, 2025
CVE-2025-36938
6.8 MEDIUM

In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of …

Dec 11, 2025
CVE-2025-36929
5.5 MEDIUM

In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to local information disclosure with no additional …

Dec 11, 2025
CVE-2025-36922
6.7 MEDIUM

In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege in …

Dec 11, 2025
CVE-2025-36921
5.5 MEDIUM

In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Dec 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.