CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-34260
5.4 MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule …

Dec 5, 2025
CVE-2025-34259
5.4 MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map …

Dec 5, 2025
CVE-2025-34258
5.4 MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area …

Dec 5, 2025
CVE-2025-34257
5.4 MEDIUM

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, …

Dec 5, 2025
CVE-2025-66552
4.3 MEDIUM

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders …

Dec 5, 2025
CVE-2025-66550
5.7 MEDIUM

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment …

Dec 5, 2025
CVE-2025-66547
4.3 MEDIUM

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files …

Dec 5, 2025
CVE-2025-66512
5.4 MEDIUM

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious …

Dec 5, 2025
CVE-2025-66511
4.8 MEDIUM

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing …

Dec 5, 2025
CVE-2025-66510
4.5 MEDIUM

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, …

Dec 5, 2025
CVE-2025-14104
6.1 MEDIUM

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set …

Dec 5, 2025
CVE-2025-14094
4.7 MEDIUM

A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the …

Dec 5, 2025
CVE-2025-14093
4.7 MEDIUM

A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument host results …

Dec 5, 2025
CVE-2025-64056
4.3 MEDIUM

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

Dec 5, 2025
CVE-2025-64052
5.1 MEDIUM

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.

Dec 5, 2025
CVE-2025-14092
4.7 MEDIUM

A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDiagnosticRun. The manipulation of the …

Dec 5, 2025
CVE-2025-14090
4.7 MEDIUM

A security flaw has been discovered in AMTT Hotel Broadband Operation System 1.0. This affects an unknown part of the file /manager/card/cardmake_down.php. Performing manipulation of …

Dec 5, 2025
CVE-2025-14089
6.3 MEDIUM

A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the file /api/admin/update_account/ of the component …

Dec 5, 2025
CVE-2025-14088
6.3 MEDIUM

A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of the file /je/load. This manipulation of …

Dec 5, 2025
CVE-2025-14086
6.3 MEDIUM

A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipulation of the argument openid results in …

Dec 5, 2025
CVE-2025-14085
6.3 MEDIUM

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads …

Dec 5, 2025
CVE-2025-6966
5.5 MEDIUM

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a …

Dec 5, 2025
CVE-2025-66200
5.4 MEDIUM

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts …

Dec 5, 2025
CVE-2025-65082
6.5 MEDIUM

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated …

Dec 5, 2025
CVE-2025-13620
5.3 MEDIUM

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is …

Dec 5, 2025
CVE-2025-13739
6.4 MEDIUM

The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all versions up to, and including, 4.0.5 due …

Dec 5, 2025
CVE-2025-13682
4.4 MEDIUM

The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to …

Dec 5, 2025
CVE-2025-13678
6.4 MEDIUM

The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcode in all versions up to, and including, 2.5. …

Dec 5, 2025
CVE-2025-12876
5.3 MEDIUM

The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pto_delete_file …

Dec 5, 2025
CVE-2025-13684
4.3 MEDIUM

The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to missing or incorrect nonce validation …

Dec 5, 2025
CVE-2025-12130
4.3 MEDIUM

The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Dec 5, 2025
CVE-2025-13515
6.1 MEDIUM

The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.0.1.3 due …

Dec 5, 2025
CVE-2025-12373
4.3 MEDIUM

The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Dec 5, 2025
CVE-2025-12355
5.3 MEDIUM

The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_update_order_status' AJAX endpoint in all …

Dec 5, 2025
CVE-2025-12354
4.3 MEDIUM

The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_frontend_save' AJAX endpoint …

Dec 5, 2025
CVE-2025-12186
4.4 MEDIUM

The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to …

Dec 5, 2025
CVE-2025-12093
5.3 MEDIUM

The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions …

Dec 5, 2025
CVE-2025-66270
4.7 MEDIUM

The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect …

Dec 5, 2025
CVE-2025-32900
4.3 MEDIUM

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP …

Dec 5, 2025
CVE-2025-13860
6.4 MEDIUM

The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter in all versions up to, and including, …

Dec 5, 2025
CVE-2025-13625
6.1 MEDIUM

The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.9.2 …

Dec 5, 2025
CVE-2025-13623
6.1 MEDIUM

The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in all versions up to, and including, 0.1.1 due to …

Dec 5, 2025
CVE-2025-13622
6.1 MEDIUM

The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in all versions up to, and including, 0.99-RC2 due to …

Dec 5, 2025
CVE-2025-13621
6.1 MEDIUM

The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Dec 5, 2025
CVE-2025-13528
5.3 MEDIUM

The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_export' function …

Dec 5, 2025
CVE-2025-13512
6.1 MEDIUM

The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.3.1 …

Dec 5, 2025
CVE-2025-13360
4.3 MEDIUM

The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due …

Dec 5, 2025
CVE-2025-13144
4.3 MEDIUM

The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or …

Dec 5, 2025
CVE-2025-12370
4.3 MEDIUM

The Takeads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.13. This is due to the plugin not …

Dec 5, 2025
CVE-2025-12368
6.4 MEDIUM

The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sermon-views` shortcode in all versions up to, and including, 2.30.0. This …

Dec 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.