CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12191
5.4 MEDIUM

The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' AJAX action in all versions up to, and …

Dec 5, 2025
CVE-2025-12190
4.3 MEDIUM

The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due …

Dec 5, 2025
CVE-2025-12189
4.3 MEDIUM

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site …

Dec 5, 2025
CVE-2025-12165
4.3 MEDIUM

The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webcake_save_config' …

Dec 5, 2025
CVE-2025-12163
6.4 MEDIUM

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to …

Dec 5, 2025
CVE-2025-12133
4.3 MEDIUM

The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_eprolo_delete_tracking and wp_ajax_eprolo_save_tracking_data AJAX …

Dec 5, 2025
CVE-2025-12128
4.3 MEDIUM

The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7. …

Dec 5, 2025
CVE-2025-12124
4.4 MEDIUM

The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.1 due …

Dec 5, 2025
CVE-2025-10055
4.3 MEDIUM

The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing …

Dec 5, 2025
CVE-2016-20023
5.0 MEDIUM

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

Dec 5, 2025
CVE-2025-32901
4.3 MEDIUM

In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.

Dec 5, 2025
CVE-2025-32899
4.3 MEDIUM

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery …

Dec 5, 2025
CVE-2025-32898
4.7 MEDIUM

The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE …

Dec 5, 2025
CVE-2025-13494
5.3 MEDIUM

The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the …

Dec 5, 2025
CVE-2025-13362
4.3 MEDIUM

The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing …

Dec 5, 2025
CVE-2025-13312
5.3 MEDIUM

The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all …

Dec 5, 2025
CVE-2025-13006
5.3 MEDIUM

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via …

Dec 5, 2025
CVE-2025-12417
6.4 MEDIUM

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, …

Dec 5, 2025
CVE-2025-12804
6.4 MEDIUM

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 …

Dec 5, 2025
CVE-2025-11759
4.3 MEDIUM

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 5, 2025
CVE-2025-62223
4.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Dec 5, 2025
CVE-2025-14052
6.3 MEDIUM

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the …

Dec 5, 2025
CVE-2025-66563
6.1 MEDIUM

Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute …

Dec 4, 2025
CVE-2025-14051
6.3 MEDIUM

A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control …

Dec 4, 2025
CVE-2025-6946
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the IPS module. This …

Dec 4, 2025
CVE-2025-65900
6.5 MEDIUM

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in …

Dec 4, 2025
CVE-2025-65899
5.3 MEDIUM

Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid …

Dec 4, 2025
CVE-2025-13940
5.5 MEDIUM

An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and …

Dec 4, 2025
CVE-2025-13939
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.This issue …

Dec 4, 2025
CVE-2025-13938
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.This issue …

Dec 4, 2025
CVE-2025-13937
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.This issue …

Dec 4, 2025
CVE-2025-13936
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.This issue …

Dec 4, 2025
CVE-2025-66574
5.4 MEDIUM

TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate …

Dec 4, 2025
CVE-2025-66237
6.7 MEDIUM

DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform …

Dec 4, 2025
CVE-2025-65806
4.3 MEDIUM

The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a nested ZIP (a ZIP containing another ZIP) where …

Dec 4, 2025
CVE-2025-63499
6.1 MEDIUM

Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

Dec 4, 2025
CVE-2025-12996
4.1 MEDIUM

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under …

Dec 4, 2025
CVE-2025-12994
5.3 MEDIUM

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine …

Dec 4, 2025
CVE-2025-63361
5.7 MEDIUM

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator password in plaintext.

Dec 4, 2025
CVE-2025-59788
6.4 MEDIUM

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, …

Dec 4, 2025
CVE-2025-14016
5.4 MEDIUM

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the …

Dec 4, 2025
CVE-2025-9127
5.5 MEDIUM

A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.

Dec 4, 2025
CVE-2025-14012
4.7 MEDIUM

A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/Comment/deleteAll.html of the component Batch Delete …

Dec 4, 2025
CVE-2025-14011
4.7 MEDIUM

A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Comment/addcomment.html of the component Add Display Name Field. …

Dec 4, 2025
CVE-2025-66373
4.8 MEDIUM

Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai …

Dec 4, 2025
CVE-2025-8074
5.6 MEDIUM

Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified …

Dec 4, 2025
CVE-2025-65516
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. When Seafile is configured with the Golang file server, …

Dec 4, 2025
CVE-2025-63681
4.3 MEDIUM

open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) …

Dec 4, 2025
CVE-2025-61148
6.5 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records …

Dec 4, 2025
CVE-2025-40251
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy The function devl_rate_nodes_destroy is documented to "Unset parent …

Dec 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.