CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-51733
5.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-12143
6.1 MEDIUM

Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

Nov 28, 2025
CVE-2025-13771
6.5 MEDIUM

WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

Nov 28, 2025
CVE-2025-13770
6.5 MEDIUM

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Nov 28, 2025
CVE-2025-13769
6.5 MEDIUM

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Nov 28, 2025
CVE-2025-66386
4.1 MEDIUM

app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

Nov 28, 2025
CVE-2025-66371
5.0 MEDIUM

Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and …

Nov 28, 2025
CVE-2025-66370
5.0 MEDIUM

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the …

Nov 28, 2025
CVE-2025-64312
4.9 MEDIUM

Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58311
5.8 MEDIUM

UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58305
6.2 MEDIUM

Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58304
4.9 MEDIUM

Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-13737
4.3 MEDIUM

The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is …

Nov 28, 2025
CVE-2025-64315
4.4 MEDIUM

Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.

Nov 28, 2025
CVE-2025-64313
5.3 MEDIUM

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-64311
5.1 MEDIUM

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58315
5.5 MEDIUM

Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58314
6.6 MEDIUM

Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58312
5.1 MEDIUM

Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-58309
6.8 MEDIUM

Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58307
6.4 MEDIUM

UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-58294
6.2 MEDIUM

Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-66361
6.5 MEDIUM

An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.

Nov 28, 2025
CVE-2025-12559
4.3 MEDIUM

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to …

Nov 27, 2025
CVE-2025-13765
4.3 MEDIUM

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Nov 27, 2025
CVE-2025-12971
4.3 MEDIUM

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due …

Nov 27, 2025
CVE-2025-59454
4.3 MEDIUM

In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs …

Nov 27, 2025
CVE-2025-59302
4.7 MEDIUM

In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * …

Nov 27, 2025
CVE-2025-54057
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: <= 10.2.0. Users are …

Nov 27, 2025
CVE-2025-13742
6.1 MEDIUM

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it …

Nov 27, 2025
CVE-2025-10476
4.3 MEDIUM

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in …

Nov 27, 2025
CVE-2025-59026
5.4 MEDIUM

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-59025
6.1 MEDIUM

Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of …

Nov 27, 2025
CVE-2025-30190
5.4 MEDIUM

Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-30186
5.4 MEDIUM

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-13381
5.3 MEDIUM

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Nov 27, 2025
CVE-2025-13378
6.5 MEDIUM

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Nov 27, 2025
CVE-2025-12584
5.3 MEDIUM

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX …

Nov 27, 2025
CVE-2025-13441
5.3 MEDIUM

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This …

Nov 27, 2025
CVE-2025-13157
5.3 MEDIUM

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the …

Nov 27, 2025
CVE-2025-13525
6.1 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 …

Nov 27, 2025
CVE-2025-13143
4.3 MEDIUM

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Nov 27, 2025
CVE-2025-12185
4.4 MEDIUM

The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient …

Nov 27, 2025
CVE-2025-12123
6.1 MEDIUM

The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email-text' parameter in all versions up to, and …

Nov 27, 2025
CVE-2025-3784
5.5 MEDIUM

Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As …

Nov 27, 2025
CVE-2025-12151
6.4 MEDIUM

The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in all versions up to, and including, 1.1.0 due …

Nov 27, 2025
CVE-2025-12713
6.4 MEDIUM

The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to …

Nov 27, 2025
CVE-2025-12712
6.4 MEDIUM

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up to, and including, 0.2.1 due to …

Nov 27, 2025
CVE-2025-12670
6.4 MEDIUM

The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic' shortcode in all versions up to, and including, …

Nov 27, 2025
CVE-2025-12666
6.4 MEDIUM

The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in …

Nov 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.