CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12649
6.4 MEDIUM

The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sorttablepost shortcode in all versions up to, …

Nov 27, 2025
CVE-2025-12579
5.3 MEDIUM

The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action in all …

Nov 27, 2025
CVE-2025-12578
4.3 MEDIUM

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing …

Nov 27, 2025
CVE-2025-66030
5.3 MEDIUM

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables …

Nov 26, 2025
CVE-2025-7449
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-6195
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-65670
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized …

Nov 26, 2025
CVE-2025-12653
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific …

Nov 26, 2025
CVE-2025-65676
5.4 MEDIUM

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images.

Nov 26, 2025
CVE-2025-65675
5.4 MEDIUM

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures.

Nov 26, 2025
CVE-2021-4472
6.5 MEDIUM

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files …

Nov 26, 2025
CVE-2025-65239
4.3 MEDIUM

Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.

Nov 26, 2025
CVE-2025-65238
6.5 MEDIUM

Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user …

Nov 26, 2025
CVE-2025-65237
6.1 MEDIUM

A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a …

Nov 26, 2025
CVE-2025-63938
6.5 MEDIUM

Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.

Nov 26, 2025
CVE-2025-9191
6.3 MEDIUM

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in …

Nov 26, 2025
CVE-2025-9163
6.1 MEDIUM

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to …

Nov 26, 2025
CVE-2025-13674
5.5 MEDIUM

BPv7 dissector crash in Wireshark 4.6.0 allows denial of service

Nov 26, 2025
CVE-2025-62728
5.4 MEDIUM

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized …

Nov 26, 2025
CVE-2025-59820
6.7 MEDIUM

In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow proceeds even …

Nov 26, 2025
CVE-2025-66026
6.1 MEDIUM

REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the Mediapool view where the request parameter args[types] …

Nov 26, 2025
CVE-2025-66025
4.3 MEDIUM

Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page improperly handled user-supplied Markdown, allowing attacker-controlled …

Nov 26, 2025
CVE-2025-66021
6.1 MEDIUM

OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against …

Nov 26, 2025
CVE-2025-12848
6.1 MEDIUM

Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name renderer. An unauthenticated attacker can exploit this …

Nov 26, 2025
CVE-2025-66260
6.5 MEDIUM

PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows …

Nov 26, 2025
CVE-2025-66258
5.4 MEDIUM

Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, …

Nov 26, 2025
CVE-2025-65963
5.4 MEDIUM

Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to …

Nov 26, 2025
CVE-2025-65956
6.5 MEDIUM

Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross‑site …

Nov 26, 2025
CVE-2025-64713
5.1 MEDIUM

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter …

Nov 25, 2025
CVE-2025-64704
4.7 MEDIUM

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. …

Nov 25, 2025
CVE-2025-63735
6.1 MEDIUM

A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

Nov 25, 2025
CVE-2025-21621
6.1 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XSS) vulnerability …

Nov 25, 2025
CVE-2025-65647
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.

Nov 25, 2025
CVE-2025-65960
6.6 MEDIUM

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the …

Nov 25, 2025
CVE-2025-64067
5.3 MEDIUM

Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side validation to …

Nov 25, 2025
CVE-2025-61167
6.5 MEDIUM

SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas parameters.

Nov 25, 2025
CVE-2025-33197
4.3 MEDIUM

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereference. A successful exploit of this vulnerability …

Nov 25, 2025
CVE-2025-33196
4.4 MEDIUM

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this …

Nov 25, 2025
CVE-2025-33195
4.4 MEDIUM

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer operations. A successful exploit of this vulnerability …

Nov 25, 2025
CVE-2025-33194
5.7 MEDIUM

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this …

Nov 25, 2025
CVE-2025-33193
5.7 MEDIUM

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of integrity. A successful exploit of this vulnerability …

Nov 25, 2025
CVE-2025-33192
5.7 MEDIUM

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read. A successful exploit of this vulnerability …

Nov 25, 2025
CVE-2025-33191
5.7 MEDIUM

NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this vulnerability …

Nov 25, 2025
CVE-2025-33190
6.7 MEDIUM

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A successful exploit of this vulnerability might …

Nov 25, 2025
CVE-2025-64061
4.3 MEDIUM

Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their privilege …

Nov 25, 2025
CVE-2025-64049
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML …

Nov 25, 2025
CVE-2025-13467
5.5 MEDIUM

A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects …

Nov 25, 2025
CVE-2025-13452
4.3 MEDIUM

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, …

Nov 25, 2025
CVE-2025-13414
5.3 MEDIUM

The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing capability check on the cdash_watch_for_export() function in …

Nov 25, 2025
CVE-2025-13405
5.3 MEDIUM

The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing authorization validation on the cptb_delete_custom_taxonomy() function in …

Nov 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.