CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13404
5.3 MEDIUM

The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing authorization validation on the duplicate_post() function in …

Nov 25, 2025
CVE-2025-13389
5.3 MEDIUM

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability …

Nov 25, 2025
CVE-2025-13386
5.3 MEDIUM

The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'options_update' function in …

Nov 25, 2025
CVE-2025-13385
4.9 MEDIUM

The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injection via the `filter[status]` parameter in all versions …

Nov 25, 2025
CVE-2025-13383
6.1 MEDIUM

The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.1. This is due …

Nov 25, 2025
CVE-2025-13382
4.3 MEDIUM

The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due …

Nov 25, 2025
CVE-2025-13380
6.5 MEDIUM

The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, …

Nov 25, 2025
CVE-2025-13370
4.9 MEDIUM

The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 0.3.0 due to …

Nov 25, 2025
CVE-2025-13311
4.4 MEDIUM

The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting in all versions up to, and including, 1.0.3 …

Nov 25, 2025
CVE-2025-12645
6.4 MEDIUM

The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcode in all versions up to, and including, …

Nov 25, 2025
CVE-2025-12634
4.3 MEDIUM

The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_refund_status' function …

Nov 25, 2025
CVE-2025-12587
4.3 MEDIUM

The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Nov 25, 2025
CVE-2025-12586
4.3 MEDIUM

The Conditional Maintenance Mode for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is …

Nov 25, 2025
CVE-2025-12525
5.3 MEDIUM

The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'lockerco_submit_post' AJAX endpoint. This makes it possible for …

Nov 25, 2025
CVE-2025-12043
5.3 MEDIUM

The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint …

Nov 25, 2025
CVE-2025-12040
6.5 MEDIUM

The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.3 via several functions …

Nov 25, 2025
CVE-2025-12032
4.4 MEDIUM

The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vithanhlam_zsocial_save_messager’, 'vithanhlam_zsocial_save_zalo', 'vithanhlam_zsocial_save_hotline', and …

Nov 25, 2025
CVE-2025-12025
4.4 MEDIUM

The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.0 due to …

Nov 25, 2025
CVE-2025-13644
6.5 MEDIUM

MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of …

Nov 25, 2025
CVE-2025-64730
6.1 MEDIUM

Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the …

Nov 25, 2025
CVE-2025-64304
4.0 MEDIUM

"FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptographic keys.

Nov 25, 2025
CVE-2025-62497
6.5 MEDIUM

Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logged in, unintended operations may …

Nov 25, 2025
CVE-2025-13558
5.4 MEDIUM

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Nov 25, 2025
CVE-2025-13507
6.5 MEDIUM

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process …

Nov 25, 2025
CVE-2025-12893
4.2 MEDIUM

Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Extended Key Usage (EKU) …

Nov 25, 2025
CVE-2025-10646
4.3 MEDIUM

The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capability check on the Base::get_rest_permission() method in all …

Nov 25, 2025
CVE-2025-64506
6.1 MEDIUM

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to …

Nov 25, 2025
CVE-2025-64505
6.1 MEDIUM

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, …

Nov 25, 2025
CVE-2025-10144
6.5 MEDIUM

The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortcode in all versions …

Nov 24, 2025
CVE-2025-63674
6.8 MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

Nov 24, 2025
CVE-2025-54341
5.3 MEDIUM

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.

Nov 24, 2025
CVE-2025-63498
6.1 MEDIUM

alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

Nov 24, 2025
CVE-2025-48511
5.5 MEDIUM

Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of …

Nov 24, 2025
CVE-2025-36150
5.9 MEDIUM

IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Nov 24, 2025
CVE-2025-29933
5.5 MEDIUM

Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service

Nov 24, 2025
CVE-2025-0007
5.7 MEDIUM

Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user space to kernel space, potentially compromising confidentiality, integrity, …

Nov 24, 2025
CVE-2025-64048
6.1 MEDIUM

YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the …

Nov 24, 2025
CVE-2025-64047
6.1 MEDIUM

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.

Nov 24, 2025
CVE-2025-63914
6.5 MEDIUM

An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although …

Nov 24, 2025
CVE-2025-36112
5.3 MEDIUM

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information …

Nov 24, 2025
CVE-2025-63953
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Nov 24, 2025
CVE-2025-63952
5.7 MEDIUM

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Nov 24, 2025
CVE-2025-63435
4.3 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not …

Nov 24, 2025
CVE-2025-63433
4.6 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a …

Nov 24, 2025
CVE-2025-63432
4.6 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update …

Nov 24, 2025
CVE-2025-60917
4.6 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the …

Nov 24, 2025
CVE-2025-60916
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the …

Nov 24, 2025
CVE-2025-60914
4.6 MEDIUM

Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo …

Nov 24, 2025
CVE-2025-60633
6.5 MEDIUM

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.

Nov 24, 2025
CVE-2025-60632
6.5 MEDIUM

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl …

Nov 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.