CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12651
6.4 MEDIUM

The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img_src', and 'class' parameters in the livephotos_photo shortcode …

Nov 11, 2025
CVE-2025-12644
6.4 MEDIUM

The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nonaki' shortcode in …

Nov 11, 2025
CVE-2025-12632
5.5 MEDIUM

The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.4 due to insufficient …

Nov 11, 2025
CVE-2025-12631
4.4 MEDIUM

The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due …

Nov 11, 2025
CVE-2025-12590
6.1 MEDIUM

The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.1. This is …

Nov 11, 2025
CVE-2025-12589
6.1 MEDIUM

The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 0.5.3.5. This is …

Nov 11, 2025
CVE-2025-12588
4.3 MEDIUM

The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This …

Nov 11, 2025
CVE-2025-12538
4.4 MEDIUM

The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.1 due to …

Nov 11, 2025
CVE-2025-12526
4.3 MEDIUM

The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in …

Nov 11, 2025
CVE-2025-12132
4.3 MEDIUM

The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8.4. This …

Nov 11, 2025
CVE-2025-12126
5.4 MEDIUM

The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via several …

Nov 11, 2025
CVE-2025-12021
6.1 MEDIUM

The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 0.4.1 due to …

Nov 11, 2025
CVE-2025-12020
4.9 MEDIUM

The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin …

Nov 11, 2025
CVE-2025-12019
4.4 MEDIUM

The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions up to, and including, 2.1 due to …

Nov 11, 2025
CVE-2025-12010
6.5 MEDIUM

The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method …

Nov 11, 2025
CVE-2025-11999
5.3 MEDIUM

The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and …

Nov 11, 2025
CVE-2025-11997
5.3 MEDIUM

The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9. …

Nov 11, 2025
CVE-2025-11996
5.3 MEDIUM

The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() …

Nov 11, 2025
CVE-2025-11988
5.3 MEDIUM

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the …

Nov 11, 2025
CVE-2025-11986
5.3 MEDIUM

The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering …

Nov 11, 2025
CVE-2025-11894
5.3 MEDIUM

The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in …

Nov 11, 2025
CVE-2025-11891
5.3 MEDIUM

The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files. …

Nov 11, 2025
CVE-2025-11886
4.3 MEDIUM

The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to …

Nov 11, 2025
CVE-2025-11882
6.4 MEDIUM

The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortcode in versions less than, or equal to, 1.0 …

Nov 11, 2025
CVE-2025-11874
5.4 MEDIUM

The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slippy-slider' shortcode in all versions …

Nov 11, 2025
CVE-2025-11873
6.4 MEDIUM

The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 1.8.1 …

Nov 11, 2025
CVE-2025-11869
6.4 MEDIUM

The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attribute in all versions up to, and including, 1.0. …

Nov 11, 2025
CVE-2025-11863
6.4 MEDIUM

The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode in all versions up to, and including, …

Nov 11, 2025
CVE-2025-11860
6.4 MEDIUM

The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This …

Nov 11, 2025
CVE-2025-11859
6.4 MEDIUM

The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. …

Nov 11, 2025
CVE-2025-11856
6.4 MEDIUM

The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketwidget' shortcode in all versions up to, and including, 1.0. …

Nov 11, 2025
CVE-2025-11829
6.4 MEDIUM

The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the [five9-chat] shortcode in all versions up …

Nov 11, 2025
CVE-2025-11828
6.4 MEDIUM

The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, …

Nov 11, 2025
CVE-2025-11822
6.4 MEDIUM

The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcode in all versions up to, and including, 1.0.4. …

Nov 11, 2025
CVE-2025-11821
6.4 MEDIUM

The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_products_custom_tax' shortcode in all versions up to, …

Nov 11, 2025
CVE-2025-11805
6.4 MEDIUM

The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in all versions up to, and including, 1.4.4. …

Nov 11, 2025
CVE-2025-11532
5.3 MEDIUM

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validation on …

Nov 11, 2025
CVE-2025-11129
6.4 MEDIUM

The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'type' parameters in all versions up to, and …

Nov 11, 2025
CVE-2025-42924
6.1 MEDIUM

SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled …

Nov 11, 2025
CVE-2025-42919
5.3 MEDIUM

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could …

Nov 11, 2025
CVE-2025-42899
4.3 MEDIUM

SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. This has low impact on …

Nov 11, 2025
CVE-2025-42897
5.3 MEDIUM

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized …

Nov 11, 2025
CVE-2025-42895
6.9 MEDIUM

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead …

Nov 11, 2025
CVE-2025-42894
6.8 MEDIUM

Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete …

Nov 11, 2025
CVE-2025-42893
6.1 MEDIUM

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects …

Nov 11, 2025
CVE-2025-42892
6.8 MEDIUM

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted …

Nov 11, 2025
CVE-2025-42889
5.4 MEDIUM

SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this vulnerability has a low …

Nov 11, 2025
CVE-2025-42888
5.5 MEDIUM

SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during …

Nov 11, 2025
CVE-2025-42886
6.1 MEDIUM

Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. …

Nov 11, 2025
CVE-2025-42885
5.8 MEDIUM

Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled function that will enable them to view information. As …

Nov 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.