CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12915
6.4 MEDIUM

A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init Script Handler. The manipulation results …

Nov 8, 2025
CVE-2025-12914
4.7 MEDIUM

A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The …

Nov 8, 2025
CVE-2025-12913
4.7 MEDIUM

A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument …

Nov 8, 2025
CVE-2025-12837
6.4 MEDIUM

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in versions up to, and …

Nov 8, 2025
CVE-2025-12643
6.4 MEDIUM

The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay' shortcode in all versions up to, and including, …

Nov 8, 2025
CVE-2025-12092
6.5 MEDIUM

The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality in all versions …

Nov 8, 2025
CVE-2025-11980
4.9 MEDIUM

The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all versions up to, and including, 13.7.3 due …

Nov 8, 2025
CVE-2025-11448
4.3 MEDIUM

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Nov 8, 2025
CVE-2025-12098
5.3 MEDIUM

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Nov 8, 2025
CVE-2025-12621
5.3 MEDIUM

The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on …

Nov 8, 2025
CVE-2025-12498
4.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note creation due to a missing capability check on …

Nov 8, 2025
CVE-2025-7663
6.5 MEDIUM

The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /class-ovaem-ajax.php file …

Nov 8, 2025
CVE-2025-12353
5.3 MEDIUM

The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user …

Nov 8, 2025
CVE-2025-12193
6.1 MEDIUM

The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all versions up to, and including, 2.3.1 …

Nov 8, 2025
CVE-2025-12177
5.3 MEDIUM

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in …

Nov 8, 2025
CVE-2025-12167
4.3 MEDIUM

The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_aweber_logreset' …

Nov 8, 2025
CVE-2025-12125
4.4 MEDIUM

The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

Nov 8, 2025
CVE-2025-12112
6.4 MEDIUM

The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adding scripts in all versions up …

Nov 8, 2025
CVE-2025-12064
6.1 MEDIUM

The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 2.4.7 due to …

Nov 8, 2025
CVE-2025-12042
5.3 MEDIUM

The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the csv-export.php file in …

Nov 8, 2025
CVE-2025-12000
6.5 MEDIUM

The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpfnl_delete_log() function in all versions up …

Nov 8, 2025
CVE-2025-11972
4.9 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all …

Nov 8, 2025
CVE-2025-11748
4.3 MEDIUM

The Groups plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.0 via the 'group_id' parameter of …

Nov 8, 2025
CVE-2025-12583
6.4 MEDIUM

The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_neofix_sdl_edit' AJAX endpoint …

Nov 8, 2025
CVE-2025-64494
4.6 MEDIUM

Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert …

Nov 8, 2025
CVE-2025-64493
6.5 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the …

Nov 8, 2025
CVE-2025-64491
6.1 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scripting (XSS). Successful exploitation could lead …

Nov 8, 2025
CVE-2025-12911
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Nov 8, 2025
CVE-2025-12910
6.2 MEDIUM

Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: …

Nov 8, 2025
CVE-2025-12909
5.3 MEDIUM

Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low)

Nov 8, 2025
CVE-2025-12908
5.4 MEDIUM

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a …

Nov 8, 2025
CVE-2025-12906
5.4 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Nov 8, 2025
CVE-2025-12905
5.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted …

Nov 8, 2025
CVE-2025-64437
5.0 MEDIUM

KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the launcher-sock is a …

Nov 7, 2025
CVE-2025-64436
5.3 MEDIUM

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability …

Nov 7, 2025
CVE-2025-64435
5.3 MEDIUM

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disrupt the control …

Nov 7, 2025
CVE-2025-64434
4.7 MEDIUM

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an …

Nov 7, 2025
CVE-2025-64433
6.5 MEDIUM

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered that allows a VM to read arbitrary …

Nov 7, 2025
CVE-2025-63420
4.1 MEDIUM

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin …

Nov 7, 2025
CVE-2025-64442
6.1 MEDIUM

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be …

Nov 7, 2025
CVE-2025-63544
6.1 MEDIUM

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter.

Nov 7, 2025
CVE-2025-63543
6.1 MEDIUM

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter.

Nov 7, 2025
CVE-2025-12902
4.4 MEDIUM

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a …

Nov 7, 2025
CVE-2025-12896
4.4 MEDIUM

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a …

Nov 7, 2025
CVE-2025-12875
5.3 MEDIUM

A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing a manipulation of the argument start/length …

Nov 7, 2025
CVE-2025-63640
6.1 MEDIUM

Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing …

Nov 7, 2025
CVE-2025-63639
6.1 MEDIUM

The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied …

Nov 7, 2025
CVE-2025-63638
6.1 MEDIUM

Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing …

Nov 7, 2025
CVE-2025-7700
5.3 MEDIUM

A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to …

Nov 7, 2025
CVE-2025-64432
4.7 MEDIUM

KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication …

Nov 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.