CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20304
5.4 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-20303
5.4 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-20289
4.8 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-60753
5.5 MEDIUM

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause …

Nov 5, 2025
CVE-2025-52602
4.2 MEDIUM

HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may …

Nov 5, 2025
CVE-2025-3125
6.7 MEDIUM

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with …

Nov 5, 2025
CVE-2025-11745
6.4 MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' …

Nov 5, 2025
CVE-2025-58337
5.4 MEDIUM

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been …

Nov 5, 2025
CVE-2025-12469
4.3 MEDIUM

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up …

Nov 5, 2025
CVE-2025-12468
5.3 MEDIUM

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Nov 5, 2025
CVE-2025-12192
5.3 MEDIUM

The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided …

Nov 5, 2025
CVE-2025-11987
6.4 MEDIUM

The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 …

Nov 5, 2025
CVE-2025-11820
6.4 MEDIUM

The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widgets in all versions up to, …

Nov 5, 2025
CVE-2025-12677
5.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the register_api_route() function in …

Nov 5, 2025
CVE-2025-12676
5.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin …

Nov 5, 2025
CVE-2025-12675
4.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all …

Nov 5, 2025
CVE-2025-64151
6.7 MEDIUM

Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A user with the write permission on the root directory …

Nov 5, 2025
CVE-2025-62225
6.7 MEDIUM

Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write permission on the …

Nov 5, 2025
CVE-2025-12388
6.4 MEDIUM

The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, …

Nov 5, 2025
CVE-2025-11917
6.4 MEDIUM

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() …

Nov 5, 2025
CVE-2025-11373
4.3 MEDIUM

The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for …

Nov 5, 2025
CVE-2025-6027
6.3 MEDIUM

The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, …

Nov 5, 2025
CVE-2025-21076
5.5 MEDIUM

Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local attackers to access data in Samsung Account. User interaction …

Nov 5, 2025
CVE-2025-21075
4.3 MEDIUM

Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Nov 5, 2025
CVE-2025-21074
4.3 MEDIUM

Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Nov 5, 2025
CVE-2025-21073
6.8 MEDIUM

Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attackers to access user data. User interaction is required …

Nov 5, 2025
CVE-2025-21071
5.7 MEDIUM

Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Nov 5, 2025
CVE-2025-11072
5.3 MEDIUM

The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker …

Nov 5, 2025
CVE-2025-10873
5.3 MEDIUM

The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses due to missing authorization on the …

Nov 5, 2025
CVE-2025-10567
6.3 MEDIUM

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to …

Nov 5, 2025
CVE-2025-11162
6.4 MEDIUM

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in …

Nov 5, 2025
CVE-2025-12580
6.1 MEDIUM

The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in all versions up to, and including, 1.1.8 …

Nov 5, 2025
CVE-2025-11835
5.3 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Nov 5, 2025
CVE-2025-8871
5.6 MEDIUM

The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted …

Nov 5, 2025
CVE-2025-12582
4.3 MEDIUM

The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'features_revert_option AJAX endpoint in all …

Nov 5, 2025
CVE-2025-62722
5.4 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) …

Nov 4, 2025
CVE-2025-59596
6.5 MEDIUM

CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy …

Nov 4, 2025
CVE-2025-62721
6.5 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement …

Nov 4, 2025
CVE-2025-62720
6.5 MEDIUM

LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from …

Nov 4, 2025
CVE-2025-62719
4.3 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and …

Nov 4, 2025
CVE-2025-62715
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Scripting (XSS) vulnerability in ClipBucket’s Collection tags feature. …

Nov 4, 2025
CVE-2025-62520
4.3 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access …

Nov 4, 2025
CVE-2025-55155
5.4 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail …

Nov 4, 2025
CVE-2025-54335
6.5 MEDIUM

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU …

Nov 4, 2025
CVE-2025-48884
6.1 MEDIUM

Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette's Document Type is vulnerable to Cross-site Scripting. This …

Nov 4, 2025
CVE-2025-48076
5.4 MEDIUM

Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert …

Nov 4, 2025
CVE-2025-27374
5.3 MEDIUM

An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, …

Nov 4, 2025
CVE-2025-61431
6.1 MEDIUM

A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary …

Nov 4, 2025
CVE-2025-54327
6.5 MEDIUM

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validation in the …

Nov 4, 2025
CVE-2025-33176
6.2 MEDIUM

NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adjacent network. A successful …

Nov 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.