CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64322
5.3 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.

Nov 4, 2025
CVE-2025-64321
5.3 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before …

Nov 4, 2025
CVE-2025-64320
6.5 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.

Nov 4, 2025
CVE-2025-64319
5.3 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before …

Nov 4, 2025
CVE-2025-64318
5.3 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code …

Nov 4, 2025
CVE-2025-10875
6.5 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue affects Mulesoft Anypoint Code Builder: before …

Nov 4, 2025
CVE-2025-54333
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the …

Nov 4, 2025
CVE-2025-54325
5.3 MEDIUM

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. …

Nov 4, 2025
CVE-2025-60925
5.3 MEDIUM

codeshare v1.0.0 was discovered to contain an information leakage vulnerability.

Nov 4, 2025
CVE-2025-54331
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the …

Nov 4, 2025
CVE-2025-54330
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me …

Nov 4, 2025
CVE-2025-63294
6.5 MEDIUM

WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf …

Nov 4, 2025
CVE-2025-12184
4.4 MEDIUM

The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.11 due to insufficient …

Nov 4, 2025
CVE-2025-12695
5.9 MEDIUM

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input …

Nov 4, 2025
CVE-2025-12045
6.4 MEDIUM

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 4, 2025
CVE-2025-20749
6.7 MEDIUM

In charger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Nov 4, 2025
CVE-2025-20748
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20747
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Nov 4, 2025
CVE-2025-20746
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Nov 4, 2025
CVE-2025-20745
4.2 MEDIUM

In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Nov 4, 2025
CVE-2025-20744
4.2 MEDIUM

In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious …

Nov 4, 2025
CVE-2025-20743
4.2 MEDIUM

In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious …

Nov 4, 2025
CVE-2025-20741
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20740
4.7 MEDIUM

In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with …

Nov 4, 2025
CVE-2025-20739
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20738
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20736
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20734
5.3 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20732
5.3 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20731
5.3 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20730
6.7 MEDIUM

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a …

Nov 4, 2025
CVE-2025-20729
4.2 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-12456
6.1 MEDIUM

The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or …

Nov 4, 2025
CVE-2025-12452
6.1 MEDIUM

The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on …

Nov 4, 2025
CVE-2025-12416
6.1 MEDIUM

The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This …

Nov 4, 2025
CVE-2025-12415
6.1 MEDIUM

The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or …

Nov 4, 2025
CVE-2025-12413
5.4 MEDIUM

The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3. This is …

Nov 4, 2025
CVE-2025-12412
6.1 MEDIUM

The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to …

Nov 4, 2025
CVE-2025-12410
6.1 MEDIUM

The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to …

Nov 4, 2025
CVE-2025-12403
6.1 MEDIUM

The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to …

Nov 4, 2025
CVE-2025-12402
6.1 MEDIUM

The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.00. This is due to missing …

Nov 4, 2025
CVE-2025-12400
6.1 MEDIUM

The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2. This is due to missing …

Nov 4, 2025
CVE-2025-12396
4.4 MEDIUM

The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.2 due to insufficient …

Nov 4, 2025
CVE-2025-12393
4.4 MEDIUM

The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.6 due to …

Nov 4, 2025
CVE-2025-12389
4.3 MEDIUM

The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function …

Nov 4, 2025
CVE-2025-12371
4.4 MEDIUM

The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versions up to, and including, 1.0.12 due to …

Nov 4, 2025
CVE-2025-12369
6.4 MEDIUM

The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker` shortcode in all versions up to, and including, …

Nov 4, 2025
CVE-2025-12350
5.3 MEDIUM

The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up …

Nov 4, 2025
CVE-2025-12188
4.3 MEDIUM

The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Nov 4, 2025
CVE-2025-12157
5.3 MEDIUM

The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_reset_capability' AJAX endpoint …

Nov 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.