CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36091
4.3 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due …

Nov 3, 2025
CVE-2025-63443
5.4 MEDIUM

School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.

Nov 3, 2025
CVE-2025-63442
4.6 MEDIUM

Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, …

Nov 3, 2025
CVE-2025-60892
6.8 MEDIUM

An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub …

Nov 3, 2025
CVE-2025-45663
6.5 MEDIUM

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

Nov 3, 2025
CVE-2025-29699
6.5 MEDIUM

NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

Nov 3, 2025
CVE-2024-51317
6.5 MEDIUM

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

Nov 3, 2025
CVE-2025-64294
5.3 MEDIUM

Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through …

Nov 3, 2025
CVE-2025-12626
4.3 MEDIUM

A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the …

Nov 3, 2025
CVE-2025-12503
6.5 MEDIUM

EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database …

Nov 3, 2025
CVE-2025-12615
5.0 MEDIUM

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of …

Nov 3, 2025
CVE-2025-12614
4.7 MEDIUM

A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of …

Nov 3, 2025
CVE-2025-12612
6.3 MEDIUM

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The …

Nov 3, 2025
CVE-2025-12610
4.7 MEDIUM

A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument …

Nov 3, 2025
CVE-2025-12609
4.7 MEDIUM

A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation …

Nov 3, 2025
CVE-2025-12598
4.7 MEDIUM

A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. …

Nov 2, 2025
CVE-2025-12597
4.7 MEDIUM

A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing …

Nov 2, 2025
CVE-2025-12594
4.7 MEDIUM

A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown function of the file /admin/add_account.php. The manipulation …

Nov 2, 2025
CVE-2025-12593
4.7 MEDIUM

A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the …

Nov 2, 2025
CVE-2025-6988
6.4 MEDIUM

The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 4.23.0 …

Nov 1, 2025
CVE-2025-12137
4.9 MEDIUM

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions …

Nov 1, 2025
CVE-2025-12180
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin …

Nov 1, 2025
CVE-2025-12090
6.4 MEDIUM

The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social URLs in …

Nov 1, 2025
CVE-2025-12038
4.3 MEDIUM

The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the /wp-json/folderly/v1/config/clear-all-data REST API endpoint in …

Nov 1, 2025
CVE-2025-11983
4.3 MEDIUM

The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9. This is due to the plugin …

Nov 1, 2025
CVE-2025-11740
6.5 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to …

Nov 1, 2025
CVE-2025-11502
6.4 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all …

Nov 1, 2025
CVE-2025-12118
6.4 MEDIUM

The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.6.1 due …

Nov 1, 2025
CVE-2025-11927
4.4 MEDIUM

The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in …

Nov 1, 2025
CVE-2025-11377
4.3 MEDIUM

The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.92.0 via the 'catlist' shortcode due …

Nov 1, 2025
CVE-2025-12367
4.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.3.1. This is due to the …

Nov 1, 2025
CVE-2025-11928
4.4 MEDIUM

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 …

Nov 1, 2025
CVE-2025-62275
5.3 MEDIUM

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, …

Nov 1, 2025
CVE-2025-11922
6.4 MEDIUM

The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due …

Nov 1, 2025
CVE-2025-11816
5.3 MEDIUM

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due …

Nov 1, 2025
CVE-2025-11174
5.3 MEDIUM

The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the …

Nov 1, 2025
CVE-2025-62276
5.5 MEDIUM

The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 …

Nov 1, 2025
CVE-2025-12464
6.2 MEDIUM

A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and …

Oct 31, 2025
CVE-2025-63563
6.5 MEDIUM

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker …

Oct 31, 2025
CVE-2025-63562
6.3 MEDIUM

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions …

Oct 31, 2025
CVE-2025-60711
6.3 MEDIUM

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Oct 31, 2025
CVE-2025-62267
6.1 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 …

Oct 31, 2025
CVE-2025-62264
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 …

Oct 31, 2025
CVE-2025-6075
5.5 MEDIUM

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

Oct 31, 2025
CVE-2025-59501
4.8 MEDIUM

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

Oct 31, 2025
CVE-2025-12357
6.3 MEDIUM

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers …

Oct 31, 2025
CVE-2025-61427
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execute arbitrary code in the context of a …

Oct 31, 2025
CVE-2025-12521
5.3 MEDIUM

The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify Tag HTML …

Oct 31, 2025
CVE-2024-13992
5.4 MEDIUM

Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following …

Oct 31, 2025
CVE-2025-64368
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a through <= 1.6.

Oct 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.