CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59438
5.3 MEDIUM

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

Oct 21, 2025
CVE-2025-57521
6.1 MEDIUM

Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without …

Oct 21, 2025
CVE-2025-56450
6.5 MEDIUM

Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLeadHistory` endpoint. A remote attacker can exploit this …

Oct 21, 2025
CVE-2020-36855
5.3 MEDIUM

A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of …

Oct 21, 2025
CVE-2025-6239
6.5 MEDIUM

Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

Oct 21, 2025
CVE-2025-7473
5.2 MEDIUM

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

Oct 21, 2025
CVE-2025-10612
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Information Technologies City Guide allows Reflected XSS.This issue affects City …

Oct 21, 2025
CVE-2025-26392
5.4 MEDIUM

SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege …

Oct 21, 2025
CVE-2025-54764
6.2 MEDIUM

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.

Oct 20, 2025
CVE-2025-12001
6.1 MEDIUM

Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 20, 2025
CVE-2025-11536
5.0 MEDIUM

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via …

Oct 20, 2025
CVE-2025-60783
6.5 MEDIUM

There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipulate the application's database through …

Oct 20, 2025
CVE-2025-60781
6.1 MEDIUM

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_name parameter.

Oct 20, 2025
CVE-2025-8051
6.5 MEDIUM

Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue …

Oct 20, 2025
CVE-2025-8048
6.5 MEDIUM

External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to submit a stored local …

Oct 20, 2025
CVE-2025-62528
5.4 MEDIUM

Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for a project …

Oct 20, 2025
CVE-2025-5517
6.8 MEDIUM

Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (MID/ CE) -Terra AC MID, ABB …

Oct 20, 2025
CVE-2025-11979
5.3 MEDIUM

An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being …

Oct 20, 2025
CVE-2025-6515
6.8 MEDIUM

The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers …

Oct 20, 2025
CVE-2025-60856
6.8 MEDIUM

Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can connect to the exposed interface …

Oct 20, 2025
CVE-2025-48025
4.3 MEDIUM

In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000, there is an improper access control …

Oct 20, 2025
CVE-2025-40005
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle unbind during busy driver support indirect read and indirect …

Oct 20, 2025
CVE-2025-8884
5.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers.This issue affects ACE Center: …

Oct 20, 2025
CVE-2025-61456
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoint. Unsanitized input in the /index parameter is directly reflected back …

Oct 20, 2025
CVE-2025-61454
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoint. Unsanitized input in the /search parameter is directly reflected back …

Oct 20, 2025
CVE-2025-57839
4.0 MEDIUM

Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Oct 20, 2025
CVE-2025-57838
4.0 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Oct 20, 2025
CVE-2025-11947
4.5 MEDIUM

A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. …

Oct 19, 2025
CVE-2025-11944
4.7 MEDIUM

A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the component Raw SQL Handler. …

Oct 19, 2025
CVE-2025-11941
5.4 MEDIUM

A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler. Performing …

Oct 19, 2025
CVE-2025-11939
4.7 MEDIUM

A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php of the component Backup Restore Handler. …

Oct 19, 2025
CVE-2025-11938
5.6 MEDIUM

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL …

Oct 19, 2025
CVE-2025-62672
5.3 MEDIUM

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy …

Oct 19, 2025
CVE-2025-11926
4.4 MEDIUM

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due …

Oct 18, 2025
CVE-2025-11256
5.3 MEDIUM

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions …

Oct 18, 2025
CVE-2025-10750
5.3 MEDIUM

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to …

Oct 18, 2025
CVE-2025-9562
6.4 MEDIUM

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, …

Oct 18, 2025
CVE-2025-11741
5.3 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the …

Oct 18, 2025
CVE-2025-11703
5.3 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This …

Oct 18, 2025
CVE-2025-11519
4.3 MEDIUM

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure …

Oct 18, 2025
CVE-2025-11510
4.3 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Oct 18, 2025
CVE-2025-11372
6.5 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is …

Oct 18, 2025
CVE-2025-11270
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute …

Oct 18, 2025
CVE-2025-10187
4.9 MEDIUM

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' parameter in all versions up …

Oct 18, 2025
CVE-2025-10006
6.4 MEDIUM

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, …

Oct 18, 2025
CVE-2025-11857
6.4 MEDIUM

The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display_embed' shortcode in all versions up to, and including, 1.9.9. …

Oct 18, 2025
CVE-2025-11742
4.3 MEDIUM

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' …

Oct 18, 2025
CVE-2025-11738
5.3 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. …

Oct 18, 2025
CVE-2025-11361
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Oct 18, 2025
CVE-2025-11378
5.4 MEDIUM

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Oct 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.