CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-47148
6.5 MEDIUM

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) …

Oct 15, 2025
CVE-2025-9640
4.3 MEDIUM

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated …

Oct 15, 2025
CVE-2025-10869
6.1 MEDIUM

Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious …

Oct 15, 2025
CVE-2025-55082
5.3 MEDIUM

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a …

Oct 15, 2025
CVE-2025-11728
5.3 MEDIUM

The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the …

Oct 15, 2025
CVE-2025-11701
5.3 MEDIUM

The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check as well as missing post status …

Oct 15, 2025
CVE-2025-11692
5.3 MEDIUM

The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and capability checks on the download.php file …

Oct 15, 2025
CVE-2025-11365
6.5 MEDIUM

The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google_map' shortcode in all versions …

Oct 15, 2025
CVE-2025-11196
4.3 MEDIUM

The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.11.2 due to the 'exlog_test_connection' AJAX …

Oct 15, 2025
CVE-2025-10730
6.5 MEDIUM

The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all versions up to, and including, 4.0 due …

Oct 15, 2025
CVE-2025-10682
6.5 MEDIUM

The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to insufficient neutralization of user-supplied …

Oct 15, 2025
CVE-2025-10660
6.5 MEDIUM

The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.0.3 due …

Oct 15, 2025
CVE-2025-10648
5.3 MEDIUM

The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Oct 15, 2025
CVE-2025-10575
6.5 MEDIUM

The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter handled by the WPJqueryPaged::get_gallery_page_imgs() function in all …

Oct 15, 2025
CVE-2025-10486
5.3 MEDIUM

The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly exposed log files. …

Oct 15, 2025
CVE-2025-10312
4.3 MEDIUM

The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Oct 15, 2025
CVE-2025-10310
4.9 MEDIUM

The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versions up to, and including, 2.0.0105 …

Oct 15, 2025
CVE-2025-10303
4.3 MEDIUM

The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in …

Oct 15, 2025
CVE-2025-10301
4.3 MEDIUM

The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or …

Oct 15, 2025
CVE-2025-10300
4.3 MEDIUM

The TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or …

Oct 15, 2025
CVE-2025-10194
6.4 MEDIUM

The Shortcode Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.9 …

Oct 15, 2025
CVE-2025-10186
5.3 MEDIUM

The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability …

Oct 15, 2025
CVE-2025-10141
6.4 MEDIUM

The Digiseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ds' shortcode in all versions up to, and including, 1.3 due …

Oct 15, 2025
CVE-2025-10140
6.4 MEDIUM

The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' shortcode in all versions up to, and including, …

Oct 15, 2025
CVE-2025-10139
6.4 MEDIUM

The WP BookWidgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bw_link' shortcode in all versions up to, and including, 0.9 …

Oct 15, 2025
CVE-2025-10135
6.4 MEDIUM

The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewstl' shortcode in all versions up to, and including, 1.0 …

Oct 15, 2025
CVE-2025-10133
6.4 MEDIUM

The URLYar URL Shortner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'urlyar_shortlink' shortcode in all versions up to, and including, …

Oct 15, 2025
CVE-2025-10132
6.4 MEDIUM

The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode in all versions up to, and including, 0.1 …

Oct 15, 2025
CVE-2025-10056
4.4 MEDIUM

The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.3 via the “Check Website” task. …

Oct 15, 2025
CVE-2025-10045
4.9 MEDIUM

The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 6.5.1 due …

Oct 15, 2025
CVE-2025-10038
6.5 MEDIUM

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to …

Oct 15, 2025
CVE-2025-55039
6.5 MEDIUM

This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption …

Oct 15, 2025
CVE-2025-11161
6.4 MEDIUM

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. …

Oct 15, 2025
CVE-2025-11160
6.4 MEDIUM

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and including, …

Oct 15, 2025
CVE-2025-8561
6.4 MEDIUM

The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.1.7 due …

Oct 15, 2025
CVE-2025-31702
6.8 MEDIUM

A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which …

Oct 15, 2025
CVE-2025-11176
4.3 MEDIUM

The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail …

Oct 15, 2025
CVE-2025-10406
5.5 MEDIUM

The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any …

Oct 15, 2025
CVE-2025-55079
5.5 MEDIUM

In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't …

Oct 15, 2025
CVE-2025-54278
5.5 MEDIUM

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this …

Oct 15, 2025
CVE-2025-54270
5.5 MEDIUM

Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this …

Oct 15, 2025
CVE-2025-54269
5.5 MEDIUM

Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability …

Oct 15, 2025
CVE-2025-61797
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-61796
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-54272
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-54196
4.3 MEDIUM

Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to …

Oct 14, 2025
CVE-2025-54267
6.5 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability …

Oct 14, 2025
CVE-2025-54266
4.8 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by …

Oct 14, 2025
CVE-2025-54265
5.9 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to …

Oct 14, 2025
CVE-2025-62374
6.4 MEDIUM

Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to …

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.