CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8691
6.4 MEDIUM

The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 2.0.0 due …

Sep 11, 2025
CVE-2025-8689
6.4 MEDIUM

The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, HotSpot Plus, and Google Maps widgets in all …

Sep 11, 2025
CVE-2025-8686
6.4 MEDIUM

The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WP_EASY_FAQ shortcode in all versions up to, and including, …

Sep 11, 2025
CVE-2025-8492
5.3 MEDIUM

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Sep 11, 2025
CVE-2025-8481
4.3 MEDIUM

The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.1.7. This …

Sep 11, 2025
CVE-2025-8445
6.4 MEDIUM

The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_label' Parameter in all versions up to, and including, …

Sep 11, 2025
CVE-2025-8423
5.4 MEDIUM

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_plugin() and ajax_update_export_code() …

Sep 11, 2025
CVE-2025-8398
6.4 MEDIUM

The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 2.0.4 …

Sep 11, 2025
CVE-2025-8392
6.4 MEDIUM

The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all versions up to, and including, 1.1.5 due to …

Sep 11, 2025
CVE-2025-8318
6.4 MEDIUM

The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’ parameter in all versions up to, and including, 1.4.4 due to …

Sep 11, 2025
CVE-2025-8316
6.4 MEDIUM

The Certifica WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘evento’ parameter in all versions up to, and including, 3.1 due …

Sep 11, 2025
CVE-2025-8215
6.4 MEDIUM

The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.0.1 …

Sep 11, 2025
CVE-2025-5801
6.4 MEDIUM

The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ parameter in all versions up to, and including, 1.0.8 …

Sep 11, 2025
CVE-2025-0763
4.3 MEDIUM

The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_custom_fields function in …

Sep 11, 2025
CVE-2025-8479
4.3 MEDIUM

The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1. This is due to missing or …

Sep 11, 2025
CVE-2025-9034
6.1 MEDIUM

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open …

Sep 11, 2025
CVE-2025-10247
6.3 MEDIUM

A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of the component Filter Handler. Such manipulation leads to improper …

Sep 11, 2025
CVE-2025-9910
4.7 MEDIUM

Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that …

Sep 11, 2025
CVE-2025-9776
6.5 MEDIUM

The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Injection via the CSV Import contents in …

Sep 11, 2025
CVE-2025-10245
4.3 MEDIUM

A security flaw has been discovered in Display Painéis TGA up to 7.1.41. Affected by this issue is some unknown functionality of the file /gallery/rename …

Sep 11, 2025
CVE-2025-10236
4.3 MEDIUM

A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File …

Sep 11, 2025
CVE-2025-10233
6.3 MEDIUM

A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path …

Sep 10, 2025
CVE-2025-10232
5.4 MEDIUM

A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the file plugin/filemanager/controllers/FileManagerAPIController.php. Executing manipulation can …

Sep 10, 2025
CVE-2025-10229
4.3 MEDIUM

A vulnerability has been found in Freshwork up to 1.2.3. This impacts an unknown function of the file /api/v2/logout. Such manipulation of the argument post_logout_redirect_uri …

Sep 10, 2025
CVE-2025-10218
6.3 MEDIUM

A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/dao/SysRoleDao.go of the component Background Management Page. This …

Sep 10, 2025
CVE-2025-43783
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 update …

Sep 10, 2025
CVE-2025-10211
6.3 MEDIUM

A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectController of the file /cms/collect/getArticle. The manipulation of the …

Sep 10, 2025
CVE-2024-47120
6.4 MEDIUM

IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host …

Sep 10, 2025
CVE-2024-45671
5.9 MEDIUM

IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive …

Sep 10, 2025
CVE-2024-45669
6.5 MEDIUM

IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handling …

Sep 10, 2025
CVE-2025-9714
6.2 MEDIUM

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. …

Sep 10, 2025
CVE-2025-43784
6.5 MEDIUM

Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 …

Sep 10, 2025
CVE-2025-10210
6.3 MEDIUM

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument …

Sep 10, 2025
CVE-2025-10209
5.4 MEDIUM

A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Handler. Performing …

Sep 10, 2025
CVE-2025-57520
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized …

Sep 10, 2025
CVE-2025-43785
6.1 MEDIUM

Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 …

Sep 10, 2025
CVE-2025-8681
5.5 MEDIUM

Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with …

Sep 10, 2025
CVE-2025-59035
4.6 MEDIUM

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a Cross-Site-Scripting vulnerability when …

Sep 10, 2025
CVE-2025-59034
4.3 MEDIUM

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user …

Sep 10, 2025
CVE-2025-57573
5.6 MEDIUM

Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi.

Sep 10, 2025
CVE-2025-57572
5.6 MEDIUM

Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentControl.

Sep 10, 2025
CVE-2025-57571
5.6 MEDIUM

Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT.

Sep 10, 2025
CVE-2025-57570
5.6 MEDIUM

Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.

Sep 10, 2025
CVE-2025-57569
5.6 MEDIUM

Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.

Sep 10, 2025
CVE-2025-43938
5.0 MEDIUM

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could …

Sep 10, 2025
CVE-2025-43886
4.4 MEDIUM

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerability. A high privileged attacker with local access could potentially exploit …

Sep 10, 2025
CVE-2025-29592
5.6 MEDIUM

oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.

Sep 10, 2025
CVE-2025-20248
6.0 MEDIUM

A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature …

Sep 10, 2025
CVE-2025-20159
5.3 MEDIUM

A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass …

Sep 10, 2025
CVE-2025-56578
5.7 MEDIUM

An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authentication mechanisms

Sep 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.