CVE Database

57948+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-65089
6.8 MEDIUM

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights …

Nov 19, 2025
CVE-2025-65032
6.5 MEDIUM

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability allows any authenticated user to change …

Nov 19, 2025
CVE-2025-65031
6.5 MEDIUM

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in the comment creation endpoint allows authenticated users to …

Nov 19, 2025
CVE-2025-65028
6.5 MEDIUM

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authenticated user to modify …

Nov 19, 2025
CVE-2025-65026
6.1 MEDIUM

esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Literal Injection vulnerability …

Nov 19, 2025
CVE-2025-65020
6.5 MEDIUM

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the poll duplication endpoint (/api/trpc/polls.duplicate) …

Nov 19, 2025
CVE-2025-65019
5.4 MEDIUM

Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a …

Nov 19, 2025
CVE-2025-64765
5.3 MEDIUM

Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the application’s middleware …

Nov 19, 2025
CVE-2025-64708
5.8 MEDIUM

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are expired …

Nov 19, 2025
CVE-2025-64521
4.8 MEDIUM

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a …

Nov 19, 2025
CVE-2025-34330
5.3 MEDIUM

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload …

Nov 19, 2025
CVE-2025-12766
5.0 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacker to potentially gain unauthorized …

Nov 19, 2025
CVE-2025-63879
6.1 MEDIUM

A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 and earlier allows attackers to execute arbitrary Javascript in the context …

Nov 19, 2025
CVE-2025-63878
6.5 MEDIUM

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.

Nov 19, 2025
CVE-2025-13396
6.3 MEDIUM

A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument …

Nov 19, 2025
CVE-2025-63243
4.6 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.1 (01). The sle_sSenha parameter to the loginAlterarSenha.asp file. An …

Nov 19, 2025
CVE-2025-11963
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities allows Reflected XSS.This issue …

Nov 19, 2025
CVE-2025-0421
4.7 MEDIUM

Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allows iFrame Overlay.This issue affects Shopside: through 05022025.

Nov 19, 2025
CVE-2025-64408
6.3 MEDIUM

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality …

Nov 19, 2025
CVE-2025-58412
4.7 MEDIUM

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0, FortiADC 7.6.0 through 7.6.3, FortiADC 7.4 all …

Nov 19, 2025
CVE-2025-11446
6.5 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 …

Nov 19, 2025
CVE-2025-13085
4.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta Disclosure in versions up to and including …

Nov 19, 2025
CVE-2025-12535
5.3 MEDIUM

The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the …

Nov 19, 2025
CVE-2025-13054
6.4 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 19, 2025
CVE-2025-12878
6.4 MEDIUM

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up …

Nov 19, 2025
CVE-2025-12842
5.3 MEDIUM

The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 …

Nov 19, 2025
CVE-2025-12822
4.3 MEDIUM

The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Nov 19, 2025
CVE-2025-12814
5.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect capability check on the siteseo_reset_settings function …

Nov 19, 2025
CVE-2025-12751
4.3 MEDIUM

The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'reset_settings' …

Nov 19, 2025
CVE-2025-12710
6.4 MEDIUM

The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shortcode in all versions up to, and including, 3.6.1 …

Nov 19, 2025
CVE-2025-12359
5.4 MEDIUM

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' …

Nov 19, 2025
CVE-2025-12174
6.5 MEDIUM

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Nov 19, 2025
CVE-2025-12426
5.3 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the …

Nov 19, 2025
CVE-2025-12349
5.3 MEDIUM

The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This …

Nov 19, 2025
CVE-2025-6251
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 …

Nov 19, 2025
CVE-2025-12777
5.3 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the …

Nov 19, 2025
CVE-2025-12770
5.3 MEDIUM

The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API …

Nov 19, 2025
CVE-2025-12427
5.3 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST …

Nov 19, 2025
CVE-2025-13225
5.6 MEDIUM

Tanium addressed an arbitrary file deletion vulnerability in TanOS.

Nov 19, 2025
CVE-2025-65093
5.5 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application …

Nov 18, 2025
CVE-2025-65013
6.2 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application …

Nov 18, 2025
CVE-2025-65012
5.4 MEDIUM

Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any …

Nov 18, 2025
CVE-2025-64515
4.3 MEDIUM

Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data fields are dynamically set to …

Nov 18, 2025
CVE-2025-54990
5.3 MEDIUM

XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights …

Nov 18, 2025
CVE-2025-63229
5.4 MEDIUM

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious …

Nov 18, 2025
CVE-2025-12119
6.8 MEDIUM

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

Nov 18, 2025
CVE-2025-63226
5.7 MEDIUM

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. …

Nov 18, 2025
CVE-2025-37162
6.5 MEDIUM

A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could …

Nov 18, 2025
CVE-2025-63749
6.5 MEDIUM

pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.

Nov 18, 2025
CVE-2025-63693
5.4 MEDIUM

The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows …

Nov 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.