CVE Database

52406+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49896
5.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord …

Aug 20, 2025
CVE-2025-49412
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in numixtech Page Transition page-transition allows Stored XSS.This issue affects Page Transition: from n/a …

Aug 20, 2025
CVE-2025-49397
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Colorbox Lightbox wp-colorbox allows Stored XSS.This issue affects Colorbox Lightbox: from …

Aug 20, 2025
CVE-2025-49396
4.3 MEDIUM

Missing Authorization vulnerability in themifyme Themify Builder themify-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Themify Builder: from n/a through <= 7.6.7.

Aug 20, 2025
CVE-2025-49395
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Icons themify-icons allows Stored XSS.This issue affects Themify Icons: from n/a …

Aug 20, 2025
CVE-2025-49392
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Audio Dock themify-audio-dock allows Stored XSS.This issue affects Themify Audio Dock: …

Aug 20, 2025
CVE-2025-49391
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Cross Site Request Forgery.This issue affects Sign-up Sheets: from n/a through <= 2.3.3.

Aug 20, 2025
CVE-2025-49389
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Solutions Notice Bar notice-bar allows Stored XSS.This issue affects Notice Bar: from …

Aug 20, 2025
CVE-2025-47650
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global infility-global allows Path Traversal.This issue affects Infility Global: from …

Aug 20, 2025
CVE-2025-9202
4.3 MEDIUM

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions …

Aug 20, 2025
CVE-2025-8618
6.4 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up …

Aug 20, 2025
CVE-2025-55706
4.3 MEDIUM

URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the …

Aug 20, 2025
CVE-2025-54551
4.3 MEDIUM

Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the …

Aug 20, 2025
CVE-2025-53522
5.3 MEDIUM

Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote …

Aug 20, 2025
CVE-2025-57791
6.5 MEDIUM

A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. …

Aug 20, 2025
CVE-2025-57789
5.4 MEDIUM

During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited …

Aug 20, 2025
CVE-2025-57788
6.5 MEDIUM

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does …

Aug 20, 2025
CVE-2025-9176
5.3 MEDIUM

A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment …

Aug 20, 2025
CVE-2025-9175
5.3 MEDIUM

A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c. The manipulation leads to stack-based …

Aug 19, 2025
CVE-2025-9174
5.3 MEDIUM

A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filename Handler. …

Aug 19, 2025
CVE-2025-9186
6.5 MEDIUM

Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.

Aug 19, 2025
CVE-2025-9183
6.5 MEDIUM

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.

Aug 19, 2025
CVE-2025-9181
6.5 MEDIUM

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and …

Aug 19, 2025
CVE-2025-8364
4.3 MEDIUM

A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue …

Aug 19, 2025
CVE-2025-8041
5.3 MEDIUM

In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in …

Aug 19, 2025
CVE-2025-55033
6.1 MEDIUM

Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability …

Aug 19, 2025
CVE-2025-55032
6.1 MEDIUM

Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowing for XSS attacks. This …

Aug 19, 2025
CVE-2025-55030
6.1 MEDIUM

Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for …

Aug 19, 2025
CVE-2025-55028
6.5 MEDIUM

Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed …

Aug 19, 2025
CVE-2025-54144
5.4 MEDIUM

The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if …

Aug 19, 2025
CVE-2025-9157
5.3 MEDIUM

A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. …

Aug 19, 2025
CVE-2025-55740
6.5 MEDIUM

nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender …

Aug 19, 2025
CVE-2025-55737
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. …

Aug 19, 2025
CVE-2025-52337
6.5 MEDIUM

An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to execute arbitrary code via uploading a …

Aug 19, 2025
CVE-2025-50926
6.5 MEDIUM

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function.

Aug 19, 2025
CVE-2025-43744
5.4 MEDIUM

A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, …

Aug 19, 2025
CVE-2025-43743
4.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 …

Aug 19, 2025
CVE-2025-9153
6.3 MEDIUM

A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of …

Aug 19, 2025
CVE-2025-55736
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges …

Aug 19, 2025
CVE-2025-55735
5.4 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post …

Aug 19, 2025
CVE-2025-55734
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin …

Aug 19, 2025
CVE-2025-55303
6.1 MEDIUM

Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand …

Aug 19, 2025
CVE-2025-52338
5.3 MEDIUM

An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts …

Aug 19, 2025
CVE-2025-43745
6.5 MEDIUM

A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 …

Aug 19, 2025
CVE-2025-43737
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated …

Aug 19, 2025
CVE-2025-33008
5.4 MEDIUM

IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Aug 19, 2025
CVE-2025-31988
4.9 MEDIUM

HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.

Aug 19, 2025
CVE-2025-9151
6.3 MEDIUM

A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of the file /web_config/json/name/web. Performing …

Aug 19, 2025
CVE-2025-9149
6.3 MEDIUM

A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command …

Aug 19, 2025
CVE-2025-55295
6.5 MEDIUM

qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability exists in qbit_manage's web API that …

Aug 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.