CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7959
6.4 MEDIUM

The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter in all versions up to, and including, …

Jul 24, 2025
CVE-2025-7835
4.3 MEDIUM

The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due …

Jul 24, 2025
CVE-2025-7822
4.3 MEDIUM

The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all …

Jul 24, 2025
CVE-2025-7780
6.5 MEDIUM

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to …

Jul 24, 2025
CVE-2025-7690
6.1 MEDIUM

The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing …

Jul 24, 2025
CVE-2025-6588
6.1 MEDIUM

The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to, and including, 1.4.3 due to …

Jul 24, 2025
CVE-2025-6539
6.4 MEDIUM

The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.5 …

Jul 24, 2025
CVE-2025-6387
6.4 MEDIUM

The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, …

Jul 24, 2025
CVE-2025-6385
6.4 MEDIUM

The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 0.4.1 due …

Jul 24, 2025
CVE-2025-6382
6.4 MEDIUM

The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortcode in all versions up to, and including, 0.1.10. …

Jul 24, 2025
CVE-2025-6262
6.4 MEDIUM

The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai shortcode in all versions up to, and including, …

Jul 24, 2025
CVE-2025-5084
6.1 MEDIUM

The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and including, 3.4.13 …

Jul 24, 2025
CVE-2025-4608
6.4 MEDIUM

The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and including, 1.6.4 …

Jul 24, 2025
CVE-2025-3669
6.4 MEDIUM

The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's auto_qrcodesabb shortcode in all versions up to, …

Jul 24, 2025
CVE-2025-8107
6.3 MEDIUM

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability …

Jul 24, 2025
CVE-2025-8009
4.9 MEDIUM

The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, …

Jul 24, 2025
CVE-2025-7745
5.8 MEDIUM

Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.

Jul 24, 2025
CVE-2025-7001
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have …

Jul 24, 2025
CVE-2025-4976
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain …

Jul 24, 2025
CVE-2025-4968
6.4 MEDIUM

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separator …

Jul 24, 2025
CVE-2025-4395
6.8 MEDIUM

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no …

Jul 24, 2025
CVE-2025-4394
6.8 MEDIUM

Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue …

Jul 24, 2025
CVE-2025-4393
6.5 MEDIUM

Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary …

Jul 24, 2025
CVE-2025-1299
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions …

Jul 24, 2025
CVE-2025-0765
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have …

Jul 24, 2025
CVE-2025-32019
4.1 MEDIUM

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 …

Jul 23, 2025
CVE-2025-44109
5.4 MEDIUM

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

Jul 23, 2025
CVE-2025-50477
5.4 MEDIUM

A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.

Jul 23, 2025
CVE-2025-50481
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a …

Jul 23, 2025
CVE-2025-46171
5.4 MEDIUM

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list …

Jul 23, 2025
CVE-2025-40598
6.1 MEDIUM

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

Jul 23, 2025
CVE-2025-36117
6.3 MEDIUM

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate …

Jul 23, 2025
CVE-2025-36116
6.3 MEDIUM

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated …

Jul 23, 2025
CVE-2025-33020
5.9 MEDIUM

IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to obtain highly sensitive information.

Jul 23, 2025
CVE-2025-54090
6.3 MEDIUM

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, …

Jul 23, 2025
CVE-2025-4411
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom Informatics PACS-ACSS allows Cross-Site Scripting (XSS).This issue affects PACS-ACSS: before …

Jul 23, 2025
CVE-2025-4296
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing.This issue affects B2B: before 04.06.2025.

Jul 23, 2025
CVE-2024-41751
5.5 MEDIUM

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security …

Jul 23, 2025
CVE-2024-41750
5.5 MEDIUM

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security …

Jul 23, 2025
CVE-2024-40686
5.4 MEDIUM

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input …

Jul 23, 2025
CVE-2024-40682
6.2 MEDIUM

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due …

Jul 23, 2025
CVE-2025-27930
6.4 MEDIUM

Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

Jul 23, 2025
CVE-2025-53882
4.4 MEDIUM

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP …

Jul 23, 2025
CVE-2025-6174
6.1 MEDIUM

The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_stylesheet" parameter before outputting it back in the …

Jul 23, 2025
CVE-2025-43881
4.3 MEDIUM

Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. If exploited, a denial of service (DoS) …

Jul 23, 2025
CVE-2024-53288
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated …

Jul 23, 2025
CVE-2024-53287
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated …

Jul 23, 2025
CVE-2025-42947
5.5 MEDIUM

SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An …

Jul 23, 2025
CVE-2025-6261
6.4 MEDIUM

The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetwire_list shortcode in all versions up to, and including, …

Jul 23, 2025
CVE-2025-6215
5.3 MEDIUM

The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/register endpoint is exposed to …

Jul 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.