CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53211
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Retrieve Embedded Sensitive Data.This issue …

Jun 27, 2025
CVE-2025-53206
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder ht-mega-for-wpbakery allows …

Jun 27, 2025
CVE-2025-53203
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Cross Site Request Forgery.This issue affects WooCommerce PDF Invoice Builder: from n/a …

Jun 27, 2025
CVE-2025-53202
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows DOM-Based XSS.This issue affects Responsive Blocks: from n/a …

Jun 27, 2025
CVE-2025-53200
4.3 MEDIUM

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 6.7.3.

Jun 27, 2025
CVE-2025-53199
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Slider For Elementor ht-slider-for-elementor allows DOM-Based XSS.This issue affects HT …

Jun 27, 2025
CVE-2025-53197
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in cookiebot Cookiebot cookiebot allows Cross Site Request Forgery.This issue affects Cookiebot: from n/a through <= 4.5.8.

Jun 27, 2025
CVE-2025-53193
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Burst Statistics B.V. Burst Statistics burst-statistics allows Cross Site Request Forgery.This issue affects Burst Statistics: from n/a through <= …

Jun 27, 2025
CVE-2025-52993
5.6 MEDIUM

A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the …

Jun 27, 2025
CVE-2025-45729
6.3 MEDIUM

D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.

Jun 27, 2025
CVE-2025-44163
6.3 MEDIUM

RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in …

Jun 27, 2025
CVE-2025-6767
6.3 MEDIUM

A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. It has been rated as critical. This issue affects the function findDoctorByCondition of the file …

Jun 27, 2025
CVE-2025-6766
6.3 MEDIUM

A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. It has been declared as critical. This vulnerability affects the function getOfficeName of the file …

Jun 27, 2025
CVE-2025-40910
6.5 MEDIUM

Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control …

Jun 27, 2025
CVE-2025-6765
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of …

Jun 27, 2025
CVE-2025-6762
6.3 MEDIUM

A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the file /admin/login of the …

Jun 27, 2025
CVE-2025-32281
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite darkmysite allows Cross Site Request Forgery.This issue affects DarkMySite: from n/a through <= 1.2.8.

Jun 27, 2025
CVE-2025-5398
6.4 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of …

Jun 27, 2025
CVE-2025-6689
6.4 MEDIUM

The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3raccessibilitysuite shortcode in all versions up to, and including, …

Jun 27, 2025
CVE-2025-6550
6.4 MEDIUM

The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ parameter in all versions up to, and including, …

Jun 27, 2025
CVE-2025-5940
6.4 MEDIUM

The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter in all versions …

Jun 27, 2025
CVE-2025-5936
4.3 MEDIUM

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing …

Jun 27, 2025
CVE-2025-4587
6.4 MEDIUM

The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-testing-for-wp/ab-test-block' block in all versions up to, and …

Jun 27, 2025
CVE-2025-5526
4.3 MEDIUM

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another …

Jun 27, 2025
CVE-2025-5194
4.8 MEDIUM

The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting them back in a page/post …

Jun 27, 2025
CVE-2025-5093
5.4 MEDIUM

The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back …

Jun 27, 2025
CVE-2025-5035
5.4 MEDIUM

The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with …

Jun 27, 2025
CVE-2025-41418
5.3 MEDIUM

Buffer Overflow vulnerability exists in multiple versions of TB-eye network recorders and AHD recorders. The CGI process may be terminated abnormally by processing a specially …

Jun 27, 2025
CVE-2025-6753
6.3 MEDIUM

A vulnerability was found in huija bicycleSharingServer 1.0 and classified as critical. This issue affects the function selectAdminByNameLike of the file AdminController.java. The manipulation leads …

Jun 27, 2025
CVE-2025-6488
6.4 MEDIUM

The isMobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ parameter in all versions up to, and including, 1.1.1 due to …

Jun 27, 2025
CVE-2025-45737
6.5 MEDIUM

An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL commands to the NeacSafe64.sys …

Jun 27, 2025
CVE-2025-47822
6.4 MEDIUM

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.

Jun 27, 2025
CVE-2025-6749
6.3 MEDIUM

A vulnerability classified as critical was found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this vulnerability is the function searchAdminMessageShow of the file AdminController.java. …

Jun 27, 2025
CVE-2025-47819
6.4 MEDIUM

Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.

Jun 27, 2025
CVE-2025-6738
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this issue is the function userDao.selectUserByUserNameLike of …

Jun 27, 2025
CVE-2025-6736
6.3 MEDIUM

A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/install of the …

Jun 27, 2025
CVE-2025-6735
6.3 MEDIUM

A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Import …

Jun 27, 2025
CVE-2025-6731
6.3 MEDIUM

A vulnerability was found in yzcheng90 X-SpringBoot up to 5.0 and classified as critical. Affected by this issue is the function uploadApk of the file …

Jun 26, 2025
CVE-2025-5731
5.5 MEDIUM

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command …

Jun 26, 2025
CVE-2025-52555
6.5 MEDIUM

Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate …

Jun 26, 2025
CVE-2025-49592
4.6 MEDIUM

n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to …

Jun 26, 2025
CVE-2013-1424
5.6 MEDIUM

Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787.

Jun 26, 2025
CVE-2025-53013
5.2 MEDIUM

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a user to authenticate …

Jun 26, 2025
CVE-2025-6702
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment/post. The manipulation of …

Jun 26, 2025
CVE-2025-6700
4.3 MEDIUM

A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/login. The manipulation of the argument …

Jun 26, 2025
CVE-2025-51671
5.4 MEDIUM

A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code …

Jun 26, 2025
CVE-2025-50350
5.4 MEDIUM

PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php.

Jun 26, 2025
CVE-2025-44141
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

Jun 26, 2025
CVE-2025-36034
5.3 MEDIUM

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted …

Jun 26, 2025
CVE-2025-52900
5.5 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The …

Jun 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.