CVE Database

58263+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58985
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects …

Sep 9, 2025
CVE-2025-58984
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a …

Sep 9, 2025
CVE-2025-58983
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Include Me include-me allows Stored XSS.This issue affects Include Me: from …

Sep 9, 2025
CVE-2025-58982
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline's Email Protector pixelines-email-protector allows Stored XSS.This issue affects Pixeline's Email Protector: …

Sep 9, 2025
CVE-2025-58981
5.4 MEDIUM

Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by …

Sep 9, 2025
CVE-2025-58980
5.3 MEDIUM

Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export WP Page …

Sep 9, 2025
CVE-2025-58979
5.3 MEDIUM

Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BerqWP: from n/a through <= 2.2.53.

Sep 9, 2025
CVE-2025-58978
5.3 MEDIUM

Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF Generator for WordPress: …

Sep 9, 2025
CVE-2025-58977
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Server Side Request Forgery.This issue affects WP eBay Product Feeds: from …

Sep 9, 2025
CVE-2025-58976
4.3 MEDIUM

Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by …

Sep 9, 2025
CVE-2025-58975
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: from n/a through <= 3.1.1.

Sep 9, 2025
CVE-2025-57540
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users …

Sep 9, 2025
CVE-2025-57539
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to …

Sep 9, 2025
CVE-2025-57538
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated …

Sep 9, 2025
CVE-2025-55226
6.7 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.

Sep 9, 2025
CVE-2025-55225
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-54917
4.3 MEDIUM

Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

Sep 9, 2025
CVE-2025-54915
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-54901
5.5 MEDIUM

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 9, 2025
CVE-2025-54252
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Sep 9, 2025
CVE-2025-54251
4.3 MEDIUM

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker …

Sep 9, 2025
CVE-2025-54250
4.9 MEDIUM

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privileged …

Sep 9, 2025
CVE-2025-54249
6.5 MEDIUM

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A …

Sep 9, 2025
CVE-2025-54247
6.5 MEDIUM

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged …

Sep 9, 2025
CVE-2025-54246
6.5 MEDIUM

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker …

Sep 9, 2025
CVE-2025-54109
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-54107
4.3 MEDIUM

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

Sep 9, 2025
CVE-2025-54104
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-54101
4.8 MEDIUM

Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.

Sep 9, 2025
CVE-2025-54097
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-54096
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-54095
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-54094
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53810
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53809
6.5 MEDIUM

Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

Sep 9, 2025
CVE-2025-53808
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53806
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-53804
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Sep 9, 2025
CVE-2025-53803
5.5 MEDIUM

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Sep 9, 2025
CVE-2025-53799
5.5 MEDIUM

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

Sep 9, 2025
CVE-2025-53798
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-53797
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-53796
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-53348
5.3 MEDIUM

Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalium: from n/a through <= 3.18.3.

Sep 9, 2025
CVE-2025-53340
5.3 MEDIUM

Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6.

Sep 9, 2025
CVE-2025-53291
5.4 MEDIUM

Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a through <= 2.1.5.

Sep 9, 2025
CVE-2025-49860
5.3 MEDIUM

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0.

Sep 9, 2025
CVE-2025-47997
6.5 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-47437
6.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 7.0.1.

Sep 9, 2025
CVE-2025-39553
4.3 MEDIUM

Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 5.0.9.

Sep 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.