CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8690
6.4 MEDIUM

The Simple Responsive Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0 due to insufficient input …

Aug 12, 2025
CVE-2025-8688
6.4 MEDIUM

The Inline Stock Quotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock shortcode in all versions up to, and including, …

Aug 12, 2025
CVE-2025-8685
6.4 MEDIUM

The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortcode in all versions up to, and including, …

Aug 12, 2025
CVE-2025-8621
6.4 MEDIUM

The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all versions up to, and including, 1.0.5 due …

Aug 12, 2025
CVE-2025-8568
6.4 MEDIUM

The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all versions up to, and including, 1.1 due …

Aug 12, 2025
CVE-2025-8462
6.4 MEDIUM

The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the social URL parameter in all …

Aug 12, 2025
CVE-2025-4390
5.3 MEDIUM

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' …

Aug 12, 2025
CVE-2025-42975
6.1 MEDIUM

SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds …

Aug 12, 2025
CVE-2025-42949
4.9 MEDIUM

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging …

Aug 12, 2025
CVE-2025-42948
6.1 MEDIUM

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. …

Aug 12, 2025
CVE-2025-42946
6.9 MEDIUM

Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in …

Aug 12, 2025
CVE-2025-42945
6.1 MEDIUM

SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick …

Aug 12, 2025
CVE-2025-42943
4.5 MEDIUM

SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, …

Aug 12, 2025
CVE-2025-42942
6.1 MEDIUM

SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and …

Aug 12, 2025
CVE-2025-42936
5.4 MEDIUM

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users …

Aug 12, 2025
CVE-2025-42935
4.1 MEDIUM

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files …

Aug 12, 2025
CVE-2025-42934
4.3 MEDIUM

SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted …

Aug 12, 2025
CVE-2025-8285
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper …

Aug 11, 2025
CVE-2025-7677
5.9 MEDIUM

A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue …

Aug 11, 2025
CVE-2025-54463
5.9 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint …

Aug 11, 2025
CVE-2025-54458
5.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for …

Aug 11, 2025
CVE-2025-53910
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without …

Aug 11, 2025
CVE-2025-53514
5.9 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint …

Aug 11, 2025
CVE-2025-51824
6.5 MEDIUM

libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.

Aug 11, 2025
CVE-2025-51823
6.5 MEDIUM

libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function uses strcpy to copy …

Aug 11, 2025
CVE-2025-48731
6.4 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for …

Aug 11, 2025
CVE-2025-44001
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without …

Aug 11, 2025
CVE-2025-25229
5.4 MEDIUM

Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system …

Aug 11, 2025
CVE-2025-38499
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is …

Aug 11, 2025
CVE-2025-8859
6.3 MEDIUM

A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File …

Aug 11, 2025
CVE-2025-8852
4.3 MEDIUM

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation …

Aug 11, 2025
CVE-2025-8851
5.3 MEDIUM

A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. …

Aug 11, 2025
CVE-2025-8846
5.3 MEDIUM

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer …

Aug 11, 2025
CVE-2025-8845
5.3 MEDIUM

A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer …

Aug 11, 2025
CVE-2025-8843
5.3 MEDIUM

A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. …

Aug 11, 2025
CVE-2025-8842
5.3 MEDIUM

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads …

Aug 11, 2025
CVE-2025-8841
6.3 MEDIUM

A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads …

Aug 11, 2025
CVE-2025-8840
5.4 MEDIUM

A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of …

Aug 11, 2025
CVE-2025-8839
6.3 MEDIUM

A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation …

Aug 11, 2025
CVE-2025-8837
5.3 MEDIUM

A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The …

Aug 11, 2025
CVE-2025-8661
6.1 MEDIUM

A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user.

Aug 11, 2025
CVE-2025-7965
4.3 MEDIUM

The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Aug 11, 2025
CVE-2025-8830
6.3 MEDIUM

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function sub_3517C …

Aug 11, 2025
CVE-2025-8829
6.3 MEDIUM

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of …

Aug 11, 2025
CVE-2025-8828
6.3 MEDIUM

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function ipv6cmd of the file /goform/setIpv6. …

Aug 11, 2025
CVE-2025-8827
6.3 MEDIUM

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function um_inspect_cross_band of the file …

Aug 11, 2025
CVE-2025-8825
6.3 MEDIUM

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto of the file /goform/RP_setBasicAuto. …

Aug 11, 2025
CVE-2025-8823
6.3 MEDIUM

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setDeviceName of …

Aug 11, 2025
CVE-2025-8821
6.3 MEDIUM

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function RP_setBasic of the file …

Aug 11, 2025
CVE-2025-8818
6.3 MEDIUM

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setDFSSetting …

Aug 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.