CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-14649
7.3 HIGH

A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown functionality of the file /cakeshop/supplier.php. Performing manipulation …

Dec 14, 2025
CVE-2025-14648
4.7 MEDIUM

A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/catalog_add.php. Such manipulation …

Dec 14, 2025
CVE-2025-14647
7.3 HIGH

A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument …

Dec 14, 2025
CVE-2025-14646
7.3 HIGH

A security flaw has been discovered in code-projects Student File Management System 1.0. This impacts an unknown function of the file /admin/delete_student.php. The manipulation of …

Dec 14, 2025
CVE-2025-14645
7.3 HIGH

A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of the file /admin/delete_user.php. The manipulation of the argument …

Dec 14, 2025
CVE-2025-12696
5.3 MEDIUM

The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset …

Dec 14, 2025
CVE-2025-12537
6.4 MEDIUM

The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.14.3. This is due …

Dec 14, 2025
CVE-2025-67897
5.3 MEDIUM

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash …

Dec 14, 2025
CVE-2025-13126
7.5 HIGH

The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, …

Dec 14, 2025
CVE-2025-67896
7.0 HIGH

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

Dec 14, 2025
CVE-2025-14644
7.3 HIGH

A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /update_subject.php. Executing manipulation of the …

Dec 14, 2025
CVE-2025-14643
7.3 HIGH

A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown function of the file /check.php. Performing manipulation of …

Dec 14, 2025
CVE-2025-14642
4.7 MEDIUM

A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument …

Dec 14, 2025
CVE-2025-14641
4.7 MEDIUM

A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the …

Dec 14, 2025
CVE-2025-14640
7.3 HIGH

A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /admin/save_student.php. Executing manipulation …

Dec 14, 2025
CVE-2025-14639
7.3 HIGH

A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /uprec.php. Performing manipulation of the argument ID …

Dec 14, 2025
CVE-2025-14638
7.3 HIGH

A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects some unknown processing of the file /pet1/update_cnp.php. Such …

Dec 14, 2025
CVE-2025-13832

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 13, 2025
CVE-2025-14637
7.3 HIGH

A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of …

Dec 13, 2025
CVE-2025-14636
3.7 LOW

A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of …

Dec 13, 2025
CVE-2025-14623
7.3 HIGH

A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown processing of the file /admin/update_student.php. This manipulation of …

Dec 13, 2025
CVE-2025-14622
7.3 HIGH

A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.php. The manipulation of …

Dec 13, 2025
CVE-2025-14621
7.3 HIGH

A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipulation of the argument …

Dec 13, 2025
CVE-2025-9873
6.4 MEDIUM

The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.5 due to insufficient input …

Dec 13, 2025
CVE-2025-9856
6.4 MEDIUM

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode …

Dec 13, 2025
CVE-2025-9488
6.4 MEDIUM

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due …

Dec 13, 2025
CVE-2025-9218
3.7 LOW

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when …

Dec 13, 2025
CVE-2025-9207
5.3 MEDIUM

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the …

Dec 13, 2025
CVE-2025-9116
5.8 MEDIUM

The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Dec 13, 2025
CVE-2025-8780
6.4 MEDIUM

The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero Header and Pricing Table widgets in all versions …

Dec 13, 2025
CVE-2025-8779
6.4 MEDIUM

The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Team and Countdown widgets in all …

Dec 13, 2025
CVE-2025-8687
6.4 MEDIUM

The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image Comparison widgets in all versions up to, …

Dec 13, 2025
CVE-2025-8617
6.4 MEDIUM

The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_quick_view shortcode in all versions up to, and …

Dec 13, 2025
CVE-2025-8199
6.4 MEDIUM

The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee widget in all versions up to, and including, 2.4.3 …

Dec 13, 2025
CVE-2025-8195
6.4 MEDIUM

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison and Subscribe widgets in all versions up …

Dec 13, 2025
CVE-2025-7960
6.4 MEDIUM

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets …

Dec 13, 2025
CVE-2025-7058
6.4 MEDIUM

The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.1.9 due to …

Dec 13, 2025
CVE-2025-67871

Rejected reason: Not used

Dec 13, 2025
CVE-2025-67870

Rejected reason: Not used

Dec 13, 2025
CVE-2025-67869

Rejected reason: Not used

Dec 13, 2025
CVE-2025-67868

Rejected reason: Not used

Dec 13, 2025
CVE-2025-67867

Rejected reason: Not used

Dec 13, 2025
CVE-2025-67866

Rejected reason: Not used

Dec 13, 2025
CVE-2025-67865

Rejected reason: Not used

Dec 13, 2025
CVE-2025-67864

Rejected reason: Not used

Dec 13, 2025
CVE-2025-67863

Rejected reason: Not used

Dec 13, 2025
CVE-2025-36754

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings …

Dec 13, 2025
CVE-2025-36753
9.8 CRITICAL

The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and …

Dec 13, 2025
CVE-2025-36752
9.8 CRITICAL

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the device, such as allowing any attacker …

Dec 13, 2025
CVE-2025-36751

Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to the network to intercept and …

Dec 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.