CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36750
5.4 MEDIUM

ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page …

Dec 13, 2025
CVE-2025-36748
5.4 MEDIUM

ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication …

Dec 13, 2025
CVE-2025-36747
9.8 CRITICAL

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the …

Dec 13, 2025
CVE-2025-14620
7.3 HIGH

A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/login_query.php. Executing manipulation …

Dec 13, 2025
CVE-2025-14619
7.3 HIGH

A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login_query.php. Performing manipulation …

Dec 13, 2025
CVE-2025-14617
5.3 MEDIUM

A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown function of the component org.jw.jwlibrary.mobile.activity.SiloContainer. …

Dec 13, 2025
CVE-2025-14607
6.3 MEDIUM

A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicomByteString of the file dcmdata/libsrc/dcbytstr.cc of the component …

Dec 13, 2025
CVE-2025-14606
5.0 MEDIUM

A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the function pickle.loads of the file pickle_convert.go …

Dec 13, 2025
CVE-2025-14590
7.3 HIGH

A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown function of the file /admin/search1.php. The manipulation of the …

Dec 13, 2025
CVE-2025-14589
6.3 MEDIUM

A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing a manipulation of …

Dec 13, 2025
CVE-2025-14588
7.3 HIGH

A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /update_program.php. Performing manipulation of the …

Dec 13, 2025
CVE-2025-14587
7.3 HIGH

A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of the file /pet1/available.php. Such manipulation of the …

Dec 13, 2025
CVE-2025-14586
6.3 MEDIUM

A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument …

Dec 13, 2025
CVE-2025-14581
4.3 MEDIUM

The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'submit_form_reply' AJAX …

Dec 13, 2025
CVE-2025-14542
7.5 HIGH

The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endpoint. While a provider may initially …

Dec 13, 2025
CVE-2025-14540
4.3 MEDIUM

The Userback plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the userback_get_json function in all versions …

Dec 13, 2025
CVE-2025-14539
5.4 MEDIUM

The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to …

Dec 13, 2025
CVE-2025-14508
6.5 MEDIUM

The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check …

Dec 13, 2025
CVE-2025-14477
4.9 MEDIUM

The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to insufficient escaping on the …

Dec 13, 2025
CVE-2025-14476
8.8 HIGH

The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Dec 13, 2025
CVE-2025-14475
8.1 HIGH

The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.1 …

Dec 13, 2025
CVE-2025-14462
4.3 MEDIUM

The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to …

Dec 13, 2025
CVE-2025-14454
4.3 MEDIUM

The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 13, 2025
CVE-2025-14451
4.7 MEDIUM

The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0. This is due to insufficient …

Dec 13, 2025
CVE-2025-14447
4.3 MEDIUM

The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the annfu_reset_options() function in all …

Dec 13, 2025
CVE-2025-14446
5.4 MEDIUM

The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the easynotify_cp_reset() …

Dec 13, 2025
CVE-2025-14440
9.8 CRITICAL

The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect …

Dec 13, 2025
CVE-2025-14397
8.8 HIGH

The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to a missing capability check on the postem_ipsum_generate_users() …

Dec 13, 2025
CVE-2025-14395
4.3 MEDIUM

The Popover Windows plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple ajax actions (e.g., pop_submit, …

Dec 13, 2025
CVE-2025-14394
4.3 MEDIUM

The Popover Windows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2. This is due to missing or …

Dec 13, 2025
CVE-2025-14378
4.4 MEDIUM

The Quick Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1 due to …

Dec 13, 2025
CVE-2025-14367
5.3 MEDIUM

The Easy Theme Options plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0. This is due to missing …

Dec 13, 2025
CVE-2025-14366
5.3 MEDIUM

The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing …

Dec 13, 2025
CVE-2025-14365
5.3 MEDIUM

The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.0.1. This is due to missing …

Dec 13, 2025
CVE-2025-14288
4.3 MEDIUM

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to …

Dec 13, 2025
CVE-2025-14278
6.4 MEDIUM

The HT Slider for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_title' parameter in all versions up to, and including, …

Dec 13, 2025
CVE-2025-14056
4.4 MEDIUM

The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter during custom post type import in all …

Dec 13, 2025
CVE-2025-14050
4.9 MEDIUM

The Design Import/Export plugin for WordPress is vulnerable to SQL Injection via XML File Import in all versions up to, and including, 2.2 due to …

Dec 13, 2025
CVE-2025-13705
6.4 MEDIUM

The Custom Frames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'customframe' shortcode in all versions up to, …

Dec 13, 2025
CVE-2025-13403
4.3 MEDIUM

The Employee Spotlight – Team Member Showcase & Meet the Team Plugin for WordPress is vulnerable to unauthorized tracking settings modification due to missing authorization …

Dec 13, 2025
CVE-2025-13094
8.8 HIGH

The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in …

Dec 13, 2025
CVE-2025-13093
5.3 MEDIUM

The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Dec 13, 2025
CVE-2025-13092
5.3 MEDIUM

The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Dec 13, 2025
CVE-2025-13089
7.5 HIGH

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' parameter in all versions up to, and …

Dec 13, 2025
CVE-2025-13077
7.5 HIGH

The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'columns' parameter …

Dec 13, 2025
CVE-2025-12512
4.3 MEDIUM

The GenerateBlocks plugin for WordPress is vulnerable to information exposure due to missing object-level authorization checks in versions up to, and including, 2.1.2. This is …

Dec 13, 2025
CVE-2025-12362
5.3 MEDIUM

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, …

Dec 13, 2025
CVE-2025-12109
6.4 MEDIUM

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the script …

Dec 13, 2025
CVE-2025-12077
6.1 MEDIUM

The WP to LinkedIn Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.9.8 …

Dec 13, 2025
CVE-2025-12076
6.1 MEDIUM

The Social Media Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage parameter in all versions up to, and including, 3.6.5 …

Dec 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.