CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-14565
7.3 HIGH

A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/SProfile/login1.php. Such manipulation of the …

Dec 12, 2025
CVE-2025-13733
7.8 HIGH

BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2.

Dec 12, 2025
CVE-2025-12843
5.5 MEDIUM

Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.

Dec 12, 2025
CVE-2025-58770
8.8 HIGH

APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this …

Dec 12, 2025
CVE-2025-54981
7.5 HIGH

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including …

Dec 12, 2025
CVE-2025-54947
9.8 CRITICAL

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, …

Dec 12, 2025
CVE-2025-36755

The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the …

Dec 12, 2025
CVE-2025-36746
5.4 MEDIUM

SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a …

Dec 12, 2025
CVE-2025-36745
7.8 HIGH

SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws …

Dec 12, 2025
CVE-2025-36744
2.4 LOW

SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits …

Dec 12, 2025
CVE-2025-36743
6.8 MEDIUM

SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of system internals and execution of debug commands.

Dec 12, 2025
CVE-2025-13506
8.8 HIGH

Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allows Expanding Control over the Operating System from the …

Dec 12, 2025
CVE-2025-14442
5.3 MEDIUM

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in …

Dec 12, 2025
CVE-2025-14159
4.3 MEDIUM

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. …

Dec 12, 2025
CVE-2025-14065
4.3 MEDIUM

The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'simpbire_carica_prenotazioni' AJAX action …

Dec 12, 2025
CVE-2025-14030
6.4 MEDIUM

The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all versions up to, and including, 1.0.22 due …

Dec 12, 2025
CVE-2025-12965
6.4 MEDIUM

The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' parameter in the Magical Posts Accordion widget in all …

Dec 12, 2025
CVE-2025-12408
5.3 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 …

Dec 12, 2025
CVE-2025-12407
4.3 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 12, 2025
CVE-2025-12841
5.3 MEDIUM

The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.

Dec 12, 2025
CVE-2025-12835
7.3 HIGH

The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any authenticated users, such as subscriber to …

Dec 12, 2025
CVE-2025-58137
8.1 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are …

Dec 12, 2025
CVE-2025-58130
9.1 CRITICAL

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to …

Dec 12, 2025
CVE-2025-26866
8.8 HIGH

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication …

Dec 12, 2025
CVE-2025-23408
6.5 MEDIUM

Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to …

Dec 12, 2025
CVE-2025-14074
4.3 MEDIUM

The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post duplication due to a missing …

Dec 12, 2025
CVE-2025-13993
5.5 MEDIUM

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_description' and 'success_message' parameters in versions up to, …

Dec 12, 2025
CVE-2025-12348
5.3 MEDIUM

The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.9.10. …

Dec 12, 2025
CVE-2025-40829
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT …

Dec 12, 2025
CVE-2025-12960
6.5 MEDIUM

The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.1 via the `href` parameter in …

Dec 12, 2025
CVE-2025-67731
7.5 HIGH

Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Express server used …

Dec 12, 2025
CVE-2025-67730
5.4 MEDIUM

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious …

Dec 12, 2025
CVE-2025-4970
5.5 MEDIUM

The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.7.1 …

Dec 12, 2025
CVE-2025-14169
7.5 HIGH

The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'opid' parameter in all versions …

Dec 12, 2025
CVE-2025-14049
6.1 MEDIUM

The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'delto' parameter in all versions up to, and …

Dec 12, 2025
CVE-2025-13891
6.5 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. …

Dec 12, 2025
CVE-2025-11876
6.4 MEDIUM

The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_subscription_form' shortcode in all versions up to, and including, 1.3.1 …

Dec 12, 2025
CVE-2025-10583
3.5 LOW

The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.4 via the 'get_server_time_ajax_request' …

Dec 12, 2025
CVE-2025-67737
3.1 LOW

AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint that is intended for internal use by the SFTP …

Dec 12, 2025
CVE-2025-67728
9.8 CRITICAL

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, …

Dec 12, 2025
CVE-2025-67727
9.8 CRITICAL

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI …

Dec 12, 2025
CVE-2025-67726
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, …

Dec 12, 2025
CVE-2025-14356
4.3 MEDIUM

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Dec 12, 2025
CVE-2025-14068
7.5 HIGH

The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions up to, and including, 0.6.3 due to …

Dec 12, 2025
CVE-2025-13660
5.3 MEDIUM

The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. This is due to the plugin …

Dec 12, 2025
CVE-2025-12655
5.3 MEDIUM

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, …

Dec 12, 2025
CVE-2025-12570
7.2 HIGH

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 …

Dec 12, 2025
CVE-2025-67725
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's …

Dec 12, 2025
CVE-2025-67724
5.4 MEDIUM

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers …

Dec 12, 2025
CVE-2025-67508
8.4 HIGH

gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells such as Fish …

Dec 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.