CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13960
6.4 MEDIUM

The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in all versions up to, and including, 1.3 due …

Dec 12, 2025
CVE-2025-13906
6.4 MEDIUM

The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in all versions up to, and including, 0.2.2 …

Dec 12, 2025
CVE-2025-13904
6.4 MEDIUM

The WPGancio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gancio-event' shortcode in all versions up to, and including, 1.12 due …

Dec 12, 2025
CVE-2025-13889
6.4 MEDIUM

The Simple Nivo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode parameter in all versions up to, and including, …

Dec 12, 2025
CVE-2025-13885
6.4 MEDIUM

The Zenost Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' and 'target' parameters in the `button` shortcode in all versions …

Dec 12, 2025
CVE-2025-13884
6.4 MEDIUM

The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter in the `bg-hide-email-address` shortcode in all versions up …

Dec 12, 2025
CVE-2025-13866
6.4 MEDIUM

The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flow_flow_social_auth AJAX …

Dec 12, 2025
CVE-2025-13850
6.4 MEDIUM

The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'map_type' parameter in all versions up to, and including, …

Dec 12, 2025
CVE-2025-13846
6.4 MEDIUM

The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and including, 3.0.2 …

Dec 12, 2025
CVE-2025-13843
6.4 MEDIUM

The VigLink SpotLight By ShortCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'float' parameter of the 'spotlight' shortcode in all versions …

Dec 12, 2025
CVE-2025-13840
6.4 MEDIUM

The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter of the 'bukazu_search' shortcode in all versions up …

Dec 12, 2025
CVE-2025-13747
6.4 MEDIUM

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, …

Dec 12, 2025
CVE-2025-13440
5.3 MEDIUM

The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to …

Dec 12, 2025
CVE-2025-13408
4.3 MEDIUM

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Dec 12, 2025
CVE-2025-13366
4.3 MEDIUM

The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing …

Dec 12, 2025
CVE-2025-13363
4.3 MEDIUM

The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing …

Dec 12, 2025
CVE-2025-13334
8.1 HIGH

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" …

Dec 12, 2025
CVE-2025-13320
6.8 MEDIUM

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to …

Dec 12, 2025
CVE-2025-13314
5.3 MEDIUM

The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable to unauthorized modification of data in all …

Dec 12, 2025
CVE-2025-12968
8.8 HIGH

The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up …

Dec 12, 2025
CVE-2025-12963
9.8 CRITICAL

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in …

Dec 12, 2025
CVE-2025-12883
5.3 MEDIUM

The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2.2. This is due …

Dec 12, 2025
CVE-2025-12834
6.1 MEDIUM

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failure_message' parameter in versions up to, …

Dec 12, 2025
CVE-2025-12830
6.4 MEDIUM

The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in all versions up to, and including, 1.5.5 …

Dec 12, 2025
CVE-2025-12824
8.8 HIGH

The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderboard' shortcode. This …

Dec 12, 2025
CVE-2025-12783
4.3 MEDIUM

The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveBrandsSettings function …

Dec 12, 2025
CVE-2025-12650
6.4 MEDIUM

The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter in the postlist shortcode in all versions up …

Dec 12, 2025
CVE-2025-13886
7.5 HIGH

The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 via the 'template' parameter in …

Dec 12, 2025
CVE-2025-13839
6.4 MEDIUM

The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' shortcode in all versions up to, and …

Dec 12, 2025
CVE-2025-13670
6.7 MEDIUM

The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability

Dec 12, 2025
CVE-2025-13669
6.7 MEDIUM

Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 …

Dec 12, 2025
CVE-2025-13665
6.7 MEDIUM

The System Console Utility for Windows is vulnerable to a DLL planting vulnerability

Dec 12, 2025
CVE-2025-13053
3.7 LOW

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to …

Dec 12, 2025
CVE-2025-13052
5.9 MEDIUM

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who …

Dec 12, 2025
CVE-2025-10451
8.2 HIGH

Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.

Dec 12, 2025
CVE-2025-67779
7.5 HIGH

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a …

Dec 12, 2025
CVE-2025-67780
4.2 MEDIUM

SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2. The cross-origin policy can …

Dec 11, 2025
CVE-2025-66452
6.1 MEDIUM

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing errors; SyntaxError from express.json() includes …

Dec 11, 2025
CVE-2025-66451
6.5 MEDIUM

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modify the …

Dec 11, 2025
CVE-2025-66450
5.4 MEDIUM

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the iconURL parameter of the POST …

Dec 11, 2025
CVE-2025-66446
8.8 HIGH

MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker …

Dec 11, 2025
CVE-2025-66419
8.8 HIGH

MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and …

Dec 11, 2025
CVE-2025-64721
10.0 CRITICAL

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the SYSTEM-level service SbieSvc.exe exposes SbieIniServer::RC4Crypt …

Dec 11, 2025
CVE-2025-34506
8.8 HIGH

WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially …

Dec 11, 2025
CVE-2025-34504
6.1 MEDIUM

KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs …

Dec 11, 2025
CVE-2025-34499

AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can …

Dec 11, 2025
CVE-2025-13668
6.7 MEDIUM

A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.

Dec 11, 2025
CVE-2024-58313
7.2 HIGH

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting …

Dec 11, 2025
CVE-2024-58312
7.5 HIGH

xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal …

Dec 11, 2025
CVE-2024-58310

APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can …

Dec 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.