CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-14390
8.8 HIGH

The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to missing or incorrect nonce validation …

Dec 10, 2025
CVE-2025-9315

An unauthenticated device registration vulnerability, caused by Improperly Controlled Modification of Dynamically-Determined Object Attributes, has been identified in the MXsecurity Series. An unauthenticated remote attacker …

Dec 10, 2025
CVE-2025-66004
5.7 MEDIUM

A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba.

Dec 10, 2025
CVE-2025-1161
7.1 HIGH

Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem allows Privilege Escalation.This issue affects Nomysem: through May 2025.

Dec 10, 2025
CVE-2025-14087
5.6 MEDIUM

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or …

Dec 10, 2025
CVE-2025-14082
2.7 LOW

A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks …

Dec 10, 2025
CVE-2025-13955

Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II version 1.17478.146 allows attackers in Wi-Fi range to gain access to the dongle …

Dec 10, 2025
CVE-2025-13954

Hard-coded cryptographic keys in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin …

Dec 10, 2025
CVE-2025-12952

A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook editor permission are able to configure Webhooks using Dialogflow service …

Dec 10, 2025
CVE-2025-9571

A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can …

Dec 10, 2025
CVE-2025-13073
7.1 HIGH

The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading …

Dec 10, 2025
CVE-2025-13072
7.1 HIGH

The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading …

Dec 10, 2025
CVE-2025-13339
7.5 HIGH

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() …

Dec 10, 2025
CVE-2025-9056
5.3 MEDIUM

Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.

Dec 10, 2025
CVE-2025-67613

Rejected reason: Not used

Dec 10, 2025
CVE-2025-67612

Rejected reason: Not used

Dec 10, 2025
CVE-2025-67611

Rejected reason: Not used

Dec 10, 2025
CVE-2025-67610

Rejected reason: Not used

Dec 10, 2025
CVE-2025-67609

Rejected reason: Not used

Dec 10, 2025
CVE-2025-67608

Rejected reason: Not used

Dec 10, 2025
CVE-2025-67607

Rejected reason: Not used

Dec 10, 2025
CVE-2025-67606

Rejected reason: Not used

Dec 10, 2025
CVE-2025-67605

Rejected reason: Not used

Dec 10, 2025
CVE-2025-13677
4.9 MEDIUM

The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.2. This is due to insufficient …

Dec 10, 2025
CVE-2025-13613
9.8 CRITICAL

The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin …

Dec 10, 2025
CVE-2025-67507
8.1 HIGH

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for …

Dec 10, 2025
CVE-2025-67506
9.8 CRITICAL

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The …

Dec 10, 2025
CVE-2025-67485
5.3 MEDIUM

mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers …

Dec 10, 2025
CVE-2025-67503

Rejected reason: This CVE is a duplicate of another CVE.

Dec 10, 2025
CVE-2025-67502
5.4 MEDIUM

Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites …

Dec 10, 2025
CVE-2025-67501
8.8 HIGH

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain an SQL Injection vulnerability …

Dec 10, 2025
CVE-2025-67500
3.7 LOW

Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have …

Dec 10, 2025
CVE-2025-67499
6.6 MEDIUM

The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all …

Dec 10, 2025
CVE-2025-64898
4.3 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker …

Dec 10, 2025
CVE-2025-64897
5.6 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass …

Dec 10, 2025
CVE-2025-61823
6.2 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary …

Dec 10, 2025
CVE-2025-61822
6.2 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker …

Dec 10, 2025
CVE-2025-61821
6.8 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary …

Dec 10, 2025
CVE-2025-61813
8.2 HIGH

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary …

Dec 10, 2025
CVE-2025-61812
8.4 HIGH

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary …

Dec 10, 2025
CVE-2025-61811
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2025
CVE-2025-61810
8.4 HIGH

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the …

Dec 10, 2025
CVE-2025-61809
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker …

Dec 10, 2025
CVE-2025-61808
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code …

Dec 10, 2025
CVE-2025-67498

Rejected reason: Further research determined the issue is not a vulnerability.

Dec 9, 2025
CVE-2025-67497

Rejected reason: Further research determined the issue is not a vulnerability.

Dec 9, 2025
CVE-2025-67496
4.3 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting …

Dec 9, 2025
CVE-2025-67495
8.0 HIGH

ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint …

Dec 9, 2025
CVE-2025-13760

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 9, 2025
CVE-2025-67494
9.3 CRITICAL

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats …

Dec 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.