CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13949
6.3 MEDIUM

A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.go. The manipulation of the argument File leads to …

Dec 3, 2025
CVE-2025-13948
5.6 MEDIUM

A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. …

Dec 3, 2025
CVE-2025-13756
4.3 MEDIUM

The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in …

Dec 3, 2025
CVE-2025-13401
6.4 MEDIUM

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, …

Dec 3, 2025
CVE-2025-13390
10.0 CRITICAL

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of …

Dec 3, 2025
CVE-2025-13359
6.5 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in …

Dec 3, 2025
CVE-2025-13354
4.3 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and …

Dec 3, 2025
CVE-2025-13342
9.8 CRITICAL

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. …

Dec 3, 2025
CVE-2025-13109
4.3 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Dec 3, 2025
CVE-2025-12887
5.4 MEDIUM

The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin …

Dec 3, 2025
CVE-2025-12358
4.3 MEDIUM

The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is …

Dec 3, 2025
CVE-2025-39665
5.3 MEDIUM

User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.

Dec 3, 2025
CVE-2025-13947
7.4 HIGH

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via …

Dec 3, 2025
CVE-2025-29864

Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 before 12.29.

Dec 3, 2025
CVE-2025-13472

A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like …

Dec 3, 2025
CVE-2025-12744
8.8 HIGH

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them …

Dec 3, 2025
CVE-2025-13946
5.5 MEDIUM

MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service

Dec 3, 2025
CVE-2025-13945
5.5 MEDIUM

HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

Dec 3, 2025
CVE-2025-13486
9.8 CRITICAL

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is …

Dec 3, 2025
CVE-2025-12954
2.7 LOW

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading …

Dec 3, 2025
CVE-2025-13495
4.9 MEDIUM

The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, and including, 1.3.1. This is due …

Dec 3, 2025
CVE-2025-12585
5.3 MEDIUM

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 via …

Dec 3, 2025
CVE-2025-10304
5.3 MEDIUM

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Dec 3, 2025
CVE-2025-13646
7.5 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions …

Dec 3, 2025
CVE-2025-13645
7.2 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions …

Dec 3, 2025
CVE-2025-13448
6.4 MEDIUM

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 …

Dec 3, 2025
CVE-2025-65955
4.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ …

Dec 2, 2025
CVE-2025-66476
7.8 HIGH

Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious …

Dec 2, 2025
CVE-2025-55181
5.3 MEDIUM

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends …

Dec 2, 2025
CVE-2025-65657
6.5 MEDIUM

FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files …

Dec 2, 2025
CVE-2025-65380
6.5 MEDIUM

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated …

Dec 2, 2025
CVE-2025-64778
7.3 HIGH

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application …

Dec 2, 2025
CVE-2025-64642
8.0 HIGH

NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations …

Dec 2, 2025
CVE-2025-64298
8.4 HIGH

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked …

Dec 2, 2025
CVE-2025-62575
8.3 HIGH

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the …

Dec 2, 2025
CVE-2025-61940
8.3 HIGH

NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application …

Dec 2, 2025
CVE-2025-65877
7.5 HIGH

Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 'title' parameter in com.wanli.lvzhoucms.service.ContentService#findPage. The parameter is concatenated directly into a dynamic …

Dec 2, 2025
CVE-2025-65379
6.5 MEDIUM

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is …

Dec 2, 2025
CVE-2025-13658

A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence of code signing …

Dec 2, 2025
CVE-2025-13542
9.8 CRITICAL

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' …

Dec 2, 2025
CVE-2025-13510

The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated users to access and modify critical …

Dec 2, 2025
CVE-2025-66468
7.6 HIGH

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript …

Dec 2, 2025
CVE-2025-66460
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66459
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66458
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66454
6.5 MEDIUM

Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret …

Dec 2, 2025
CVE-2025-66416
8.1 HIGH

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context …

Dec 2, 2025
CVE-2025-66414
8.1 HIGH

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK …

Dec 2, 2025
CVE-2025-66409
9.1 CRITICAL

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving …

Dec 2, 2025
CVE-2025-65896
9.8 CRITICAL

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

Dec 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.