CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-41347
9.8 CRITICAL

Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending …

Nov 18, 2025
CVE-2025-11427
5.8 MEDIUM

The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and …

Nov 18, 2025
CVE-2025-4212
7.2 HIGH

The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, …

Nov 18, 2025
CVE-2025-41346
9.8 CRITICAL

Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning …

Nov 18, 2025
CVE-2025-13196
5.4 MEDIUM

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in …

Nov 18, 2025
CVE-2025-13133
6.6 MEDIUM

The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' …

Nov 18, 2025
CVE-2025-13069
8.8 HIGH

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This …

Nov 18, 2025
CVE-2025-12955
7.5 HIGH

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due …

Nov 18, 2025
CVE-2025-12691
6.4 MEDIUM

The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox functionality in …

Nov 18, 2025
CVE-2025-12639
4.3 MEDIUM

The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, …

Nov 18, 2025
CVE-2025-12481
4.3 MEDIUM

The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the …

Nov 18, 2025
CVE-2025-12457
6.4 MEDIUM

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, …

Nov 18, 2025
CVE-2025-12392
5.3 MEDIUM

The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_optin_optout' …

Nov 18, 2025
CVE-2025-12391
5.3 MEDIUM

The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout() function in …

Nov 18, 2025
CVE-2025-12088
6.4 MEDIUM

The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in all versions up to, and including, …

Nov 18, 2025
CVE-2025-12079
6.1 MEDIUM

The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.7.4 due …

Nov 18, 2025
CVE-2025-11734
5.4 MEDIUM

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modification due to missing …

Nov 18, 2025
CVE-2025-9625
4.3 MEDIUM

The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to …

Nov 18, 2025
CVE-2025-8609
6.4 MEDIUM

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion Block's attributes in all versions up to, …

Nov 18, 2025
CVE-2025-8605
6.4 MEDIUM

The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in …

Nov 18, 2025
CVE-2025-40549
9.1 CRITICAL

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute …

Nov 18, 2025
CVE-2025-40548
9.1 CRITICAL

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. …

Nov 18, 2025
CVE-2025-40547
9.1 CRITICAL

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. …

Nov 18, 2025
CVE-2025-40545
4.8 MEDIUM

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect …

Nov 18, 2025
CVE-2025-26391
5.4 MEDIUM

SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a …

Nov 18, 2025
CVE-2025-13088
8.8 HIGH

The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0. This is …

Nov 18, 2025
CVE-2025-12962
6.4 MEDIUM

The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5a via the `url` parameter in …

Nov 18, 2025
CVE-2025-12961
4.3 MEDIUM

The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability check on the 'wp_ajax_save_settings' AJAX action in all …

Nov 18, 2025
CVE-2025-12937
6.5 MEDIUM

The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'acf_flm_update_template_with_pasted_layout' function …

Nov 18, 2025
CVE-2025-12827
4.3 MEDIUM

The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing …

Nov 18, 2025
CVE-2025-12823
6.4 MEDIUM

The CSV to SortTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csv' shortcode in all versions up to, and including, 4.2 …

Nov 18, 2025
CVE-2025-12775
8.8 HIGH

The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 1.1.0 via the `ajax_upload_handle` function. …

Nov 18, 2025
CVE-2025-12528
8.1 HIGH

The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic …

Nov 18, 2025
CVE-2025-12411
7.1 HIGH

The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' parameter in versions up to, and including, 1.1.10. …

Nov 18, 2025
CVE-2025-12406
6.1 MEDIUM

The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is …

Nov 18, 2025
CVE-2025-12404
6.1 MEDIUM

The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or …

Nov 18, 2025
CVE-2025-12372
4.3 MEDIUM

The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.2. This is due to the plugin …

Nov 18, 2025
CVE-2025-12173
4.3 MEDIUM

The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to …

Nov 18, 2025
CVE-2025-12078
6.1 MEDIUM

The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, …

Nov 18, 2025
CVE-2025-11868
6.4 MEDIUM

The everviz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `everviz` shortcode attributes in versions up to, and including, 1.1. This is …

Nov 18, 2025
CVE-2025-11620
7.2 HIGH

The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mrpu_add_multiple_roles_ui' and …

Nov 18, 2025
CVE-2025-8727
7.2 HIGH

There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a …

Nov 18, 2025
CVE-2025-8404
5.5 MEDIUM

Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted …

Nov 18, 2025
CVE-2025-8076
7.2 HIGH

There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a …

Nov 18, 2025
CVE-2025-11267
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, …

Nov 18, 2025
CVE-2025-11265
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions …

Nov 18, 2025
CVE-2025-10089
7.7 HIGH

Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, …

Nov 18, 2025
CVE-2025-7623
5.4 MEDIUM

Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted …

Nov 18, 2025
CVE-2025-12524
5.4 MEDIUM

The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.0 due to missing validation …

Nov 18, 2025
CVE-2025-48593
8.0 HIGH

In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with …

Nov 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.