CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12611
8.8 HIGH

A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads …

Nov 3, 2025
CVE-2025-12610
4.7 MEDIUM

A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument …

Nov 3, 2025
CVE-2025-12609
4.7 MEDIUM

A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation …

Nov 3, 2025
CVE-2025-12608
7.3 HIGH

A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing …

Nov 3, 2025
CVE-2025-12607
7.3 HIGH

A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument …

Nov 3, 2025
CVE-2025-12606
7.3 HIGH

A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the …

Nov 3, 2025
CVE-2025-12605
7.3 HIGH

A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument …

Nov 2, 2025
CVE-2025-12604
7.3 HIGH

A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the …

Nov 2, 2025
CVE-2025-12598
4.7 MEDIUM

A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. …

Nov 2, 2025
CVE-2025-12597
4.7 MEDIUM

A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing …

Nov 2, 2025
CVE-2025-12596
8.8 HIGH

A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation of the argument Time …

Nov 2, 2025
CVE-2025-12595
8.8 HIGH

A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /goform/SetVirtualServerCfg. This manipulation of the argument list causes …

Nov 2, 2025
CVE-2025-12594
4.7 MEDIUM

A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown function of the file /admin/add_account.php. The manipulation …

Nov 2, 2025
CVE-2025-12593
4.7 MEDIUM

A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the …

Nov 2, 2025
CVE-2025-12603
9.8 CRITICAL

/etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Nov 1, 2025
CVE-2025-12602
9.8 CRITICAL

/etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Nov 1, 2025
CVE-2025-12601
7.5 HIGH

Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Nov 1, 2025
CVE-2025-12600
9.8 CRITICAL

Web UI Malfunction when setting unexpected locale via API.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Nov 1, 2025
CVE-2025-12599
9.8 CRITICAL

Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Nov 1, 2025
CVE-2025-36367
8.8 HIGH

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious …

Nov 1, 2025
CVE-2025-6990
8.8 HIGH

The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via the `TH_PhpCode` pagebuilder widget. This …

Nov 1, 2025
CVE-2025-6988
6.4 MEDIUM

The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 4.23.0 …

Nov 1, 2025
CVE-2025-6574
8.8 HIGH

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is …

Nov 1, 2025
CVE-2025-12171
8.8 HIGH

The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ingest_image() function in versions …

Nov 1, 2025
CVE-2025-12137
4.9 MEDIUM

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions …

Nov 1, 2025
CVE-2025-11755
8.8 HIGH

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when importing recipes via …

Nov 1, 2025
CVE-2025-11499
9.8 CRITICAL

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing …

Nov 1, 2025
CVE-2025-10487
7.3 HIGH

The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.12 …

Nov 1, 2025
CVE-2025-12180
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin …

Nov 1, 2025
CVE-2025-12090
6.4 MEDIUM

The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social URLs in …

Nov 1, 2025
CVE-2025-12038
4.3 MEDIUM

The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the /wp-json/folderly/v1/config/clear-all-data REST API endpoint in …

Nov 1, 2025
CVE-2025-11983
4.3 MEDIUM

The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9. This is due to the plugin …

Nov 1, 2025
CVE-2025-11740
6.5 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to …

Nov 1, 2025
CVE-2025-11502
6.4 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all …

Nov 1, 2025
CVE-2025-5949
8.8 HIGH

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is …

Nov 1, 2025
CVE-2025-12118
6.4 MEDIUM

The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.6.1 due …

Nov 1, 2025
CVE-2025-11995
7.2 HIGH

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due …

Nov 1, 2025
CVE-2025-11927
4.4 MEDIUM

The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in …

Nov 1, 2025
CVE-2025-11377
4.3 MEDIUM

The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.92.0 via the 'catlist' shortcode due …

Nov 1, 2025
CVE-2025-12367
4.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.3.1. This is due to the …

Nov 1, 2025
CVE-2025-11928
4.4 MEDIUM

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 …

Nov 1, 2025
CVE-2025-11833
9.8 CRITICAL

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data …

Nov 1, 2025
CVE-2025-62275
5.3 MEDIUM

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, …

Nov 1, 2025
CVE-2025-11922
6.4 MEDIUM

The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due …

Nov 1, 2025
CVE-2025-11920
8.8 HIGH

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in …

Nov 1, 2025
CVE-2025-11816
5.3 MEDIUM

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due …

Nov 1, 2025
CVE-2025-11174
5.3 MEDIUM

The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the …

Nov 1, 2025
CVE-2025-62276
5.5 MEDIUM

The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 …

Nov 1, 2025
CVE-2025-12464
6.2 MEDIUM

A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and …

Oct 31, 2025
CVE-2025-63563
6.5 MEDIUM

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker …

Oct 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.