CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12217
9.1 CRITICAL

SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 25, 2025
CVE-2025-12216
5.5 MEDIUM

Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 25, 2025
CVE-2025-11897
6.4 MEDIUM

The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ the7_fancy_title_css’ parameter in all …

Oct 25, 2025
CVE-2025-9322
7.5 HIGH

The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is vulnerable to SQL Injection via …

Oct 25, 2025
CVE-2025-8483
6.3 MEDIUM

The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.5.5. …

Oct 25, 2025
CVE-2025-8416
7.5 HIGH

The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in all versions up to, and including, 2.9.7. …

Oct 25, 2025
CVE-2025-4203
7.5 HIGH

The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, …

Oct 25, 2025
CVE-2025-12034
4.4 MEDIUM

The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.5.1 due …

Oct 25, 2025
CVE-2025-11976
4.3 MEDIUM

The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to Cross-Site Request …

Oct 25, 2025
CVE-2025-11893
6.5 MEDIUM

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to SQL Injection via the donation_ids …

Oct 25, 2025
CVE-2025-11875
6.4 MEDIUM

The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spendeonline' shortcode in all versions up to, and including, 3.0.1 due …

Oct 25, 2025
CVE-2025-11497
4.3 MEDIUM

The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to …

Oct 25, 2025
CVE-2025-11255
4.3 MEDIUM

The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Oct 25, 2025
CVE-2025-10637
5.3 MEDIUM

The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the …

Oct 25, 2025
CVE-2025-10580
6.4 MEDIUM

The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple functions in …

Oct 25, 2025
CVE-2025-10488
8.1 HIGH

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation …

Oct 25, 2025
CVE-2025-8666
6.4 MEDIUM

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions less than, or equal to, 11.6.2 …

Oct 25, 2025
CVE-2025-8588
6.4 MEDIUM

The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Marker Title' and 'Marker Description' parameters for the …

Oct 25, 2025
CVE-2025-8413
6.4 MEDIUM

The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in version less than, or equal to, 2.0.8 due …

Oct 25, 2025
CVE-2025-6680
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Oct 25, 2025
CVE-2025-6639
5.4 MEDIUM

The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Oct 25, 2025
CVE-2025-12095
8.8 HIGH

The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.8. This is due …

Oct 25, 2025
CVE-2025-12005
4.3 MEDIUM

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized access of data in all …

Oct 25, 2025
CVE-2025-11888
2.7 LOW

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an …

Oct 25, 2025
CVE-2025-11879
6.5 MEDIUM

The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_option_rest' function in all versions …

Oct 25, 2025
CVE-2025-11564
5.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Oct 25, 2025
CVE-2025-11269
5.3 MEDIUM

The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'approveNotice' action …

Oct 25, 2025
CVE-2025-11244
3.7 LOW

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is …

Oct 25, 2025
CVE-2025-11238
7.2 HIGH

The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions less than, or equal to, 3.4.4 …

Oct 25, 2025
CVE-2025-10737
6.4 MEDIUM

The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, …

Oct 25, 2025
CVE-2025-10694
5.3 MEDIUM

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due …

Oct 25, 2025
CVE-2025-11823
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Oct 25, 2025
CVE-2025-10579
5.3 MEDIUM

The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Oct 25, 2025
CVE-2025-11760
5.3 MEDIUM

The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all …

Oct 25, 2025
CVE-2025-34503

Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the …

Oct 24, 2025
CVE-2025-34502

Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. Without cryptographic boot verification, an attacker with …

Oct 24, 2025
CVE-2025-34500

Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses …

Oct 24, 2025
CVE-2025-12194

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy …

Oct 24, 2025
CVE-2025-62711
3.1 LOW

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug …

Oct 24, 2025
CVE-2025-4106

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by …

Oct 24, 2025
CVE-2025-34293

GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to the API's object endpoints …

Oct 24, 2025
CVE-2025-62723
4.3 MEDIUM

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. …

Oct 24, 2025
CVE-2025-62717
9.1 CRITICAL

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing …

Oct 24, 2025
CVE-2025-60954
8.3 HIGH

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak …

Oct 24, 2025
CVE-2025-52099

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-29088. Reason: This record is a duplicate of CVE-2025-29088. Notes: All CVE users should reference CVE-2025-29088 …

Oct 24, 2025
CVE-2025-62716
8.1 HIGH

Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to supply arbitrary schemes …

Oct 24, 2025
CVE-2025-60419
6.2 MEDIUM

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the …

Oct 24, 2025
CVE-2025-60735
7.6 HIGH

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function

Oct 24, 2025
CVE-2025-60731
7.6 HIGH

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

Oct 24, 2025
CVE-2025-60730
7.6 HIGH

PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function

Oct 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.