CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-53733

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_u32: Undo tcf_bind_filter if u32_replace_hw_knode When u32_replace_hw_knode fails, we need to undo the …

Oct 24, 2025
CVE-2025-5605
4.3 MEDIUM

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request …

Oct 24, 2025
CVE-2025-5350
5.9 MEDIUM

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted …

Oct 24, 2025
CVE-2025-36361
6.3 MEDIUM

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due …

Oct 24, 2025
CVE-2025-12136
6.8 MEDIUM

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, …

Oct 24, 2025
CVE-2025-12134
5.3 MEDIUM

The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to unauthorized modification of data …

Oct 24, 2025
CVE-2025-10680
8.8 HIGH

OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use

Oct 24, 2025
CVE-2025-12096
6.4 MEDIUM

The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricelist' shortcode in all versions up to, and …

Oct 24, 2025
CVE-2025-12072
4.3 MEDIUM

The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This …

Oct 24, 2025
CVE-2025-12028
8.8 HIGH

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce …

Oct 24, 2025
CVE-2025-12017
6.1 MEDIUM

The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 1.0.0 …

Oct 24, 2025
CVE-2025-12016
4.4 MEDIUM

The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' parameter in all versions up to, and including, 1.0.0 due to …

Oct 24, 2025
CVE-2025-12014
4.3 MEDIUM

The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nginxcacheoptimizer-blacklist-update' AJAX action …

Oct 24, 2025
CVE-2025-11992
6.1 MEDIUM

The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due …

Oct 24, 2025
CVE-2025-11889
7.2 HIGH

The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Oct 24, 2025
CVE-2025-11887
4.3 MEDIUM

The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX functions in all versions …

Oct 24, 2025
CVE-2025-11504
7.5 HIGH

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This …

Oct 24, 2025
CVE-2025-11257
4.3 MEDIUM

The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_save_blogs' AJAX …

Oct 24, 2025
CVE-2025-11253
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aksis Technology Inc. Netty ERP allows SQL Injection.This issue affects Netty …

Oct 24, 2025
CVE-2025-11172
4.3 MEDIUM

The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the chk_plag_mine_plugin_wpse10500_admin_action() function in all …

Oct 24, 2025
CVE-2025-10902
4.3 MEDIUM

The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ai_scan_result_remove' function in …

Oct 24, 2025
CVE-2025-10901
4.3 MEDIUM

The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ai_get_table' function in …

Oct 24, 2025
CVE-2025-10749
5.4 MEDIUM

The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in all versions up to, and including, 4.5.1. This …

Oct 24, 2025
CVE-2025-10748
6.5 MEDIUM

The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and including, 1.2. This is due …

Oct 24, 2025
CVE-2025-10740
6.3 MEDIUM

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missing capability …

Oct 24, 2025
CVE-2025-10701
6.4 MEDIUM

The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in …

Oct 24, 2025
CVE-2025-6440
9.8 CRITICAL

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads …

Oct 24, 2025
CVE-2025-62868
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local File Inclusion.This issue …

Oct 24, 2025
CVE-2025-9978
6.8 MEDIUM

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting …

Oct 24, 2025
CVE-2025-9158

The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability …

Oct 24, 2025
CVE-2025-61931
5.4 MEDIUM

Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attacker to execute an arbitrary script in a logged-in user's …

Oct 24, 2025
CVE-2025-58070
6.1 MEDIUM

Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to execute an arbitrary script in a logged-in user's web …

Oct 24, 2025
CVE-2025-10874
5.5 MEDIUM

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may …

Oct 24, 2025
CVE-2025-10723
2.7 LOW

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to …

Oct 24, 2025
CVE-2025-62835

Rejected reason: Not used

Oct 24, 2025
CVE-2025-62834

Rejected reason: Not used

Oct 24, 2025
CVE-2025-62833

Rejected reason: Not used

Oct 24, 2025
CVE-2025-62832

Rejected reason: Not used

Oct 24, 2025
CVE-2025-62831

Rejected reason: Not used

Oct 24, 2025
CVE-2025-62830

Rejected reason: Not used

Oct 24, 2025
CVE-2025-62829

Rejected reason: Not used

Oct 24, 2025
CVE-2025-62828

Rejected reason: Not used

Oct 24, 2025
CVE-2025-62827

Rejected reason: Not used

Oct 24, 2025
CVE-2025-7730
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 …

Oct 23, 2025
CVE-2025-62254
7.5 HIGH

The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update …

Oct 23, 2025
CVE-2025-60023
4.0 MEDIUM

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-59776
4.0 MEDIUM

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-58429
7.5 HIGH

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-62688
7.1 HIGH

An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials …

Oct 23, 2025
CVE-2025-62498
8.8 HIGH

A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity …

Oct 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.