CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11517
7.5 HIGH

The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to …

Oct 18, 2025
CVE-2025-11510
4.3 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Oct 18, 2025
CVE-2025-11391
9.8 CRITICAL

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Oct 18, 2025
CVE-2025-11372
6.5 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is …

Oct 18, 2025
CVE-2025-11270
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute …

Oct 18, 2025
CVE-2025-10187
4.9 MEDIUM

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' parameter in all versions up …

Oct 18, 2025
CVE-2025-10006
6.4 MEDIUM

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, …

Oct 18, 2025
CVE-2025-11937

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - SecurePoll Extension allows Stored XSS.This issue …

Oct 18, 2025
CVE-2025-11857
6.4 MEDIUM

The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display_embed' shortcode in all versions up to, and including, 1.9.9. …

Oct 18, 2025
CVE-2025-11742
4.3 MEDIUM

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' …

Oct 18, 2025
CVE-2025-11738
5.3 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. …

Oct 18, 2025
CVE-2025-62671

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue …

Oct 18, 2025
CVE-2025-62670

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - FlexDiagrams Extension allows Stored XSS.This issue …

Oct 18, 2025
CVE-2025-62669

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects Mediawiki - …

Oct 18, 2025
CVE-2025-62668

Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Resource Leak Exposure.This issue affects Mediawiki - GrowthExperiments Extension: from master before …

Oct 18, 2025
CVE-2025-62667

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Stored XSS.This issue …

Oct 18, 2025
CVE-2025-62666

Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch Extension allows HTTP DoS.This issue affects Mediawiki - CirrusSearch Extension: …

Oct 18, 2025
CVE-2025-62664

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - ImageRating Extension allows Stored XSS.This issue …

Oct 18, 2025
CVE-2025-62663

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - UploadWizard Extension allows Stored XSS.This issue …

Oct 18, 2025
CVE-2025-62662

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - AdvancedSearch Extension allows Stored XSS.This issue …

Oct 18, 2025
CVE-2025-11361
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Oct 18, 2025
CVE-2025-62665

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Skin:BlueSky allows Stored XSS.This issue affects Mediawiki …

Oct 18, 2025
CVE-2025-11378
5.4 MEDIUM

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Oct 18, 2025
CVE-2020-36854
6.4 MEDIUM

The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization …

Oct 18, 2025
CVE-2020-36853
7.2 HIGH

The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient …

Oct 18, 2025
CVE-2017-20208
9.8 CRITICAL

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Oct 18, 2025
CVE-2017-20207
9.8 CRITICAL

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from …

Oct 18, 2025
CVE-2017-20206
9.8 CRITICAL

The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the …

Oct 18, 2025
CVE-2025-62640

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62639

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62638

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62637

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62636

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62635

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62634

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62633

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62632

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62655

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects …

Oct 17, 2025
CVE-2025-62654

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki QuizGame extension allows Stored XSS.This issue affects …

Oct 17, 2025
CVE-2025-62653

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PollNY extension allows Stored XSS.This issue affects …

Oct 17, 2025
CVE-2025-62652

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects …

Oct 17, 2025
CVE-2025-62651
6.5 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.

Oct 17, 2025
CVE-2025-62650
8.3 HIGH

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.

Oct 17, 2025
CVE-2025-62649
5.8 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders.

Oct 17, 2025
CVE-2025-62648
6.4 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.

Oct 17, 2025
CVE-2025-62647
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to …

Oct 17, 2025
CVE-2025-62646
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.

Oct 17, 2025
CVE-2025-62645
9.9 CRITICAL

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform …

Oct 17, 2025
CVE-2025-62644
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.

Oct 17, 2025
CVE-2025-62643
3.4 LOW

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.

Oct 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.