CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11610
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown processing of the file /brand.php. The manipulation of …

Oct 11, 2025
CVE-2025-11609
3.7 LOW

A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument …

Oct 11, 2025
CVE-2025-11608
7.3 HIGH

A security vulnerability has been detected in code-projects E-Banking System 1.0. This affects an unknown function of the file /register.php of the component POST Parameter …

Oct 11, 2025
CVE-2025-11607
6.3 MEDIUM

A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the component …

Oct 11, 2025
CVE-2025-11606
6.3 MEDIUM

A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The affected element is an unknown function of the component Search. …

Oct 11, 2025
CVE-2025-11605
6.3 MEDIUM

A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/update-profile.php. Such manipulation of the argument uid …

Oct 11, 2025
CVE-2025-11604
7.3 HIGH

A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the …

Oct 11, 2025
CVE-2025-11603
6.3 MEDIUM

A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /editproduct.php. The manipulation of the argument …

Oct 11, 2025
CVE-2025-11601
7.3 HIGH

A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing manipulation …

Oct 11, 2025
CVE-2025-11600
6.3 MEDIUM

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file editcategory.php. Such manipulation of …

Oct 11, 2025
CVE-2025-11599
7.3 HIGH

A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown function of the file /forgot-password.php. This manipulation of …

Oct 11, 2025
CVE-2025-11597
6.3 MEDIUM

A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of the file /pages/product_add_qty.php. The manipulation of the argument …

Oct 11, 2025
CVE-2025-9975
6.8 MEDIUM

The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.8.1 via the wp_scraper_extract_content function. This …

Oct 11, 2025
CVE-2025-9950
4.9 MEDIUM

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwr_get_file …

Oct 11, 2025
CVE-2025-9947
4.9 MEDIUM

The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versions up to, and including, 3.12.0 …

Oct 11, 2025
CVE-2025-9626
4.3 MEDIUM

The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing …

Oct 11, 2025
CVE-2025-9621
4.3 MEDIUM

The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.1. This is due to …

Oct 11, 2025
CVE-2025-8682
4.3 MEDIUM

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up …

Oct 11, 2025
CVE-2025-8606
2.4 LOW

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due …

Oct 11, 2025
CVE-2025-8593
8.8 HIGH

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to …

Oct 11, 2025
CVE-2025-8484
5.3 MEDIUM

The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files. This makes it …

Oct 11, 2025
CVE-2025-7652
6.4 MEDIUM

The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-6439
9.8 CRITICAL

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion …

Oct 11, 2025
CVE-2025-58301
6.2 MEDIUM

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58300
6.2 MEDIUM

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58293
5.5 MEDIUM

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58289
5.9 MEDIUM

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-11596
7.3 HIGH

A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of the file /pages/delete_order_details.php. Executing manipulation of the argument …

Oct 11, 2025
CVE-2025-11595
4.7 MEDIUM

A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing a manipulation of …

Oct 11, 2025
CVE-2025-10376
4.3 MEDIUM

The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4. This is due …

Oct 11, 2025
CVE-2025-10375
4.3 MEDIUM

The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10. This is due …

Oct 11, 2025
CVE-2025-10190
6.4 MEDIUM

The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-10175
6.5 MEDIUM

The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due …

Oct 11, 2025
CVE-2025-10167
6.4 MEDIUM

The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_stock_snapshot_restocked shortcode in all versions …

Oct 11, 2025
CVE-2025-10129
6.4 MEDIUM

The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up …

Oct 11, 2025
CVE-2025-6553
9.8 CRITICAL

The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout() function in all …

Oct 11, 2025
CVE-2025-58299
8.4 HIGH

Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58298
7.3 HIGH

Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58297
5.9 MEDIUM

Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58295
5.9 MEDIUM

Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58292
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58291
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58290
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58288
5.5 MEDIUM

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58287
7.8 HIGH

Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58286
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-11594
5.3 MEDIUM

A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file …

Oct 11, 2025
CVE-2025-11518
5.3 MEDIUM

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via …

Oct 11, 2025
CVE-2025-11254
4.3 MEDIUM

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, …

Oct 11, 2025
CVE-2025-11167
4.7 MEDIUM

The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, …

Oct 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.