CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9496
6.4 MEDIUM

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-9196
5.3 MEDIUM

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Oct 11, 2025
CVE-2025-11533
9.8 CRITICAL

The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_register() …

Oct 11, 2025
CVE-2025-11197
6.4 MEDIUM

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 …

Oct 11, 2025
CVE-2025-10185
4.9 MEDIUM

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in …

Oct 11, 2025
CVE-2025-10048
4.9 MEDIUM

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due …

Oct 11, 2025
CVE-2025-11593
6.3 MEDIUM

A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument …

Oct 11, 2025
CVE-2025-11592
6.3 MEDIUM

A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edit-equipmentform.php. The manipulation of the argument ID …

Oct 11, 2025
CVE-2025-11591
6.3 MEDIUM

A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The …

Oct 11, 2025
CVE-2025-58285
5.3 MEDIUM

Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58284
5.9 MEDIUM

Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58283
5.5 MEDIUM

Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58282
2.8 LOW

Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58278
6.2 MEDIUM

Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58277
4.0 MEDIUM

Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-9560
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-11380
5.9 MEDIUM

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a …

Oct 11, 2025
CVE-2025-54654
6.2 MEDIUM

Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality

Oct 11, 2025
CVE-2025-31718
7.5 HIGH

In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of privilege with no additional execution …

Oct 11, 2025
CVE-2025-31717
7.5 HIGH

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

Oct 11, 2025
CVE-2025-11590
6.3 MEDIUM

A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing a …

Oct 11, 2025
CVE-2025-9554
5.3 MEDIUM

Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*.

Oct 10, 2025
CVE-2025-9553
5.3 MEDIUM

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

Oct 10, 2025
CVE-2025-9552
5.3 MEDIUM

Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*.

Oct 10, 2025
CVE-2025-9551
6.5 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, from 7.X-1.0 before …

Oct 10, 2025
CVE-2025-9550
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.10, …

Oct 10, 2025
CVE-2025-9549
6.5 MEDIUM

Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.

Oct 10, 2025
CVE-2025-8093
8.8 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.

Oct 10, 2025
CVE-2025-62162
7.5 HIGH

cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.11.4, parsing certain malformed CEL expressions can …

Oct 10, 2025
CVE-2025-62159

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider …

Oct 10, 2025
CVE-2025-52885

Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior …

Oct 10, 2025
CVE-2025-52647
6.1 MEDIUM

The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks.

Oct 10, 2025
CVE-2025-11626
5.5 MEDIUM

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

Oct 10, 2025
CVE-2025-61912
5.3 MEDIUM

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash …

Oct 10, 2025
CVE-2025-61911
6.5 MEDIUM

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to …

Oct 10, 2025
CVE-2025-11589
6.3 MEDIUM

A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/user-payment.php. Performing a manipulation of …

Oct 10, 2025
CVE-2025-11588
6.3 MEDIUM

A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /customer/index.php. Such manipulation of the argument fullname …

Oct 10, 2025
CVE-2025-11586
8.8 HIGH

A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based …

Oct 10, 2025
CVE-2025-11585
7.3 HIGH

A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the …

Oct 10, 2025
CVE-2025-11584
7.3 HIGH

A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation …

Oct 10, 2025
CVE-2025-62245
4.3 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update …

Oct 10, 2025
CVE-2025-62158
5.3 MEDIUM

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by …

Oct 10, 2025
CVE-2025-61930
8.1 HIGH

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change …

Oct 10, 2025
CVE-2025-61929
9.6 CRITICAL

Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation …

Oct 10, 2025
CVE-2025-61927

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower contains a security vulnerability that …

Oct 10, 2025
CVE-2025-61925
6.5 MEDIUM

Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any validation. It is …

Oct 10, 2025
CVE-2025-61921
7.5 HIGH

Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the …

Oct 10, 2025
CVE-2025-61920
7.5 HIGH

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature …

Oct 10, 2025
CVE-2025-61919
7.5 HIGH

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: …

Oct 10, 2025
CVE-2025-55903
8.3 HIGH

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate …

Oct 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.