CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8118
6.5 MEDIUM

PAD CMS implements weak client-side brute-force protection by utilizing two cookies: login_count and login_timeout. Information about attempt count or timeout is not stored on the …

Sep 30, 2025
CVE-2025-8117
7.5 HIGH

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This …

Sep 30, 2025
CVE-2025-8116
6.1 MEDIUM

PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbitrary …

Sep 30, 2025
CVE-2025-7065
9.8 CRITICAL

Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without …

Sep 30, 2025
CVE-2025-7063
9.8 CRITICAL

Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without …

Sep 30, 2025
CVE-2025-7052
8.8 HIGH

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce …

Sep 30, 2025
CVE-2025-7038
8.2 HIGH

The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the latepoint_route_call AJAX endpoint in …

Sep 30, 2025
CVE-2025-6941
6.4 MEDIUM

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the …

Sep 30, 2025
CVE-2025-6815
5.5 MEDIUM

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘service[name]’ parameter in all …

Sep 30, 2025
CVE-2025-61633

Rejected reason: Not used

Sep 30, 2025
CVE-2025-61632

Rejected reason: Not used

Sep 30, 2025
CVE-2025-61631

Rejected reason: Not used

Sep 30, 2025
CVE-2025-61630

Rejected reason: Not used

Sep 30, 2025
CVE-2025-61629

Rejected reason: Not used

Sep 30, 2025
CVE-2025-61628

Rejected reason: Not used

Sep 30, 2025
CVE-2025-61627

Rejected reason: Not used

Sep 30, 2025
CVE-2025-61626

Rejected reason: Not used

Sep 30, 2025
CVE-2025-61584

serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the …

Sep 30, 2025
CVE-2025-59956
6.5 MEDIUM

AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding …

Sep 30, 2025
CVE-2025-59954
9.8 CRITICAL

Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext …

Sep 30, 2025
CVE-2025-59668
7.5 HIGH

Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafted certain UDP packet, the affected device may abnormally terminate.

Sep 30, 2025
CVE-2025-41099
6.5 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, …

Sep 30, 2025
CVE-2025-41098
7.5 HIGH

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a misuse of the general enquiry web service.

Sep 30, 2025
CVE-2025-41097
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, …

Sep 30, 2025
CVE-2025-41096
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, …

Sep 30, 2025
CVE-2025-41095
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, …

Sep 30, 2025
CVE-2025-41094
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, …

Sep 30, 2025
CVE-2025-41093
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, …

Sep 30, 2025
CVE-2025-41092
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, …

Sep 30, 2025
CVE-2025-41091
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, …

Sep 30, 2025
CVE-2025-11163
4.3 MEDIUM

The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Sep 30, 2025
CVE-2025-11149
7.5 HIGH

This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes …

Sep 30, 2025
CVE-2025-11148
9.8 CRITICAL

All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted with locally, or via CI, to …

Sep 30, 2025
CVE-2025-10991

The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have the physical access to the …

Sep 30, 2025
CVE-2025-10196
6.4 MEDIUM

The Survey Anyplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'surveyanyplace_embed' shortcode in all versions up to, and including, 1.0.0 …

Sep 30, 2025
CVE-2025-10191
6.4 MEDIUM

The Big Post Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wooboigpost_shipping_status' shortcode in all versions up to, …

Sep 30, 2025
CVE-2025-10189
6.4 MEDIUM

The BP Direct Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bpdm_login' shortcode in all versions up to, and including, …

Sep 30, 2025
CVE-2025-10182
6.4 MEDIUM

The dbview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dbview' shortcode in all versions up to, and including, 0.5.5 due …

Sep 30, 2025
CVE-2025-10179
6.4 MEDIUM

The My AskAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'myaskai' shortcode in all versions up to, and including, 1.0.0 …

Sep 30, 2025
CVE-2025-10168
6.4 MEDIUM

The Any News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'any-ticker' shortcode in all versions up to, and including, …

Sep 30, 2025
CVE-2025-10131
6.4 MEDIUM

The All Social Share Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sc' shortcode in all versions up to, and …

Sep 30, 2025
CVE-2025-10130
6.4 MEDIUM

The Layers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up to, and including, 0.5 due …

Sep 30, 2025
CVE-2025-10128
6.4 MEDIUM

The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' shortcode in all versions up to, and including, …

Sep 30, 2025
CVE-2025-10000
6.4 MEDIUM

The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Sep 30, 2025
CVE-2024-58040
9.1 CRITICAL

Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.

Sep 30, 2025
CVE-2025-61586
5.3 MEDIUM

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, allowing attackers to …

Sep 30, 2025
CVE-2025-59952

MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. …

Sep 30, 2025
CVE-2025-59950
6.7 MEDIUM

FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible …

Sep 30, 2025
CVE-2025-59948
6.7 MEDIUM

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not sanitize certain event handler attributes in feed content, so by finding a …

Sep 29, 2025
CVE-2025-59942
7.5 HIGH

go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it validates a "poison" messages causing …

Sep 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.