CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8149
6.4 MEDIUM

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and …

Sep 6, 2025
CVE-2025-7045
6.5 MEDIUM

The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the …

Sep 6, 2025
CVE-2025-7040
8.2 HIGH

The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings' action of …

Sep 6, 2025
CVE-2025-9853
6.4 MEDIUM

The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.2 …

Sep 6, 2025
CVE-2025-9515
7.2 HIGH

The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all …

Sep 6, 2025
CVE-2025-9085
4.9 MEDIUM

The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient …

Sep 6, 2025
CVE-2025-8360
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets in all versions up …

Sep 6, 2025
CVE-2025-8359
9.8 CRITICAL

The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not …

Sep 6, 2025
CVE-2025-58912

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58911

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58910

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58909

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58908

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58907

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58906

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58905

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58904

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58437
8.1 HIGH

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session …

Sep 6, 2025
CVE-2025-58374
7.8 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that …

Sep 6, 2025
CVE-2025-10003
6.5 MEDIUM

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection …

Sep 6, 2025
CVE-2025-9849
6.4 MEDIUM

The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_btn' shortcode in all versions up to, and …

Sep 6, 2025
CVE-2025-7368
5.3 MEDIUM

The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Sep 6, 2025
CVE-2025-7366
7.3 HIGH

The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Sep 6, 2025
CVE-2025-6067
6.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Sep 6, 2025
CVE-2025-58439
8.1 HIGH

ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left …

Sep 6, 2025
CVE-2025-58375

Rejected reason: This CVE is a duplicate of another CVE.

Sep 6, 2025
CVE-2021-26383
7.9 HIGH

Insufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a command with malformed arguments leading …

Sep 6, 2025
CVE-2025-58373
5.5 MEDIUM

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be …

Sep 5, 2025
CVE-2025-58372
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace …

Sep 5, 2025
CVE-2025-58371
9.8 CRITICAL

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request …

Sep 5, 2025
CVE-2025-58370
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where …

Sep 5, 2025
CVE-2025-58369
5.3 MEDIUM

fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, and 3.13.0-M1 through 3.13.0-M6 are vulnerable to …

Sep 5, 2025
CVE-2025-58367

DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnerable to class pollution via the …

Sep 5, 2025
CVE-2025-58366

Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) …

Sep 5, 2025
CVE-2025-57807
3.8 LOW

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing …

Sep 5, 2025
CVE-2025-10027
3.5 LOW

A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This …

Sep 5, 2025
CVE-2025-53791
4.7 MEDIUM

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Sep 5, 2025
CVE-2025-10061
6.5 MEDIUM

An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect handling …

Sep 5, 2025
CVE-2025-10060
6.5 MEDIUM

MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. …

Sep 5, 2025
CVE-2025-10059
6.5 MEDIUM

An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument …

Sep 5, 2025
CVE-2025-9566
8.1 HIGH

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete …

Sep 5, 2025
CVE-2025-10044
4.3 MEDIUM

A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered …

Sep 5, 2025
CVE-2025-10043

Rejected reason: Considered by the maintainers a bug scenario experienced rather than a vulnerability.

Sep 5, 2025
CVE-2025-10026
3.5 LOW

A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The …

Sep 5, 2025
CVE-2025-10025
7.3 HIGH

A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument …

Sep 5, 2025
CVE-2025-9057
6.4 MEDIUM

The Biagiotti Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.1.3 due to insufficient input …

Sep 5, 2025
CVE-2025-9709

On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform …

Sep 5, 2025
CVE-2025-39726
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management in ism_cmd() The s390x ISM device data sheet clearly states that …

Sep 5, 2025
CVE-2025-39725
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list In shrink_folio_list(), the hwpoisoned folio may be …

Sep 5, 2025
CVE-2025-39724
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: fix panic due to PSLVERR When the PSLVERR_RESP_EN parameter is set to 1, …

Sep 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.