CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62955
4.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool [Show Current Template Info] current-template-name allows Retrieve Embedded Sensitive Data.This issue …

Dec 21, 2025
CVE-2025-14995
8.8 HIGH

A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads …

Dec 21, 2025
CVE-2025-14994
8.8 HIGH

A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the file /goform/webtypelibrary of the component HTTP Request …

Dec 21, 2025
CVE-2025-14855
7.2 HIGH

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due …

Dec 21, 2025
CVE-2025-14800
8.1 HIGH

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function …

Dec 21, 2025
CVE-2025-14993
8.8 HIGH

A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation …

Dec 21, 2025
CVE-2025-9343
7.2 HIGH

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, …

Dec 21, 2025
CVE-2025-68644
7.4 HIGH

Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security …

Dec 21, 2025
CVE-2025-14992
8.8 HIGH

A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the file /goform/GetParentControlInfo of the component HTTP …

Dec 21, 2025
CVE-2025-14991
2.4 LOW

A weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/bwdates-reports-details.php. …

Dec 21, 2025
CVE-2025-14990
7.3 HIGH

A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing …

Dec 21, 2025
CVE-2025-13693
6.4 MEDIUM

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom scripts' setting in all versions up …

Dec 21, 2025
CVE-2025-13361
4.3 MEDIUM

The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due …

Dec 21, 2025
CVE-2025-13220
6.4 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Dec 21, 2025
CVE-2025-12654
2.7 LOW

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, …

Dec 21, 2025
CVE-2025-12398
6.1 MEDIUM

The Product Table for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_key' parameter in all versions up to, and including, …

Dec 21, 2025
CVE-2025-14080
5.3 MEDIUM

The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.5. This is due …

Dec 21, 2025
CVE-2025-14071
7.5 HIGH

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 …

Dec 21, 2025
CVE-2025-14054
4.4 MEDIUM

The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'heading_color' parameter (and multiple other …

Dec 21, 2025
CVE-2025-14043
5.3 MEDIUM

The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. …

Dec 21, 2025
CVE-2025-13838
6.4 MEDIUM

The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the 'wishsuite_button' shortcode in all versions up to, and …

Dec 21, 2025
CVE-2025-12980
7.5 HIGH

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access of data due to a …

Dec 21, 2025
CVE-2025-11496
6.1 MEDIUM

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions …

Dec 21, 2025
CVE-2023-47232
4.3 MEDIUM

Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.

Dec 21, 2025
CVE-2023-25446
7.7 HIGH

Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.

Dec 21, 2025
CVE-2023-25445
5.4 MEDIUM

Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.

Dec 21, 2025
CVE-2025-14989
7.3 HIGH

A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/search-invoices.php. Such manipulation …

Dec 21, 2025
CVE-2023-25068
4.3 MEDIUM

Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Edge: from n/a through 1.13.

Dec 21, 2025
CVE-2025-14597

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 20, 2025
CVE-2025-12700

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 20, 2025
CVE-2025-34290

Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client …

Dec 20, 2025
CVE-2025-7782
7.6 HIGH

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on …

Dec 20, 2025
CVE-2025-7733
4.3 MEDIUM

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Dec 20, 2025
CVE-2025-14298
5.4 MEDIUM

The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up …

Dec 20, 2025
CVE-2025-12492
5.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Dec 20, 2025
CVE-2025-13619
9.8 CRITICAL

The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the …

Dec 20, 2025
CVE-2025-12820
5.3 MEDIUM

The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its settings, which could allow any authenticated users …

Dec 20, 2025
CVE-2025-14735
4.4 MEDIUM

The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 …

Dec 20, 2025
CVE-2025-14734
5.4 MEDIUM

The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due …

Dec 20, 2025
CVE-2025-14721
5.5 MEDIUM

The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSlider shortcode in all versions up to, and …

Dec 20, 2025
CVE-2025-14633
5.3 MEDIUM

The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'file_download' function …

Dec 20, 2025
CVE-2025-14591
7.5 HIGH

In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited …

Dec 20, 2025
CVE-2025-14168
4.3 MEDIUM

The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to …

Dec 20, 2025
CVE-2025-14164
4.3 MEDIUM

The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing …

Dec 20, 2025
CVE-2025-13624
6.1 MEDIUM

The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.1 …

Dec 20, 2025
CVE-2025-13365
6.1 MEDIUM

The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to …

Dec 20, 2025
CVE-2025-13329
9.8 CRITICAL

The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for …

Dec 20, 2025
CVE-2025-12898
5.3 MEDIUM

The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pgcal_ajax_handler() function in …

Dec 20, 2025
CVE-2025-12581
6.1 MEDIUM

The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 1.1.7 due to insufficient …

Dec 20, 2025
CVE-2025-8065
6.5 MEDIUM

A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with …

Dec 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.