CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6236
4.8 MEDIUM

The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 10, 2025
CVE-2025-6234
6.1 MEDIUM

The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 10, 2025
CVE-2023-50458
3.5 LOW

In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

Jul 10, 2025
CVE-2025-53753

Rejected reason: Not used

Jul 10, 2025
CVE-2025-53752

Rejected reason: Not used

Jul 10, 2025
CVE-2025-53751

Rejected reason: Not used

Jul 10, 2025
CVE-2025-53750

Rejected reason: Not used

Jul 10, 2025
CVE-2025-53749

Rejected reason: Not used

Jul 10, 2025
CVE-2025-53748

Rejected reason: Not used

Jul 10, 2025
CVE-2025-53747

Rejected reason: Not used

Jul 10, 2025
CVE-2025-53746

Rejected reason: Not used

Jul 10, 2025
CVE-2025-46406
5.6 MEDIUM

A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform …

Jul 10, 2025
CVE-2025-44003
4.3 MEDIUM

Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with physical access to the reader to perform a …

Jul 10, 2025
CVE-2025-35983
6.5 MEDIUM

Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged …

Jul 10, 2025
CVE-2025-5807
6.1 MEDIUM

The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ parameter in all versions up to, and including, 4.9.2 due …

Jul 10, 2025
CVE-2025-4406
5.4 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due …

Jul 10, 2025
CVE-2025-6976
6.4 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions …

Jul 9, 2025
CVE-2025-6975
6.1 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions …

Jul 9, 2025
CVE-2025-6970
7.5 HIGH

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions …

Jul 9, 2025
CVE-2025-0646

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 9, 2025
CVE-2025-0141

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to …

Jul 9, 2025
CVE-2025-0140

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the …

Jul 9, 2025
CVE-2025-0139

An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate …

Jul 9, 2025
CVE-2024-10391

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 9, 2025
CVE-2025-6377
7.8 HIGH

A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries …

Jul 9, 2025
CVE-2025-6376
7.8 HIGH

A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries …

Jul 9, 2025
CVE-2025-53624
10.0 CRITICAL

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists versions prior to 4.0.0 are …

Jul 9, 2025
CVE-2025-52357
4.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firmware V2.2.14), allowing an authenticated attacker to execute arbitrary JavaScript code …

Jul 9, 2025
CVE-2025-53620

@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid …

Jul 9, 2025
CVE-2025-36599
4.3 MEDIUM

Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access …

Jul 9, 2025
CVE-2021-27961
6.5 MEDIUM

evesys 7.1 (2152) through 8.0 (2202) allows Reflected XSS via the indexeva.php action parameter.

Jul 9, 2025
CVE-2025-53548
7.5 HIGH

Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. …

Jul 9, 2025
CVE-2025-53645
7.5 HIGH

Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper …

Jul 9, 2025
CVE-2025-44525
6.5 MEDIUM

Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data …

Jul 9, 2025
CVE-2025-7381
5.3 MEDIUM

ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could exploit …

Jul 9, 2025
CVE-2025-53743
5.3 MEDIUM

Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to …

Jul 9, 2025
CVE-2025-53742
6.5 MEDIUM

Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed …

Jul 9, 2025
CVE-2025-53678
6.5 MEDIUM

Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, where it can …

Jul 9, 2025
CVE-2025-53677
5.3 MEDIUM

Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe …

Jul 9, 2025
CVE-2025-53676
6.5 MEDIUM

Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where it can be …

Jul 9, 2025
CVE-2025-53675
6.5 MEDIUM

Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users …

Jul 9, 2025
CVE-2025-53674
5.3 MEDIUM

Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for …

Jul 9, 2025
CVE-2025-53673
6.5 MEDIUM

Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where …

Jul 9, 2025
CVE-2025-53672
6.5 MEDIUM

Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where it can be …

Jul 9, 2025
CVE-2025-53671
6.5 MEDIUM

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the …

Jul 9, 2025
CVE-2025-53670
6.5 MEDIUM

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where …

Jul 9, 2025
CVE-2025-53669
4.3 MEDIUM

Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to …

Jul 9, 2025
CVE-2025-53668
6.5 MEDIUM

Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed …

Jul 9, 2025
CVE-2025-53667
5.3 MEDIUM

Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for attackers to …

Jul 9, 2025
CVE-2025-53666
6.5 MEDIUM

Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed …

Jul 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.