CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-65082
6.5 MEDIUM

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated …

Dec 5, 2025
CVE-2025-13620
5.3 MEDIUM

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is …

Dec 5, 2025
CVE-2025-13739
6.4 MEDIUM

The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all versions up to, and including, 4.0.5 due …

Dec 5, 2025
CVE-2025-13682
4.4 MEDIUM

The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to …

Dec 5, 2025
CVE-2025-13678
6.4 MEDIUM

The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcode in all versions up to, and including, 2.5. …

Dec 5, 2025
CVE-2025-12876
5.3 MEDIUM

The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pto_delete_file …

Dec 5, 2025
CVE-2025-13684
4.3 MEDIUM

The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to missing or incorrect nonce validation …

Dec 5, 2025
CVE-2025-12130
4.3 MEDIUM

The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Dec 5, 2025
CVE-2025-13515
6.1 MEDIUM

The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.0.1.3 due …

Dec 5, 2025
CVE-2025-12373
4.3 MEDIUM

The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Dec 5, 2025
CVE-2025-12355
5.3 MEDIUM

The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_update_order_status' AJAX endpoint in all …

Dec 5, 2025
CVE-2025-12354
4.3 MEDIUM

The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_frontend_save' AJAX endpoint …

Dec 5, 2025
CVE-2025-12186
4.4 MEDIUM

The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to …

Dec 5, 2025
CVE-2025-12093
5.3 MEDIUM

The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions …

Dec 5, 2025
CVE-2025-66270
4.7 MEDIUM

The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect …

Dec 5, 2025
CVE-2025-32900
4.3 MEDIUM

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP …

Dec 5, 2025
CVE-2025-13860
6.4 MEDIUM

The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter in all versions up to, and including, …

Dec 5, 2025
CVE-2025-13625
6.1 MEDIUM

The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.9.2 …

Dec 5, 2025
CVE-2025-13623
6.1 MEDIUM

The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in all versions up to, and including, 0.1.1 due to …

Dec 5, 2025
CVE-2025-13622
6.1 MEDIUM

The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in all versions up to, and including, 0.99-RC2 due to …

Dec 5, 2025
CVE-2025-13621
6.1 MEDIUM

The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Dec 5, 2025
CVE-2025-13528
5.3 MEDIUM

The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_export' function …

Dec 5, 2025
CVE-2025-13512
6.1 MEDIUM

The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.3.1 …

Dec 5, 2025
CVE-2025-13360
4.3 MEDIUM

The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due …

Dec 5, 2025
CVE-2025-13144
4.3 MEDIUM

The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or …

Dec 5, 2025
CVE-2025-12370
4.3 MEDIUM

The Takeads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.13. This is due to the plugin not …

Dec 5, 2025
CVE-2025-12368
6.4 MEDIUM

The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sermon-views` shortcode in all versions up to, and including, 2.30.0. This …

Dec 5, 2025
CVE-2025-12191
5.4 MEDIUM

The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' AJAX action in all versions up to, and …

Dec 5, 2025
CVE-2025-12190
4.3 MEDIUM

The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due …

Dec 5, 2025
CVE-2025-12189
4.3 MEDIUM

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site …

Dec 5, 2025
CVE-2025-12165
4.3 MEDIUM

The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webcake_save_config' …

Dec 5, 2025
CVE-2025-12163
6.4 MEDIUM

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to …

Dec 5, 2025
CVE-2025-12133
4.3 MEDIUM

The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_eprolo_delete_tracking and wp_ajax_eprolo_save_tracking_data AJAX …

Dec 5, 2025
CVE-2025-12128
4.3 MEDIUM

The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7. …

Dec 5, 2025
CVE-2025-12124
4.4 MEDIUM

The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.1 due …

Dec 5, 2025
CVE-2025-10055
4.3 MEDIUM

The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing …

Dec 5, 2025
CVE-2016-20023
5.0 MEDIUM

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

Dec 5, 2025
CVE-2025-32901
4.3 MEDIUM

In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.

Dec 5, 2025
CVE-2025-32899
4.3 MEDIUM

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery …

Dec 5, 2025
CVE-2025-32898
4.7 MEDIUM

The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE …

Dec 5, 2025
CVE-2025-13494
5.3 MEDIUM

The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the …

Dec 5, 2025
CVE-2025-13362
4.3 MEDIUM

The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing …

Dec 5, 2025
CVE-2025-13312
5.3 MEDIUM

The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all …

Dec 5, 2025
CVE-2025-13006
5.3 MEDIUM

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via …

Dec 5, 2025
CVE-2025-12417
6.4 MEDIUM

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, …

Dec 5, 2025
CVE-2025-12804
6.4 MEDIUM

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 …

Dec 5, 2025
CVE-2025-11759
4.3 MEDIUM

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 5, 2025
CVE-2025-62223
4.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Dec 5, 2025
CVE-2025-14052
6.3 MEDIUM

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the …

Dec 5, 2025
CVE-2025-66563
6.1 MEDIUM

Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute …

Dec 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.