CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12559
4.3 MEDIUM

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to …

Nov 27, 2025
CVE-2025-13765
4.3 MEDIUM

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Nov 27, 2025
CVE-2025-12971
4.3 MEDIUM

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due …

Nov 27, 2025
CVE-2025-59454
4.3 MEDIUM

In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs …

Nov 27, 2025
CVE-2025-59302
4.7 MEDIUM

In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * …

Nov 27, 2025
CVE-2025-54057
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: <= 10.2.0. Users are …

Nov 27, 2025
CVE-2025-13742
6.1 MEDIUM

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it …

Nov 27, 2025
CVE-2025-10476
4.3 MEDIUM

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in …

Nov 27, 2025
CVE-2025-59026
5.4 MEDIUM

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-59025
6.1 MEDIUM

Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of …

Nov 27, 2025
CVE-2025-30190
5.4 MEDIUM

Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-30186
5.4 MEDIUM

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-13381
5.3 MEDIUM

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Nov 27, 2025
CVE-2025-13378
6.5 MEDIUM

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Nov 27, 2025
CVE-2025-12584
5.3 MEDIUM

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX …

Nov 27, 2025
CVE-2025-13441
5.3 MEDIUM

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This …

Nov 27, 2025
CVE-2025-13157
5.3 MEDIUM

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the …

Nov 27, 2025
CVE-2025-13525
6.1 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 …

Nov 27, 2025
CVE-2025-13143
4.3 MEDIUM

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Nov 27, 2025
CVE-2025-12185
4.4 MEDIUM

The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient …

Nov 27, 2025
CVE-2025-12123
6.1 MEDIUM

The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email-text' parameter in all versions up to, and …

Nov 27, 2025
CVE-2025-3784
5.5 MEDIUM

Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As …

Nov 27, 2025
CVE-2025-12151
6.4 MEDIUM

The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in all versions up to, and including, 1.1.0 due …

Nov 27, 2025
CVE-2025-12713
6.4 MEDIUM

The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to …

Nov 27, 2025
CVE-2025-12712
6.4 MEDIUM

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up to, and including, 0.2.1 due to …

Nov 27, 2025
CVE-2025-12670
6.4 MEDIUM

The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic' shortcode in all versions up to, and including, …

Nov 27, 2025
CVE-2025-12666
6.4 MEDIUM

The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in …

Nov 27, 2025
CVE-2025-12649
6.4 MEDIUM

The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sorttablepost shortcode in all versions up to, …

Nov 27, 2025
CVE-2025-12579
5.3 MEDIUM

The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action in all …

Nov 27, 2025
CVE-2025-12578
4.3 MEDIUM

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing …

Nov 27, 2025
CVE-2025-66030
5.3 MEDIUM

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables …

Nov 26, 2025
CVE-2025-7449
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-6195
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-65670
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized …

Nov 26, 2025
CVE-2025-12653
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific …

Nov 26, 2025
CVE-2025-65676
5.4 MEDIUM

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images.

Nov 26, 2025
CVE-2025-65675
5.4 MEDIUM

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures.

Nov 26, 2025
CVE-2021-4472
6.5 MEDIUM

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files …

Nov 26, 2025
CVE-2025-65239
4.3 MEDIUM

Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.

Nov 26, 2025
CVE-2025-65238
6.5 MEDIUM

Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user …

Nov 26, 2025
CVE-2025-65237
6.1 MEDIUM

A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a …

Nov 26, 2025
CVE-2025-63938
6.5 MEDIUM

Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.

Nov 26, 2025
CVE-2025-9191
6.3 MEDIUM

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in …

Nov 26, 2025
CVE-2025-9163
6.1 MEDIUM

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to …

Nov 26, 2025
CVE-2025-13674
5.5 MEDIUM

BPv7 dissector crash in Wireshark 4.6.0 allows denial of service

Nov 26, 2025
CVE-2025-62728
5.4 MEDIUM

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized …

Nov 26, 2025
CVE-2025-59820
6.7 MEDIUM

In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow proceeds even …

Nov 26, 2025
CVE-2025-66026
6.1 MEDIUM

REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the Mediapool view where the request parameter args[types] …

Nov 26, 2025
CVE-2025-66025
4.3 MEDIUM

Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page improperly handled user-supplied Markdown, allowing attacker-controlled …

Nov 26, 2025
CVE-2025-66021
6.1 MEDIUM

OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against …

Nov 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.