CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25458
4.6 MEDIUM

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

Apr 15, 2025
CVE-2025-25453
4.6 MEDIUM

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.

Apr 15, 2025
CVE-2025-22911
5.6 MEDIUM

RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.

Apr 15, 2025
CVE-2025-32923
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Tourmaster tourmaster allows Reflected XSS.This issue affects Tourmaster: from n/a through < …

Apr 15, 2025
CVE-2025-32784

conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025.4.10, a race condition vulnerability has been identified …

Apr 15, 2025
CVE-2025-32782
5.3 MEDIUM

Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent …

Apr 15, 2025
CVE-2025-31950
5.3 MEDIUM

An unauthenticated attacker can obtain EV charger energy consumption information of other users.

Apr 15, 2025
CVE-2025-31945
5.3 MEDIUM

An unauthenticated attacker can obtain other users' charger information.

Apr 15, 2025
CVE-2025-31654
5.3 MEDIUM

An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").

Apr 15, 2025
CVE-2025-31360
6.5 MEDIUM

Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.

Apr 15, 2025
CVE-2025-31147
5.3 MEDIUM

Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

Apr 15, 2025
CVE-2025-30984
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dzynit SEO Tools seo-automatic-seo-tools allows Reflected XSS.This issue affects SEO Tools: from n/a …

Apr 15, 2025
CVE-2025-30982
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookProgress by Stormhill Media mybookprogress allows Stored XSS.This issue affects MyBookProgress by …

Apr 15, 2025
CVE-2025-30970
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scottwallick Easy Contact easy-contact allows Reflected XSS.This issue affects Easy Contact: from n/a …

Apr 15, 2025
CVE-2025-30967
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.

Apr 15, 2025
CVE-2025-30966
5.4 MEDIUM

Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a through n/a.

Apr 15, 2025
CVE-2025-30512
6.5 MEDIUM

Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

Apr 15, 2025
CVE-2025-30510
9.8 CRITICAL

An attacker can upload an arbitrary file instead of a plant image.

Apr 15, 2025
CVE-2025-30257
5.3 MEDIUM

Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.

Apr 15, 2025
CVE-2025-29471
8.3 HIGH

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.

Apr 15, 2025
CVE-2025-27929
5.3 MEDIUM

Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.

Apr 15, 2025
CVE-2025-27927
5.3 MEDIUM

An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

Apr 15, 2025
CVE-2025-27892
6.8 MEDIUM

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and …

Apr 15, 2025
CVE-2025-27719
5.3 MEDIUM

Unauthenticated attackers can query an API endpoint and get device details.

Apr 15, 2025
CVE-2025-27575
5.3 MEDIUM

An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.

Apr 15, 2025
CVE-2025-27565
5.3 MEDIUM

An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

Apr 15, 2025
CVE-2025-27561
5.3 MEDIUM

Unauthenticated attackers can rename "rooms" of arbitrary users.

Apr 15, 2025
CVE-2025-27011
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows PHP Local …

Apr 15, 2025
CVE-2025-27008
7.5 HIGH

Missing Authorization vulnerability in NotFound Unlimited Timeline unlimited-timeline allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Unlimited Timeline: from n/a through < 1.6.1.

Apr 15, 2025
CVE-2025-26998
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a …

Apr 15, 2025
CVE-2025-26996
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through …

Apr 15, 2025
CVE-2025-26953
7.5 HIGH

Missing Authorization vulnerability in Crocoblock JetMenu jet-menu allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetMenu: from n/a through <= 2.4.9.

Apr 15, 2025
CVE-2025-26951
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in covertnine C9 Blocks c9-blocks allows DOM-Based XSS.This issue affects C9 Blocks: from n/a …

Apr 15, 2025
CVE-2025-26950
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonsPress Nepali Date Converter nepali-date-converter allows Stored XSS.This issue affects Nepali Date Converter: …

Apr 15, 2025
CVE-2025-26934
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphthemes Glossy Blog glossy-blog allows Stored XSS.This issue affects Glossy Blog: from n/a …

Apr 15, 2025
CVE-2025-26930
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Home Services home-services allows DOM-Based XSS.This issue affects Home Services: from n/a …

Apr 15, 2025
CVE-2025-26927
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to a Web Server.This issue affects AI …

Apr 15, 2025
CVE-2025-26919
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainá taina allows Stored XSS.This issue affects Tainá: from n/a through < …

Apr 15, 2025
CVE-2025-26908
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gurmehub Kargo Entegratör kargo-entegrator allows SQL Injection.This issue affects Kargo Entegratör: …

Apr 15, 2025
CVE-2025-26906
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows DOM-Based XSS.This issue affects WP …

Apr 15, 2025
CVE-2025-26903
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery inpost-gallery allows Cross Site Request Forgery.This issue affects InPost Gallery: from n/a through <= 2.1.4.3.

Apr 15, 2025
CVE-2025-26880
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar skt-skill-bar allows Stored XSS.This issue affects SKT Skill Bar: …

Apr 15, 2025
CVE-2025-26870
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows DOM-Based XSS.This issue affects JetEngine: from n/a through <= …

Apr 15, 2025
CVE-2025-26857
5.3 MEDIUM

Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

Apr 15, 2025
CVE-2025-26749
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects …

Apr 15, 2025
CVE-2025-26748
8.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in looswebstudio Arkhe arkhe allows PHP Local File Inclusion.This issue affects Arkhe: from n/a through <= 3.12.0.

Apr 15, 2025
CVE-2025-26746
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in caalami Advanced Custom Fields: Link Picker Field acf-link-picker-field allows Reflected XSS.This issue affects …

Apr 15, 2025
CVE-2025-26740
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware SpaBiz spabiz allows DOM-Based XSS.This issue affects SpaBiz: from n/a through <= …

Apr 15, 2025
CVE-2025-26730
7.5 HIGH

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator with Admin Email Optin & Data. This issue affects Macro …

Apr 15, 2025
CVE-2025-25276
5.3 MEDIUM

An unauthenticated attacker can hijack other users' devices and potentially control them.

Apr 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.