CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13742
6.1 MEDIUM

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it …

Nov 27, 2025
CVE-2025-10476
4.3 MEDIUM

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in …

Nov 27, 2025
CVE-2025-59026
5.4 MEDIUM

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-59025
6.1 MEDIUM

Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of …

Nov 27, 2025
CVE-2025-30190
5.4 MEDIUM

Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-30186
5.4 MEDIUM

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-13381
5.3 MEDIUM

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Nov 27, 2025
CVE-2025-13378
6.5 MEDIUM

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Nov 27, 2025
CVE-2025-12584
5.3 MEDIUM

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX …

Nov 27, 2025
CVE-2025-13441
5.3 MEDIUM

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This …

Nov 27, 2025
CVE-2025-13157
5.3 MEDIUM

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the …

Nov 27, 2025
CVE-2025-13525
6.1 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 …

Nov 27, 2025
CVE-2025-13143
4.3 MEDIUM

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Nov 27, 2025
CVE-2025-12185
4.4 MEDIUM

The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient …

Nov 27, 2025
CVE-2025-12123
6.1 MEDIUM

The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email-text' parameter in all versions up to, and …

Nov 27, 2025
CVE-2025-3784
5.5 MEDIUM

Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As …

Nov 27, 2025
CVE-2025-12151
6.4 MEDIUM

The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in all versions up to, and including, 1.1.0 due …

Nov 27, 2025
CVE-2025-12713
6.4 MEDIUM

The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to …

Nov 27, 2025
CVE-2025-12712
6.4 MEDIUM

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up to, and including, 0.2.1 due to …

Nov 27, 2025
CVE-2025-12670
6.4 MEDIUM

The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic' shortcode in all versions up to, and including, …

Nov 27, 2025
CVE-2025-12666
6.4 MEDIUM

The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in …

Nov 27, 2025
CVE-2025-12649
6.4 MEDIUM

The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sorttablepost shortcode in all versions up to, …

Nov 27, 2025
CVE-2025-12579
5.3 MEDIUM

The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action in all …

Nov 27, 2025
CVE-2025-12578
4.3 MEDIUM

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing …

Nov 27, 2025
CVE-2025-66030
5.3 MEDIUM

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables …

Nov 26, 2025
CVE-2025-7449
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-6195
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-65670
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized …

Nov 26, 2025
CVE-2025-12653
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific …

Nov 26, 2025
CVE-2025-65676
5.4 MEDIUM

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images.

Nov 26, 2025
CVE-2025-65675
5.4 MEDIUM

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures.

Nov 26, 2025
CVE-2021-4472
6.5 MEDIUM

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files …

Nov 26, 2025
CVE-2025-65239
4.3 MEDIUM

Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.

Nov 26, 2025
CVE-2025-65238
6.5 MEDIUM

Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user …

Nov 26, 2025
CVE-2025-65237
6.1 MEDIUM

A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a …

Nov 26, 2025
CVE-2025-63938
6.5 MEDIUM

Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.

Nov 26, 2025
CVE-2025-9191
6.3 MEDIUM

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in …

Nov 26, 2025
CVE-2025-9163
6.1 MEDIUM

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to …

Nov 26, 2025
CVE-2025-13674
5.5 MEDIUM

BPv7 dissector crash in Wireshark 4.6.0 allows denial of service

Nov 26, 2025
CVE-2025-62728
5.4 MEDIUM

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized …

Nov 26, 2025
CVE-2025-59820
6.7 MEDIUM

In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow proceeds even …

Nov 26, 2025
CVE-2025-66026
6.1 MEDIUM

REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the Mediapool view where the request parameter args[types] …

Nov 26, 2025
CVE-2025-66025
4.3 MEDIUM

Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page improperly handled user-supplied Markdown, allowing attacker-controlled …

Nov 26, 2025
CVE-2025-66021
6.1 MEDIUM

OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against …

Nov 26, 2025
CVE-2025-12848
6.1 MEDIUM

Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name renderer. An unauthenticated attacker can exploit this …

Nov 26, 2025
CVE-2025-66260
6.5 MEDIUM

PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows …

Nov 26, 2025
CVE-2025-66258
5.4 MEDIUM

Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, …

Nov 26, 2025
CVE-2025-65963
5.4 MEDIUM

Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to …

Nov 26, 2025
CVE-2025-65956
6.5 MEDIUM

Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross‑site …

Nov 26, 2025
CVE-2025-64713
5.1 MEDIUM

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter …

Nov 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.