CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64263
5.4 MEDIUM

Missing Authorization vulnerability in PluginEver WP Content Pilot wp-content-pilot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Content Pilot: from n/a through …

Nov 13, 2025
CVE-2025-64262
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Request Forgery.This issue affects Auto Prune Posts: from n/a through …

Nov 13, 2025
CVE-2025-64261
5.4 MEDIUM

Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Appointment Booking Calendar: from n/a through …

Nov 13, 2025
CVE-2025-64259
5.3 MEDIUM

Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a …

Nov 13, 2025
CVE-2025-8397
6.4 MEDIUM

The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbutton shortcode in all versions up to, and …

Nov 13, 2025
CVE-2025-12015
4.3 MEDIUM

The Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed plugin for WordPress is vulnerable to …

Nov 13, 2025
CVE-2025-11769
6.4 MEDIUM

The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortcode attribute of the 'flipper_front' shortcode in all versions …

Nov 13, 2025
CVE-2025-11260
5.3 MEDIUM

The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.15. This is due …

Nov 13, 2025
CVE-2025-10295
6.4 MEDIUM

The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting the profile media uploader in all versions …

Nov 13, 2025
CVE-2025-12681
5.3 MEDIUM

The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0 …

Nov 13, 2025
CVE-2025-12620
4.9 MEDIUM

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the ‘filterbyauthor’ parameter in all …

Nov 13, 2025
CVE-2025-12891
5.3 MEDIUM

The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results' AJAX endpoint in …

Nov 13, 2025
CVE-2025-12979
5.3 MEDIUM

The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' action in all …

Nov 13, 2025
CVE-2025-12892
5.3 MEDIUM

The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all …

Nov 13, 2025
CVE-2025-12536
5.3 MEDIUM

The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. …

Nov 13, 2025
CVE-2025-12366
4.3 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Nov 13, 2025
CVE-2025-12089
6.5 MEDIUM

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function …

Nov 13, 2025
CVE-2025-64707
5.4 MEDIUM

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins revoked a …

Nov 12, 2025
CVE-2025-64705
4.3 MEDIUM

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, users were able to …

Nov 12, 2025
CVE-2025-13076
4.7 MEDIUM

A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/usersetting.php. Executing manipulation of …

Nov 12, 2025
CVE-2025-13075
4.7 MEDIUM

A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/usersettingdel.php. Performing manipulation of the argument eid …

Nov 12, 2025
CVE-2025-64517
4.4 MEDIUM

sudo-rs is a memory safe implementation of sudo and su written in Rust. With `Defaults targetpw` (or `Defaults rootpw`) enabled, the password of the target …

Nov 12, 2025
CVE-2025-64503
4.0 MEDIUM

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In cups-filters prior to …

Nov 12, 2025
CVE-2025-64482
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition …

Nov 12, 2025
CVE-2025-64429
6.5 MEDIUM

DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues …

Nov 12, 2025
CVE-2025-63645
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application's message system. Unsanitized message content submitted by one user is persisted …

Nov 12, 2025
CVE-2025-33119
6.5 MEDIUM

IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.

Nov 12, 2025
CVE-2025-36223
5.4 MEDIUM

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an …

Nov 12, 2025
CVE-2025-13061
6.3 MEDIUM

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Performing manipulation results in unrestricted upload. …

Nov 12, 2025
CVE-2025-8421
6.6 MEDIUM

An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect …

Nov 12, 2025
CVE-2025-64117
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1761813675 and Tuleap Enterprise Edition …

Nov 12, 2025
CVE-2025-27368
4.3 MEDIUM

IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points …

Nov 12, 2025
CVE-2025-13059
6.3 MEDIUM

A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career.php. This manipulation of …

Nov 12, 2025
CVE-2025-12047
5.3 MEDIUM

A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the …

Nov 12, 2025
CVE-2024-48829
6.7 MEDIUM

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A high privileged attacker with local …

Nov 12, 2025
CVE-2025-63927
4.0 MEDIUM

A heap-use-after-free vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). During multi-threaded client execution, the function Iec10x_Scheduled can access memory that has already been …

Nov 12, 2025
CVE-2025-60646
6.1 MEDIUM

A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitrary web scripts or HTML via injecting a …

Nov 12, 2025
CVE-2025-13057
6.3 MEDIUM

A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_student. The manipulation of the …

Nov 12, 2025
CVE-2024-45301
5.3 MEDIUM

Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access …

Nov 12, 2025
CVE-2025-60645
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.

Nov 12, 2025
CVE-2025-25236
5.3 MEDIUM

Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and …

Nov 12, 2025
CVE-2025-63419
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to …

Nov 12, 2025
CVE-2025-59491
6.1 MEDIUM

Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.

Nov 12, 2025
CVE-2025-59089
5.9 MEDIUM

If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact that kdcproxy does …

Nov 12, 2025
CVE-2025-52331
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the computer username, generated …

Nov 12, 2025
CVE-2025-40164
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible code warnings Syzbot reported the following warning: BUG: using …

Nov 12, 2025
CVE-2025-11454
6.5 MEDIUM

The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable to SQL Injection via the eos_scfm_duplicate_post_as_draft() function in …

Nov 12, 2025
CVE-2025-64407
5.3 MEDIUM

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links …

Nov 12, 2025
CVE-2025-61623
6.5 MEDIUM

Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the …

Nov 12, 2025
CVE-2025-37734
4.3 MEDIUM

Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

Nov 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.