CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10567
6.3 MEDIUM

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to …

Nov 5, 2025
CVE-2025-11162
6.4 MEDIUM

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in …

Nov 5, 2025
CVE-2025-12580
6.1 MEDIUM

The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in all versions up to, and including, 1.1.8 …

Nov 5, 2025
CVE-2025-11835
5.3 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Nov 5, 2025
CVE-2025-8871
5.6 MEDIUM

The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted …

Nov 5, 2025
CVE-2025-12582
4.3 MEDIUM

The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'features_revert_option AJAX endpoint in all …

Nov 5, 2025
CVE-2025-62722
5.4 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) …

Nov 4, 2025
CVE-2025-59596
6.5 MEDIUM

CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy …

Nov 4, 2025
CVE-2025-62721
6.5 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement …

Nov 4, 2025
CVE-2025-62720
6.5 MEDIUM

LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from …

Nov 4, 2025
CVE-2025-62719
4.3 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and …

Nov 4, 2025
CVE-2025-62715
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Scripting (XSS) vulnerability in ClipBucket’s Collection tags feature. …

Nov 4, 2025
CVE-2025-62520
4.3 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access …

Nov 4, 2025
CVE-2025-55155
5.4 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their profile to change their e-mail …

Nov 4, 2025
CVE-2025-54335
6.5 MEDIUM

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU …

Nov 4, 2025
CVE-2025-48884
6.1 MEDIUM

Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette's Document Type is vulnerable to Cross-site Scripting. This …

Nov 4, 2025
CVE-2025-48076
5.4 MEDIUM

Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user to edit a group name and insert …

Nov 4, 2025
CVE-2025-27374
5.3 MEDIUM

An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, …

Nov 4, 2025
CVE-2025-61431
6.1 MEDIUM

A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary …

Nov 4, 2025
CVE-2025-54327
6.5 MEDIUM

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validation in the …

Nov 4, 2025
CVE-2025-33176
6.2 MEDIUM

NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adjacent network. A successful …

Nov 4, 2025
CVE-2025-64322
5.3 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.

Nov 4, 2025
CVE-2025-64321
5.3 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before …

Nov 4, 2025
CVE-2025-64320
6.5 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.

Nov 4, 2025
CVE-2025-64319
5.3 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before …

Nov 4, 2025
CVE-2025-64318
5.3 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code …

Nov 4, 2025
CVE-2025-10875
6.5 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue affects Mulesoft Anypoint Code Builder: before …

Nov 4, 2025
CVE-2025-54333
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the …

Nov 4, 2025
CVE-2025-54325
5.3 MEDIUM

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. …

Nov 4, 2025
CVE-2025-60925
5.3 MEDIUM

codeshare v1.0.0 was discovered to contain an information leakage vulnerability.

Nov 4, 2025
CVE-2025-54331
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the …

Nov 4, 2025
CVE-2025-54330
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me …

Nov 4, 2025
CVE-2025-63294
6.5 MEDIUM

WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf …

Nov 4, 2025
CVE-2025-12184
4.4 MEDIUM

The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.11 due to insufficient …

Nov 4, 2025
CVE-2025-12695
5.9 MEDIUM

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input …

Nov 4, 2025
CVE-2025-12045
6.4 MEDIUM

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 4, 2025
CVE-2025-20749
6.7 MEDIUM

In charger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Nov 4, 2025
CVE-2025-20748
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20747
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Nov 4, 2025
CVE-2025-20746
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Nov 4, 2025
CVE-2025-20745
4.2 MEDIUM

In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Nov 4, 2025
CVE-2025-20744
4.2 MEDIUM

In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious …

Nov 4, 2025
CVE-2025-20743
4.2 MEDIUM

In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious …

Nov 4, 2025
CVE-2025-20741
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20740
4.7 MEDIUM

In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with …

Nov 4, 2025
CVE-2025-20739
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20738
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20736
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20734
5.3 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20732
5.3 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.