CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20731
5.3 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20730
6.7 MEDIUM

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a …

Nov 4, 2025
CVE-2025-20729
4.2 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-12456
6.1 MEDIUM

The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or …

Nov 4, 2025
CVE-2025-12452
6.1 MEDIUM

The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on …

Nov 4, 2025
CVE-2025-12416
6.1 MEDIUM

The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This …

Nov 4, 2025
CVE-2025-12415
6.1 MEDIUM

The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or …

Nov 4, 2025
CVE-2025-12413
5.4 MEDIUM

The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3. This is …

Nov 4, 2025
CVE-2025-12412
6.1 MEDIUM

The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to …

Nov 4, 2025
CVE-2025-12410
6.1 MEDIUM

The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to …

Nov 4, 2025
CVE-2025-12403
6.1 MEDIUM

The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to …

Nov 4, 2025
CVE-2025-12402
6.1 MEDIUM

The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.00. This is due to missing …

Nov 4, 2025
CVE-2025-12400
6.1 MEDIUM

The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2. This is due to missing …

Nov 4, 2025
CVE-2025-12396
4.4 MEDIUM

The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.2 due to insufficient …

Nov 4, 2025
CVE-2025-12393
4.4 MEDIUM

The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.6 due to …

Nov 4, 2025
CVE-2025-12389
4.3 MEDIUM

The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function …

Nov 4, 2025
CVE-2025-12371
4.4 MEDIUM

The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versions up to, and including, 1.0.12 due to …

Nov 4, 2025
CVE-2025-12369
6.4 MEDIUM

The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker` shortcode in all versions up to, and including, …

Nov 4, 2025
CVE-2025-12350
5.3 MEDIUM

The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up …

Nov 4, 2025
CVE-2025-12188
4.3 MEDIUM

The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Nov 4, 2025
CVE-2025-12157
5.3 MEDIUM

The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_reset_capability' AJAX endpoint …

Nov 4, 2025
CVE-2025-12156
4.3 MEDIUM

The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due …

Nov 4, 2025
CVE-2025-12065
4.4 MEDIUM

The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter in all versions up to, and including, 1.0.0 due …

Nov 4, 2025
CVE-2025-11812
6.4 MEDIUM

The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_title' shortcode in all versions up to, and including, 1.7. This …

Nov 4, 2025
CVE-2025-11758
6.5 MEDIUM

The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up …

Nov 4, 2025
CVE-2025-11753
4.4 MEDIUM

The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 …

Nov 4, 2025
CVE-2025-47370
6.5 MEDIUM

Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.

Nov 4, 2025
CVE-2025-47362
6.1 MEDIUM

Information disclosure while processing message from client with invalid payload.

Nov 4, 2025
CVE-2025-27064
6.1 MEDIUM

Information disclosure while registering commands from clients with diag through diagHal.

Nov 4, 2025
CVE-2025-12401
6.1 MEDIUM

The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing …

Nov 4, 2025
CVE-2025-12070
4.3 MEDIUM

The ViaAds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing nonce …

Nov 4, 2025
CVE-2025-12069
4.3 MEDIUM

The WP Global Screen Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due …

Nov 4, 2025
CVE-2025-12324
6.4 MEDIUM

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `table` shortcode attributes in all …

Nov 4, 2025
CVE-2025-11841
6.4 MEDIUM

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Chart Data attributes in all versions …

Nov 4, 2025
CVE-2025-43507
6.5 MEDIUM

A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS …

Nov 4, 2025
CVE-2025-43504
4.9 MEDIUM

A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be …

Nov 4, 2025
CVE-2025-43503
4.3 MEDIUM

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 …

Nov 4, 2025
CVE-2025-43499
5.5 MEDIUM

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS …

Nov 4, 2025
CVE-2025-43498
5.5 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, …

Nov 4, 2025
CVE-2025-43495
5.4 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may …

Nov 4, 2025
CVE-2025-43493
4.3 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS …

Nov 4, 2025
CVE-2025-43481
5.2 MEDIUM

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to break …

Nov 4, 2025
CVE-2025-43479
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may …

Nov 4, 2025
CVE-2025-43478
5.5 MEDIUM

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. …

Nov 4, 2025
CVE-2025-43477
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS …

Nov 4, 2025
CVE-2025-43469
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may …

Nov 4, 2025
CVE-2025-43468
5.5 MEDIUM

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS …

Nov 4, 2025
CVE-2025-43460
4.6 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a …

Nov 4, 2025
CVE-2025-43459
4.6 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in watchOS 26.1. An attacker with physical access to a locked Apple …

Nov 4, 2025
CVE-2025-43458
4.3 MEDIUM

This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, …

Nov 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.