CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11377
4.3 MEDIUM

The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.92.0 via the 'catlist' shortcode due …

Nov 1, 2025
CVE-2025-12367
4.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.3.1. This is due to the …

Nov 1, 2025
CVE-2025-11928
4.4 MEDIUM

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 …

Nov 1, 2025
CVE-2025-62275
5.3 MEDIUM

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, …

Nov 1, 2025
CVE-2025-11922
6.4 MEDIUM

The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due …

Nov 1, 2025
CVE-2025-11816
5.3 MEDIUM

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due …

Nov 1, 2025
CVE-2025-11174
5.3 MEDIUM

The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the …

Nov 1, 2025
CVE-2025-62276
5.5 MEDIUM

The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 …

Nov 1, 2025
CVE-2025-12464
6.2 MEDIUM

A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and …

Oct 31, 2025
CVE-2025-63563
6.5 MEDIUM

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker …

Oct 31, 2025
CVE-2025-63562
6.3 MEDIUM

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions …

Oct 31, 2025
CVE-2025-60711
6.3 MEDIUM

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Oct 31, 2025
CVE-2025-62267
6.1 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 …

Oct 31, 2025
CVE-2025-62264
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 …

Oct 31, 2025
CVE-2025-6075
5.5 MEDIUM

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

Oct 31, 2025
CVE-2025-59501
4.8 MEDIUM

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

Oct 31, 2025
CVE-2025-12357
6.3 MEDIUM

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers …

Oct 31, 2025
CVE-2025-61427
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execute arbitrary code in the context of a …

Oct 31, 2025
CVE-2025-12521
5.3 MEDIUM

The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify Tag HTML …

Oct 31, 2025
CVE-2024-13992
5.4 MEDIUM

Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following …

Oct 31, 2025
CVE-2025-64368
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a through <= 1.6.

Oct 31, 2025
CVE-2025-64367
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groundhogg groundhogg allows Stored XSS.This issue affects Groundhogg: from n/a through …

Oct 31, 2025
CVE-2025-64365
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extra ohio-extra allows DOM-Based XSS.This issue affects Ohio Extra: from n/a …

Oct 31, 2025
CVE-2025-64362
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Elements k-elements allows DOM-Based XSS.This issue affects K Elements: from n/a …

Oct 31, 2025
CVE-2025-64361
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows DOM-Based XSS.This issue affects Consulting Elementor Widgets: …

Oct 31, 2025
CVE-2025-64358
4.3 MEDIUM

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Coupons for WooCommerce: from …

Oct 31, 2025
CVE-2025-64357
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allows Cross Site Request Forgery.This issue affects Advanced Database Cleaner: from n/a through …

Oct 31, 2025
CVE-2025-64356
4.3 MEDIUM

Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Insert PHP Code Snippet: from …

Oct 31, 2025
CVE-2025-64354
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through …

Oct 31, 2025
CVE-2025-64351
4.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math …

Oct 31, 2025
CVE-2025-40603
4.5 MEDIUM

A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view …

Oct 31, 2025
CVE-2025-12041
5.3 MEDIUM

The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'erifl_file' AJAX action …

Oct 31, 2025
CVE-2025-8383
4.3 MEDIUM

The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or …

Oct 31, 2025
CVE-2025-30191
5.4 MEDIUM

Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to …

Oct 31, 2025
CVE-2025-12175
4.3 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all …

Oct 31, 2025
CVE-2025-12094
5.3 MEDIUM

The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to IP Header Spoofing in all versions up …

Oct 31, 2025
CVE-2025-8385
6.8 MEDIUM

The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is due to insufficient input validation …

Oct 31, 2025
CVE-2025-63675
6.9 MEDIUM

cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.

Oct 31, 2025
CVE-2025-58152
5.3 MEDIUM

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. …

Oct 31, 2025
CVE-2025-11191
5.3 MEDIUM

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the …

Oct 31, 2025
CVE-2025-11975
4.3 MEDIUM

The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to unauthorized modification …

Oct 31, 2025
CVE-2025-11806
6.4 MEDIUM

The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all versions up to, and including, 1.0.1. This …

Oct 31, 2025
CVE-2025-48980
6.5 MEDIUM

In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did …

Oct 31, 2025
CVE-2025-27208
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user …

Oct 31, 2025
CVE-2025-34283
6.5 MEDIUM

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user …

Oct 30, 2025
CVE-2025-34278
5.4 MEDIUM

Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can …

Oct 30, 2025
CVE-2025-34273
6.5 MEDIUM

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly …

Oct 30, 2025
CVE-2025-34272
6.5 MEDIUM

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an …

Oct 30, 2025
CVE-2025-34270
4.9 MEDIUM

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during …

Oct 30, 2025
CVE-2025-34135
4.4 MEDIUM

Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable …

Oct 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.