CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8483
6.3 MEDIUM

The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.5.5. …

Oct 25, 2025
CVE-2025-12034
4.4 MEDIUM

The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.5.1 due …

Oct 25, 2025
CVE-2025-11976
4.3 MEDIUM

The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to Cross-Site Request …

Oct 25, 2025
CVE-2025-11893
6.5 MEDIUM

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to SQL Injection via the donation_ids …

Oct 25, 2025
CVE-2025-11875
6.4 MEDIUM

The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spendeonline' shortcode in all versions up to, and including, 3.0.1 due …

Oct 25, 2025
CVE-2025-11497
4.3 MEDIUM

The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.6. This is due to …

Oct 25, 2025
CVE-2025-11255
4.3 MEDIUM

The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Oct 25, 2025
CVE-2025-10637
5.3 MEDIUM

The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the …

Oct 25, 2025
CVE-2025-10580
6.4 MEDIUM

The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple functions in …

Oct 25, 2025
CVE-2025-8666
6.4 MEDIUM

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions less than, or equal to, 11.6.2 …

Oct 25, 2025
CVE-2025-8588
6.4 MEDIUM

The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Marker Title' and 'Marker Description' parameters for the …

Oct 25, 2025
CVE-2025-8413
6.4 MEDIUM

The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in version less than, or equal to, 2.0.8 due …

Oct 25, 2025
CVE-2025-6680
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Oct 25, 2025
CVE-2025-6639
5.4 MEDIUM

The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Oct 25, 2025
CVE-2025-12005
4.3 MEDIUM

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorized access of data in all …

Oct 25, 2025
CVE-2025-11879
6.5 MEDIUM

The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_option_rest' function in all versions …

Oct 25, 2025
CVE-2025-11564
5.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Oct 25, 2025
CVE-2025-11269
5.3 MEDIUM

The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'approveNotice' action …

Oct 25, 2025
CVE-2025-10737
6.4 MEDIUM

The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, …

Oct 25, 2025
CVE-2025-10694
5.3 MEDIUM

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due …

Oct 25, 2025
CVE-2025-11823
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Oct 25, 2025
CVE-2025-10579
5.3 MEDIUM

The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Oct 25, 2025
CVE-2025-11760
5.3 MEDIUM

The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all …

Oct 25, 2025
CVE-2025-62723
4.3 MEDIUM

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. …

Oct 24, 2025
CVE-2025-60419
6.2 MEDIUM

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the …

Oct 24, 2025
CVE-2025-60729
5.3 MEDIUM

PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function

Oct 24, 2025
CVE-2025-61430
6.5 MEDIUM

Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the …

Oct 24, 2025
CVE-2025-60936
6.1 MEDIUM

Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code …

Oct 24, 2025
CVE-2025-56438
6.8 MEDIUM

An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically proximate attackers to escalate privileges to root …

Oct 24, 2025
CVE-2025-46425
6.5 MEDIUM

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote …

Oct 24, 2025
CVE-2025-46185
6.2 MEDIUM

An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames.

Oct 24, 2025
CVE-2021-43768
5.3 MEDIUM

In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface running in mbamservice.exe.

Oct 24, 2025
CVE-2025-11576
4.3 MEDIUM

The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, …

Oct 24, 2025
CVE-2025-5605
4.3 MEDIUM

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request …

Oct 24, 2025
CVE-2025-5350
5.9 MEDIUM

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted …

Oct 24, 2025
CVE-2025-36361
6.3 MEDIUM

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due …

Oct 24, 2025
CVE-2025-12136
6.8 MEDIUM

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, …

Oct 24, 2025
CVE-2025-12134
5.3 MEDIUM

The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to unauthorized modification of data …

Oct 24, 2025
CVE-2025-12096
6.4 MEDIUM

The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricelist' shortcode in all versions up to, and …

Oct 24, 2025
CVE-2025-12072
4.3 MEDIUM

The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This …

Oct 24, 2025
CVE-2025-12017
6.1 MEDIUM

The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 1.0.0 …

Oct 24, 2025
CVE-2025-12016
4.4 MEDIUM

The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' parameter in all versions up to, and including, 1.0.0 due to …

Oct 24, 2025
CVE-2025-12014
4.3 MEDIUM

The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nginxcacheoptimizer-blacklist-update' AJAX action …

Oct 24, 2025
CVE-2025-11992
6.1 MEDIUM

The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due …

Oct 24, 2025
CVE-2025-11887
4.3 MEDIUM

The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX functions in all versions …

Oct 24, 2025
CVE-2025-11257
4.3 MEDIUM

The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_save_blogs' AJAX …

Oct 24, 2025
CVE-2025-11172
4.3 MEDIUM

The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the chk_plag_mine_plugin_wpse10500_admin_action() function in all …

Oct 24, 2025
CVE-2025-10902
4.3 MEDIUM

The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ai_scan_result_remove' function in …

Oct 24, 2025
CVE-2025-10901
4.3 MEDIUM

The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ai_get_table' function in …

Oct 24, 2025
CVE-2025-10749
5.4 MEDIUM

The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in all versions up to, and including, 4.5.1. This …

Oct 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.