CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10748
6.5 MEDIUM

The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and including, 1.2. This is due …

Oct 24, 2025
CVE-2025-10740
6.3 MEDIUM

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missing capability …

Oct 24, 2025
CVE-2025-10701
6.4 MEDIUM

The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in …

Oct 24, 2025
CVE-2025-9978
6.8 MEDIUM

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting …

Oct 24, 2025
CVE-2025-61931
5.4 MEDIUM

Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attacker to execute an arbitrary script in a logged-in user's …

Oct 24, 2025
CVE-2025-58070
6.1 MEDIUM

Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to execute an arbitrary script in a logged-in user's web …

Oct 24, 2025
CVE-2025-10874
5.5 MEDIUM

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may …

Oct 24, 2025
CVE-2025-7730
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 …

Oct 23, 2025
CVE-2025-60023
4.0 MEDIUM

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-59776
4.0 MEDIUM

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-58456
6.8 MEDIUM

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-62517
5.9 MEDIUM

Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution …

Oct 23, 2025
CVE-2025-62236
5.3 MEDIUM

The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could …

Oct 23, 2025
CVE-2025-57848
6.4 MEDIUM

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during …

Oct 23, 2025
CVE-2025-54966
4.3 MEDIUM

An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return sensitive information in certain …

Oct 23, 2025
CVE-2025-54963
6.5 MEDIUM

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a …

Oct 23, 2025
CVE-2025-62255
6.1 MEDIUM

Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP …

Oct 23, 2025
CVE-2025-60859
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bbs/view_comment.php.

Oct 23, 2025
CVE-2025-60837
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted …

Oct 23, 2025
CVE-2025-23345
4.4 MEDIUM

NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds read. A successful exploit …

Oct 23, 2025
CVE-2025-23332
5.0 MEDIUM

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A …

Oct 23, 2025
CVE-2025-23330
5.5 MEDIUM

NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer dereference. A successful exploit of this …

Oct 23, 2025
CVE-2025-23300
5.5 MEDIUM

NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific …

Oct 23, 2025
CVE-2025-10937
5.5 MEDIUM

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local authentication token during startup, before copying …

Oct 23, 2025
CVE-2025-61464
6.5 MEDIUM

gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.

Oct 23, 2025
CVE-2025-61413
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating …

Oct 23, 2025
CVE-2025-57240
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute arbitrary code via the registration step.

Oct 23, 2025
CVE-2025-50951
6.5 MEDIUM

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

Oct 23, 2025
CVE-2025-50949
6.5 MEDIUM

FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.

Oct 23, 2025
CVE-2025-12114
5.5 MEDIUM

Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 23, 2025
CVE-2025-56009
5.3 MEDIUM

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users …

Oct 23, 2025
CVE-2025-56008
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via …

Oct 23, 2025
CVE-2025-56007
6.5 MEDIUM

CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing …

Oct 23, 2025
CVE-2025-12110
5.4 MEDIUM

A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token …

Oct 23, 2025
CVE-2025-62256
5.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and …

Oct 23, 2025
CVE-2025-60852
6.5 MEDIUM

A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize …

Oct 23, 2025
CVE-2025-53702
6.5 MEDIUM

Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action …

Oct 23, 2025
CVE-2025-53701
6.1 MEDIUM

Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET requests sent to /cgi-bin/action endpoint are not sanitized properly, …

Oct 23, 2025
CVE-2025-11429
5.4 MEDIUM

A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created …

Oct 23, 2025
CVE-2025-8427
6.4 MEDIUM

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and …

Oct 23, 2025
CVE-2025-11128
5.0 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery …

Oct 23, 2025
CVE-2025-10705
5.3 MEDIUM

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.4.6. …

Oct 23, 2025
CVE-2025-62401
5.4 MEDIUM

An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

Oct 23, 2025
CVE-2025-62400
4.3 MEDIUM

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal …

Oct 23, 2025
CVE-2025-62398
5.4 MEDIUM

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

Oct 23, 2025
CVE-2025-62397
5.3 MEDIUM

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

Oct 23, 2025
CVE-2025-62396
5.3 MEDIUM

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

Oct 23, 2025
CVE-2025-62395
4.3 MEDIUM

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted …

Oct 23, 2025
CVE-2025-62394
4.3 MEDIUM

Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course …

Oct 23, 2025
CVE-2025-62393
4.3 MEDIUM

A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view …

Oct 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.