CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11941
5.4 MEDIUM

A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler. Performing …

Oct 19, 2025
CVE-2025-11939
4.7 MEDIUM

A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php of the component Backup Restore Handler. …

Oct 19, 2025
CVE-2025-11938
5.6 MEDIUM

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL …

Oct 19, 2025
CVE-2025-62672
5.3 MEDIUM

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy …

Oct 19, 2025
CVE-2025-11926
4.4 MEDIUM

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due …

Oct 18, 2025
CVE-2025-11256
5.3 MEDIUM

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions …

Oct 18, 2025
CVE-2025-10750
5.3 MEDIUM

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to …

Oct 18, 2025
CVE-2025-9562
6.4 MEDIUM

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, …

Oct 18, 2025
CVE-2025-11741
5.3 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the …

Oct 18, 2025
CVE-2025-11703
5.3 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This …

Oct 18, 2025
CVE-2025-11519
4.3 MEDIUM

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure …

Oct 18, 2025
CVE-2025-11510
4.3 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Oct 18, 2025
CVE-2025-11372
6.5 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is …

Oct 18, 2025
CVE-2025-11270
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute …

Oct 18, 2025
CVE-2025-10187
4.9 MEDIUM

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' parameter in all versions up …

Oct 18, 2025
CVE-2025-10006
6.4 MEDIUM

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, …

Oct 18, 2025
CVE-2025-11857
6.4 MEDIUM

The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display_embed' shortcode in all versions up to, and including, 1.9.9. …

Oct 18, 2025
CVE-2025-11742
4.3 MEDIUM

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' …

Oct 18, 2025
CVE-2025-11738
5.3 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. …

Oct 18, 2025
CVE-2025-11361
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Oct 18, 2025
CVE-2025-11378
5.4 MEDIUM

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Oct 18, 2025
CVE-2020-36854
6.4 MEDIUM

The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization …

Oct 18, 2025
CVE-2025-62651
6.5 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.

Oct 17, 2025
CVE-2025-62649
5.8 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders.

Oct 17, 2025
CVE-2025-62648
6.4 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.

Oct 17, 2025
CVE-2025-62647
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to …

Oct 17, 2025
CVE-2025-62646
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.

Oct 17, 2025
CVE-2025-62644
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.

Oct 17, 2025
CVE-2025-62642
5.8 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, …

Oct 17, 2025
CVE-2025-62508
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in …

Oct 17, 2025
CVE-2025-11914
4.3 MEDIUM

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function Download of the file /DeviceFileReport.do?Action=Download. Performing manipulation …

Oct 17, 2025
CVE-2025-62511
6.3 MEDIUM

yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-367) in …

Oct 17, 2025
CVE-2025-11925
6.1 MEDIUM

Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through …

Oct 17, 2025
CVE-2025-11913
4.3 MEDIUM

A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is the function Download of the file /Service.do?Action=Download. Such …

Oct 17, 2025
CVE-2025-11912
6.3 MEDIUM

A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file /DeviceState.do?Action=Query. This manipulation of the …

Oct 17, 2025
CVE-2025-11911
6.3 MEDIUM

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Action=Query. The manipulation of the argument …

Oct 17, 2025
CVE-2025-11910
6.3 MEDIUM

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /MemoryState.do?Action=Query. The manipulation of …

Oct 17, 2025
CVE-2025-56320
5.4 MEDIUM

Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary …

Oct 17, 2025
CVE-2025-34281
5.4 MEDIUM

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting …

Oct 17, 2025
CVE-2025-11909
6.3 MEDIUM

A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. Executing manipulation …

Oct 17, 2025
CVE-2025-11908
6.3 MEDIUM

A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing …

Oct 17, 2025
CVE-2024-31573
4.0 MEDIUM

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension …

Oct 17, 2025
CVE-2025-62430
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site scripting (XSS) in multiple video and photo …

Oct 17, 2025
CVE-2025-62424
6.7 MEDIUM

ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of …

Oct 17, 2025
CVE-2025-62421
5.4 MEDIUM

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scripting vulnerability exists due to improper file upload validation …

Oct 17, 2025
CVE-2025-60514
6.5 MEDIUM

Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts.

Oct 17, 2025
CVE-2025-57164
6.5 MEDIUM

Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.

Oct 17, 2025
CVE-2025-62171
5.9 MEDIUM

ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer …

Oct 17, 2025
CVE-2025-58747
6.1 MEDIUM

Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects …

Oct 17, 2025
CVE-2025-11905
6.3 MEDIUM

A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code …

Oct 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.