CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9947
4.9 MEDIUM

The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versions up to, and including, 3.12.0 …

Oct 11, 2025
CVE-2025-9626
4.3 MEDIUM

The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing …

Oct 11, 2025
CVE-2025-9621
4.3 MEDIUM

The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.1. This is due to …

Oct 11, 2025
CVE-2025-8682
4.3 MEDIUM

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up …

Oct 11, 2025
CVE-2025-8484
5.3 MEDIUM

The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files. This makes it …

Oct 11, 2025
CVE-2025-7652
6.4 MEDIUM

The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-58301
6.2 MEDIUM

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58300
6.2 MEDIUM

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58293
5.5 MEDIUM

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58289
5.9 MEDIUM

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-11595
4.7 MEDIUM

A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing a manipulation of …

Oct 11, 2025
CVE-2025-10376
4.3 MEDIUM

The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4. This is due …

Oct 11, 2025
CVE-2025-10375
4.3 MEDIUM

The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10. This is due …

Oct 11, 2025
CVE-2025-10190
6.4 MEDIUM

The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-10175
6.5 MEDIUM

The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due …

Oct 11, 2025
CVE-2025-10167
6.4 MEDIUM

The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_stock_snapshot_restocked shortcode in all versions …

Oct 11, 2025
CVE-2025-10129
6.4 MEDIUM

The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up …

Oct 11, 2025
CVE-2025-58297
5.9 MEDIUM

Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58295
5.9 MEDIUM

Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58288
5.5 MEDIUM

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-11594
5.3 MEDIUM

A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file …

Oct 11, 2025
CVE-2025-11518
5.3 MEDIUM

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via …

Oct 11, 2025
CVE-2025-11254
4.3 MEDIUM

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, …

Oct 11, 2025
CVE-2025-11167
4.7 MEDIUM

The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, …

Oct 11, 2025
CVE-2025-9496
6.4 MEDIUM

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-9196
5.3 MEDIUM

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Oct 11, 2025
CVE-2025-11197
6.4 MEDIUM

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 …

Oct 11, 2025
CVE-2025-10185
4.9 MEDIUM

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in …

Oct 11, 2025
CVE-2025-10048
4.9 MEDIUM

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due …

Oct 11, 2025
CVE-2025-11593
6.3 MEDIUM

A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument …

Oct 11, 2025
CVE-2025-11592
6.3 MEDIUM

A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edit-equipmentform.php. The manipulation of the argument ID …

Oct 11, 2025
CVE-2025-11591
6.3 MEDIUM

A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The …

Oct 11, 2025
CVE-2025-58285
5.3 MEDIUM

Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58284
5.9 MEDIUM

Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58283
5.5 MEDIUM

Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58278
6.2 MEDIUM

Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58277
4.0 MEDIUM

Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-9560
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-11380
5.9 MEDIUM

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a …

Oct 11, 2025
CVE-2025-54654
6.2 MEDIUM

Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality

Oct 11, 2025
CVE-2025-11590
6.3 MEDIUM

A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing a …

Oct 11, 2025
CVE-2025-9554
5.3 MEDIUM

Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*.

Oct 10, 2025
CVE-2025-9553
5.3 MEDIUM

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

Oct 10, 2025
CVE-2025-9552
5.3 MEDIUM

Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*.

Oct 10, 2025
CVE-2025-9551
6.5 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, from 7.X-1.0 before …

Oct 10, 2025
CVE-2025-9550
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.10, …

Oct 10, 2025
CVE-2025-9549
6.5 MEDIUM

Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.

Oct 10, 2025
CVE-2025-52647
6.1 MEDIUM

The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks.

Oct 10, 2025
CVE-2025-11626
5.5 MEDIUM

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

Oct 10, 2025
CVE-2025-61912
5.3 MEDIUM

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash …

Oct 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.