CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9045
6.4 MEDIUM

The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in versions less than, or equal to, 2.2.9 …

Oct 3, 2025
CVE-2025-8776
6.4 MEDIUM

The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in all versions up to, and including, 1.0 …

Oct 3, 2025
CVE-2025-8669
4.3 MEDIUM

The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing or incorrect nonce validation on the …

Oct 3, 2025
CVE-2025-7825
6.3 MEDIUM

The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all versions up to, and including, 4.3.2 via …

Oct 3, 2025
CVE-2025-49641
4.3 MEDIUM

A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve …

Oct 3, 2025
CVE-2025-27236
6.5 MEDIUM

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to …

Oct 3, 2025
CVE-2025-27231
4.9 MEDIUM

The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue …

Oct 3, 2025
CVE-2025-10311
4.3 MEDIUM

The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to …

Oct 3, 2025
CVE-2025-10309
4.3 MEDIUM

The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing …

Oct 3, 2025
CVE-2025-10302
4.3 MEDIUM

The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to …

Oct 3, 2025
CVE-2025-10212
5.3 MEDIUM

The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in …

Oct 3, 2025
CVE-2025-10192
6.4 MEDIUM

The WP Photo Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wppe_effect' shortcode in all versions up to, and including, …

Oct 3, 2025
CVE-2025-10165
6.4 MEDIUM

The AP Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adv_parallax_back' shortcode in all versions up to, and including, 3.8.2 …

Oct 3, 2025
CVE-2025-10053
4.4 MEDIUM

The TableGen – Data Table Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, …

Oct 3, 2025
CVE-2025-0876
4.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Isin Basi Advertisement Information Technologies Trade Inc. IT's Workif allows Cross-Site …

Oct 3, 2025
CVE-2025-61599
5.4 MEDIUM

Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitter"feature of EMLOG Pro 2.5.21 and below. An …

Oct 3, 2025
CVE-2025-61589
5.9 MEDIUM

Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then …

Oct 3, 2025
CVE-2025-11241
6.4 MEDIUM

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to …

Oct 3, 2025
CVE-2025-61606
6.1 MEDIUM

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the …

Oct 2, 2025
CVE-2025-54088
6.1 MEDIUM

CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. …

Oct 2, 2025
CVE-2025-56019
6.5 MEDIUM

An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without …

Oct 2, 2025
CVE-2025-60661
5.3 MEDIUM

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.

Oct 2, 2025
CVE-2025-59406
6.2 MEDIUM

The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a …

Oct 2, 2025
CVE-2025-34210
5.5 MEDIUM

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, …

Oct 2, 2025
CVE-2025-57305
6.5 MEDIUM

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

Oct 2, 2025
CVE-2025-56162
6.5 MEDIUM

YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), …

Oct 2, 2025
CVE-2025-56154
6.1 MEDIUM

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before …

Oct 2, 2025
CVE-2025-61096
6.5 MEDIUM

PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.

Oct 2, 2025
CVE-2025-61087
6.1 MEDIUM

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.

Oct 2, 2025
CVE-2025-60782
5.4 MEDIUM

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject …

Oct 2, 2025
CVE-2025-59774
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59773
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59772
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59771
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59770
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59769
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59768
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59767
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59766
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59765
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59764
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59763
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59762
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59761
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59760
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59759
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59758
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59757
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59756
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59755
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.