CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5315
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have …

Jun 26, 2025
CVE-2025-48497
4.3 MEDIUM

Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to …

Jun 26, 2025
CVE-2025-41404
4.3 MEDIUM

Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an …

Jun 26, 2025
CVE-2025-3279
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have …

Jun 26, 2025
CVE-2025-1754
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have …

Jun 26, 2025
CVE-2025-6546
6.4 MEDIUM

The Drive Folder Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tablecssclass’ parameter in all versions up to, and including, 1.1.0 …

Jun 26, 2025
CVE-2025-6540
6.4 MEDIUM

The web-cam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all versions up to, and including, 3.0 due to …

Jun 26, 2025
CVE-2025-6537
6.4 MEDIUM

The Namasha By Mdesign plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘playicon_title’ parameter in all versions up to, and including, 1.2.00 …

Jun 26, 2025
CVE-2025-5932
4.3 MEDIUM

The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.30. This is due to missing or …

Jun 26, 2025
CVE-2025-5929
6.4 MEDIUM

The The Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘clientId’ parameter in all versions up to, and including, 2.0.1 due …

Jun 26, 2025
CVE-2025-5813
5.3 MEDIUM

The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function …

Jun 26, 2025
CVE-2025-5275
4.4 MEDIUM

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 26, 2025
CVE-2025-6538
6.4 MEDIUM

The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, …

Jun 26, 2025
CVE-2025-6383
6.4 MEDIUM

The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in all versions up to, and including, 1.2.2 due …

Jun 26, 2025
CVE-2025-6378
6.4 MEDIUM

The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_pdf_menus shortcode in all versions up to, …

Jun 26, 2025
CVE-2025-6290
6.4 MEDIUM

The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, …

Jun 26, 2025
CVE-2025-6258
6.4 MEDIUM

The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 …

Jun 26, 2025
CVE-2025-5812
4.3 MEDIUM

The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gutenberg_save_post() function in …

Jun 26, 2025
CVE-2025-5588
6.4 MEDIUM

The Image Editor by Pixo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘download’ parameter in all versions up to, and including, …

Jun 26, 2025
CVE-2025-5564
6.4 MEDIUM

The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, …

Jun 26, 2025
CVE-2025-5559
6.4 MEDIUM

The TimeZoneCalculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'timezonecalculator_output' shortcode in all versions up to, and including, 3.37 due …

Jun 26, 2025
CVE-2025-5540
6.4 MEDIUM

The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions …

Jun 26, 2025
CVE-2025-5535
6.4 MEDIUM

The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.3 …

Jun 26, 2025
CVE-2025-5488
6.4 MEDIUM

The WP Masonry & Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wmis' shortcode in all versions up to, …

Jun 26, 2025
CVE-2025-3863
4.3 MEDIUM

The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to improper authorization due to a missing capability check on the process_wbelps_promo_form() function in …

Jun 26, 2025
CVE-2025-6667
6.3 MEDIUM

A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 25, 2025
CVE-2025-6664
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affected is an unknown function. The manipulation leads to …

Jun 25, 2025
CVE-2025-6621
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSetting of the file ap.so. The manipulation of the …

Jun 25, 2025
CVE-2025-6620
6.3 MEDIUM

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the function setUpgradeUboot of the file …

Jun 25, 2025
CVE-2025-6619
6.3 MEDIUM

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerability is the function setUpgradeFW of the file …

Jun 25, 2025
CVE-2025-6618
6.3 MEDIUM

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function SetWLanApcliSettings of the file wps.so. The manipulation …

Jun 25, 2025
CVE-2025-6444
5.9 MEDIUM

ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This vulnerability allows remote attackers to relay NTLM credentials on affected installations of ServiceStack. Interaction with this …

Jun 25, 2025
CVE-2025-5833
6.8 MEDIUM

Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX …

Jun 25, 2025
CVE-2025-5832
6.8 MEDIUM

Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of …

Jun 25, 2025
CVE-2025-5829
6.8 MEDIUM

Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected …

Jun 25, 2025
CVE-2025-5828
6.8 MEDIUM

Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations …

Jun 25, 2025
CVE-2025-5826
6.3 MEDIUM

Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel …

Jun 25, 2025
CVE-2025-5823
6.5 MEDIUM

Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations …

Jun 25, 2025
CVE-2025-49550
4.3 MEDIUM

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. …

Jun 25, 2025
CVE-2025-6442
5.9 MEDIUM

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue …

Jun 25, 2025
CVE-2025-52893
4.5 MEDIUM

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive …

Jun 25, 2025
CVE-2025-52576
5.3 MEDIUM

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vulnerable to username enumeration and IP spoofing-based brute-force …

Jun 25, 2025
CVE-2025-50179
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a cross-site request forgery vulnerability in Tuleap …

Jun 25, 2025
CVE-2025-44206
4.6 MEDIUM

Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a …

Jun 25, 2025
CVE-2025-20264
6.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for …

Jun 25, 2025
CVE-2024-57708
5.7 MEDIUM

An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this …

Jun 25, 2025
CVE-2025-6610
4.7 MEDIUM

A vulnerability was found in itsourcecode Employee Management System up to 1.0. It has been classified as critical. This affects an unknown part of the …

Jun 25, 2025
CVE-2025-6609
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jun 25, 2025
CVE-2025-6608
6.3 MEDIUM

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jun 25, 2025
CVE-2025-49135
6.5 MEDIUM

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the import process …

Jun 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.