CVE Database

112325+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13528
5.3 MEDIUM

The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_export' function …

Dec 5, 2025
CVE-2025-13512
6.1 MEDIUM

The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.3.1 …

Dec 5, 2025
CVE-2025-13360
4.3 MEDIUM

The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due …

Dec 5, 2025
CVE-2025-13144
4.3 MEDIUM

The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or …

Dec 5, 2025
CVE-2025-12370
4.3 MEDIUM

The Takeads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.13. This is due to the plugin not …

Dec 5, 2025
CVE-2025-12368
6.4 MEDIUM

The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sermon-views` shortcode in all versions up to, and including, 2.30.0. This …

Dec 5, 2025
CVE-2025-12191
5.4 MEDIUM

The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' AJAX action in all versions up to, and …

Dec 5, 2025
CVE-2025-12190
4.3 MEDIUM

The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due …

Dec 5, 2025
CVE-2025-12189
4.3 MEDIUM

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site …

Dec 5, 2025
CVE-2025-12181
8.8 HIGH

The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up …

Dec 5, 2025
CVE-2025-12165
4.3 MEDIUM

The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webcake_save_config' …

Dec 5, 2025
CVE-2025-12163
6.4 MEDIUM

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to …

Dec 5, 2025
CVE-2025-12154
8.8 HIGH

The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function in all versions …

Dec 5, 2025
CVE-2025-12153
8.8 HIGH

The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up …

Dec 5, 2025
CVE-2025-12133
4.3 MEDIUM

The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_eprolo_delete_tracking and wp_ajax_eprolo_save_tracking_data AJAX …

Dec 5, 2025
CVE-2025-12128
4.3 MEDIUM

The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7. …

Dec 5, 2025
CVE-2025-12124
4.4 MEDIUM

The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.1 due …

Dec 5, 2025
CVE-2025-10055
4.3 MEDIUM

The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing …

Dec 5, 2025
CVE-2016-20023
5.0 MEDIUM

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

Dec 5, 2025
CVE-2025-32901
4.3 MEDIUM

In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.

Dec 5, 2025
CVE-2025-32899
4.3 MEDIUM

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery …

Dec 5, 2025
CVE-2025-32898
4.7 MEDIUM

The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE …

Dec 5, 2025
CVE-2025-13494
5.3 MEDIUM

The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the …

Dec 5, 2025
CVE-2025-13362
4.3 MEDIUM

The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing …

Dec 5, 2025
CVE-2025-13313
9.8 CRITICAL

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due …

Dec 5, 2025
CVE-2025-13312
5.3 MEDIUM

The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all …

Dec 5, 2025
CVE-2025-13006
5.3 MEDIUM

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via …

Dec 5, 2025
CVE-2025-12417
6.4 MEDIUM

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, …

Dec 5, 2025
CVE-2025-66544

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66543

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66542

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66541

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66540

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66539

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66538

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66537

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66536

Rejected reason: Not used

Dec 5, 2025
CVE-2025-27389

A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, …

Dec 5, 2025
CVE-2025-13066
8.8 HIGH

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to …

Dec 5, 2025
CVE-2025-12804
6.4 MEDIUM

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 …

Dec 5, 2025
CVE-2025-11759
4.3 MEDIUM

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 5, 2025
CVE-2025-62223
4.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Dec 5, 2025
CVE-2025-14052
6.3 MEDIUM

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the …

Dec 5, 2025
CVE-2025-66564
7.5 HIGH

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided …

Dec 4, 2025
CVE-2025-66563
6.1 MEDIUM

Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute …

Dec 4, 2025
CVE-2025-66561
7.3 HIGH

SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious …

Dec 4, 2025
CVE-2025-66559

Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising its fundamental properties. In 2.3.1 and earlier, TaikoInbox._verifyBatches (packages/protocol/contracts/layer1/based/TaikoInbox.sol:627-678) advanced the …

Dec 4, 2025
CVE-2025-14051
6.3 MEDIUM

A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control …

Dec 4, 2025
CVE-2025-13373
7.5 HIGH

Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.

Dec 4, 2025
CVE-2025-6946
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the IPS module. This …

Dec 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.