CVE Database

112325+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12954
2.7 LOW

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading …

Dec 3, 2025
CVE-2025-13495
4.9 MEDIUM

The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, and including, 1.3.1. This is due …

Dec 3, 2025
CVE-2025-12585
5.3 MEDIUM

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 via …

Dec 3, 2025
CVE-2025-10304
5.3 MEDIUM

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Dec 3, 2025
CVE-2025-13646
7.5 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions …

Dec 3, 2025
CVE-2025-13645
7.2 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions …

Dec 3, 2025
CVE-2025-13448
6.4 MEDIUM

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 …

Dec 3, 2025
CVE-2025-65955
4.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ …

Dec 2, 2025
CVE-2025-66476
7.8 HIGH

Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious …

Dec 2, 2025
CVE-2025-55181
5.3 MEDIUM

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends …

Dec 2, 2025
CVE-2025-65657
6.5 MEDIUM

FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files …

Dec 2, 2025
CVE-2025-65380
6.5 MEDIUM

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated …

Dec 2, 2025
CVE-2025-64778
7.3 HIGH

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application …

Dec 2, 2025
CVE-2025-64642
8.0 HIGH

NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations …

Dec 2, 2025
CVE-2025-64298
8.4 HIGH

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked …

Dec 2, 2025
CVE-2025-62575
8.3 HIGH

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the …

Dec 2, 2025
CVE-2025-61940
8.3 HIGH

NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application …

Dec 2, 2025
CVE-2025-65877
7.5 HIGH

Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 'title' parameter in com.wanli.lvzhoucms.service.ContentService#findPage. The parameter is concatenated directly into a dynamic …

Dec 2, 2025
CVE-2025-65379
6.5 MEDIUM

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is …

Dec 2, 2025
CVE-2025-13658

A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence of code signing …

Dec 2, 2025
CVE-2025-13542
9.8 CRITICAL

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' …

Dec 2, 2025
CVE-2025-13510

The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated users to access and modify critical …

Dec 2, 2025
CVE-2025-66468
7.6 HIGH

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript …

Dec 2, 2025
CVE-2025-66460
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66459
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66458
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66454
6.5 MEDIUM

Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret …

Dec 2, 2025
CVE-2025-66416
8.1 HIGH

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context …

Dec 2, 2025
CVE-2025-66414
8.1 HIGH

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK …

Dec 2, 2025
CVE-2025-66409
9.1 CRITICAL

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving …

Dec 2, 2025
CVE-2025-65896
9.8 CRITICAL

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

Dec 2, 2025
CVE-2025-61729
7.5 HIGH

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string …

Dec 2, 2025
CVE-2025-60736
9.8 CRITICAL

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

Dec 2, 2025
CVE-2025-57850
6.4 MEDIUM

A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during …

Dec 2, 2025
CVE-2025-34352

JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\SYSTEM during agent …

Dec 2, 2025
CVE-2025-13721
7.5 HIGH

Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security …

Dec 2, 2025
CVE-2025-13720
8.8 HIGH

Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption …

Dec 2, 2025
CVE-2025-13640
3.5 LOW

Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the device. (Chromium security …

Dec 2, 2025
CVE-2025-13639
8.1 HIGH

Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security …

Dec 2, 2025
CVE-2025-13638
8.8 HIGH

Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Dec 2, 2025
CVE-2025-13637
4.3 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Dec 2, 2025
CVE-2025-13636
4.3 MEDIUM

Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Dec 2, 2025
CVE-2025-13635
4.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Dec 2, 2025
CVE-2025-13634
4.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted …

Dec 2, 2025
CVE-2025-13633
8.8 HIGH

Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit …

Dec 2, 2025
CVE-2025-13632
5.4 MEDIUM

Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a user to install a malicious extension to potentially perform …

Dec 2, 2025
CVE-2025-13631
8.8 HIGH

Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. …

Dec 2, 2025
CVE-2025-13630
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Dec 2, 2025
CVE-2025-66399
8.8 HIGH

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An …

Dec 2, 2025
CVE-2025-65881
6.1 MEDIUM

Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php.

Dec 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.