CVE Database

113799+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13006
5.3 MEDIUM

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via …

Dec 5, 2025
CVE-2025-12417
6.4 MEDIUM

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, …

Dec 5, 2025
CVE-2025-66544

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66543

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66542

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66541

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66540

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66539

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66538

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66537

Rejected reason: Not used

Dec 5, 2025
CVE-2025-66536

Rejected reason: Not used

Dec 5, 2025
CVE-2025-27389

A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, …

Dec 5, 2025
CVE-2025-13066
8.8 HIGH

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to …

Dec 5, 2025
CVE-2025-12804
6.4 MEDIUM

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 …

Dec 5, 2025
CVE-2025-11759
4.3 MEDIUM

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 5, 2025
CVE-2025-62223
4.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Dec 5, 2025
CVE-2025-14052
6.3 MEDIUM

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the …

Dec 5, 2025
CVE-2025-66564
7.5 HIGH

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided …

Dec 4, 2025
CVE-2025-66563
6.1 MEDIUM

Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute …

Dec 4, 2025
CVE-2025-66561
7.3 HIGH

SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious …

Dec 4, 2025
CVE-2025-66559

Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising its fundamental properties. In 2.3.1 and earlier, TaikoInbox._verifyBatches (packages/protocol/contracts/layer1/based/TaikoInbox.sol:627-678) advanced the …

Dec 4, 2025
CVE-2025-14051
6.3 MEDIUM

A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control …

Dec 4, 2025
CVE-2025-13373
7.5 HIGH

Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.

Dec 4, 2025
CVE-2025-6946
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the IPS module. This …

Dec 4, 2025
CVE-2025-66509
9.8 CRITICAL

LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to …

Dec 4, 2025
CVE-2025-66506
7.5 HIGH

Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a …

Dec 4, 2025
CVE-2025-66238
7.2 HIGH

DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features …

Dec 4, 2025
CVE-2025-65900
6.5 MEDIUM

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in …

Dec 4, 2025
CVE-2025-65899
5.3 MEDIUM

Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid …

Dec 4, 2025
CVE-2025-53704
7.5 HIGH

The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.

Dec 4, 2025
CVE-2025-1910

The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the …

Dec 4, 2025
CVE-2025-1547
7.2 HIGH

A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially …

Dec 4, 2025
CVE-2025-1545
7.5 HIGH

An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from the Firebox configuration through an exposed …

Dec 4, 2025
CVE-2025-13940
5.5 MEDIUM

An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and …

Dec 4, 2025
CVE-2025-13939
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.This issue …

Dec 4, 2025
CVE-2025-13938
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.This issue …

Dec 4, 2025
CVE-2025-13937
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.This issue …

Dec 4, 2025
CVE-2025-13936
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.This issue …

Dec 4, 2025
CVE-2025-13932

The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data …

Dec 4, 2025
CVE-2025-12986

When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service triggered by a malformed …

Dec 4, 2025
CVE-2025-12196
7.2 HIGH

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.This …

Dec 4, 2025
CVE-2025-12195
7.2 HIGH

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI …

Dec 4, 2025
CVE-2025-12026
7.2 HIGH

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI …

Dec 4, 2025
CVE-2025-11838
7.5 HIGH

A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User …

Dec 4, 2025
CVE-2025-10285

The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker …

Dec 4, 2025
CVE-2025-66576
9.8 CRITICAL

Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.

Dec 4, 2025
CVE-2025-66575
7.8 HIGH

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. …

Dec 4, 2025
CVE-2025-66574
5.4 MEDIUM

TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate …

Dec 4, 2025
CVE-2025-66573
7.5 HIGH

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, …

Dec 4, 2025
CVE-2025-66572

Loaded Commerce 6.6 contains a client-side template injection vulnerability that allows unauthenticated attackers to execute code on the server via the search parameter.

Dec 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.