CVE Database

113799+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-57198
8.8 HIGH

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi endpoint. This vulnerability allows attackers to execute arbitrary …

Dec 3, 2025
CVE-2025-55182
10.0 CRITICAL KEV

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. …

Dec 3, 2025
CVE-2025-65267
9.0 CRITICAL

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an …

Dec 3, 2025
CVE-2025-57200
6.5 MEDIUM

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary …

Dec 3, 2025
CVE-2025-53841
7.8 HIGH

The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege …

Dec 3, 2025
CVE-2025-13949
6.3 MEDIUM

A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.go. The manipulation of the argument File leads to …

Dec 3, 2025
CVE-2025-13948
5.6 MEDIUM

A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. …

Dec 3, 2025
CVE-2025-13756
4.3 MEDIUM

The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in …

Dec 3, 2025
CVE-2025-13401
6.4 MEDIUM

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, …

Dec 3, 2025
CVE-2025-13390
10.0 CRITICAL

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of …

Dec 3, 2025
CVE-2025-13359
6.5 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in …

Dec 3, 2025
CVE-2025-13354
4.3 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and …

Dec 3, 2025
CVE-2025-13342
9.8 CRITICAL

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. …

Dec 3, 2025
CVE-2025-13109
4.3 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Dec 3, 2025
CVE-2025-12887
5.4 MEDIUM

The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin …

Dec 3, 2025
CVE-2025-12358
4.3 MEDIUM

The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is …

Dec 3, 2025
CVE-2025-39665
5.3 MEDIUM

User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.

Dec 3, 2025
CVE-2025-13947
7.4 HIGH

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via …

Dec 3, 2025
CVE-2025-29864

Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 before 12.29.

Dec 3, 2025
CVE-2025-13472

A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like …

Dec 3, 2025
CVE-2025-12744
8.8 HIGH

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them …

Dec 3, 2025
CVE-2025-13946
5.5 MEDIUM

MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service

Dec 3, 2025
CVE-2025-13945
5.5 MEDIUM

HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

Dec 3, 2025
CVE-2025-13486
9.8 CRITICAL

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is …

Dec 3, 2025
CVE-2025-12954
2.7 LOW

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading …

Dec 3, 2025
CVE-2025-13495
4.9 MEDIUM

The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, and including, 1.3.1. This is due …

Dec 3, 2025
CVE-2025-12585
5.3 MEDIUM

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 via …

Dec 3, 2025
CVE-2025-10304
5.3 MEDIUM

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Dec 3, 2025
CVE-2025-13646
7.5 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions …

Dec 3, 2025
CVE-2025-13645
7.2 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions …

Dec 3, 2025
CVE-2025-13448
6.4 MEDIUM

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 …

Dec 3, 2025
CVE-2025-65955
4.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ …

Dec 2, 2025
CVE-2025-66476
7.8 HIGH

Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious …

Dec 2, 2025
CVE-2025-55181
5.3 MEDIUM

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends …

Dec 2, 2025
CVE-2025-65657
6.5 MEDIUM

FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files …

Dec 2, 2025
CVE-2025-65380
6.5 MEDIUM

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated …

Dec 2, 2025
CVE-2025-64778
7.3 HIGH

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application …

Dec 2, 2025
CVE-2025-64642
8.0 HIGH

NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations …

Dec 2, 2025
CVE-2025-64298
8.4 HIGH

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked …

Dec 2, 2025
CVE-2025-62575
8.3 HIGH

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the …

Dec 2, 2025
CVE-2025-61940
8.3 HIGH

NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application …

Dec 2, 2025
CVE-2025-65877
7.5 HIGH

Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 'title' parameter in com.wanli.lvzhoucms.service.ContentService#findPage. The parameter is concatenated directly into a dynamic …

Dec 2, 2025
CVE-2025-65379
6.5 MEDIUM

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is …

Dec 2, 2025
CVE-2025-13658

A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence of code signing …

Dec 2, 2025
CVE-2025-13542
9.8 CRITICAL

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' …

Dec 2, 2025
CVE-2025-13510

The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated users to access and modify critical …

Dec 2, 2025
CVE-2025-66468
7.6 HIGH

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript …

Dec 2, 2025
CVE-2025-66460
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66459
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66458
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.