CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13765
4.3 MEDIUM

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Nov 27, 2025
CVE-2025-13758
3.5 LOW

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Nov 27, 2025
CVE-2025-13757
8.8 HIGH

SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.

Nov 27, 2025
CVE-2025-12419
9.9 CRITICAL

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication …

Nov 27, 2025
CVE-2025-8890

Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks. In order to exploit …

Nov 27, 2025
CVE-2025-13692
7.2 HIGH

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Nov 27, 2025
CVE-2025-12140

The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter' parameter. The application interprets the entered string of characters as …

Nov 27, 2025
CVE-2025-12971
4.3 MEDIUM

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due …

Nov 27, 2025
CVE-2025-59454
4.3 MEDIUM

In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs …

Nov 27, 2025
CVE-2025-59302
4.7 MEDIUM

In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * …

Nov 27, 2025
CVE-2025-54057
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: <= 10.2.0. Users are …

Nov 27, 2025
CVE-2025-59890
7.3 HIGH

Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an attacker with local access …

Nov 27, 2025
CVE-2025-13742
6.1 MEDIUM

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it …

Nov 27, 2025
CVE-2025-10476
4.3 MEDIUM

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in …

Nov 27, 2025
CVE-2025-59026
5.4 MEDIUM

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-59025
6.1 MEDIUM

Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of …

Nov 27, 2025
CVE-2025-30190
5.4 MEDIUM

Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-30186
5.4 MEDIUM

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of …

Nov 27, 2025
CVE-2025-13381
5.3 MEDIUM

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Nov 27, 2025
CVE-2025-13378
6.5 MEDIUM

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Nov 27, 2025
CVE-2025-12584
5.3 MEDIUM

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX …

Nov 27, 2025
CVE-2025-13536
8.8 HIGH

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, …

Nov 27, 2025
CVE-2025-13441
5.3 MEDIUM

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This …

Nov 27, 2025
CVE-2025-13157
5.3 MEDIUM

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the …

Nov 27, 2025
CVE-2025-13525
6.1 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 …

Nov 27, 2025
CVE-2025-13143
4.3 MEDIUM

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Nov 27, 2025
CVE-2025-12185
4.4 MEDIUM

The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient …

Nov 27, 2025
CVE-2025-12123
6.1 MEDIUM

The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email-text' parameter in all versions up to, and …

Nov 27, 2025
CVE-2025-7820
7.5 HIGH

The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.4. This is due to …

Nov 27, 2025
CVE-2025-3784
5.5 MEDIUM

Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As …

Nov 27, 2025
CVE-2025-13680
8.8 HIGH

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing …

Nov 27, 2025
CVE-2025-13675
9.8 CRITICAL

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.php' file …

Nov 27, 2025
CVE-2025-13540
9.8 CRITICAL

The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_membership_init_rest_api_register' …

Nov 27, 2025
CVE-2025-13539
9.8 CRITICAL

The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin …

Nov 27, 2025
CVE-2025-13538
9.8 CRITICAL

The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'findall_listing_user_registration_additional_params' …

Nov 27, 2025
CVE-2025-12758
7.5 HIGH

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that …

Nov 27, 2025
CVE-2025-12151
6.4 MEDIUM

The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in all versions up to, and including, 1.1.0 due …

Nov 27, 2025
CVE-2025-66314
7.5 HIGH

Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ElasticNet UME R32: ElasticNet_UME_R32_V16.23.20.04.

Nov 27, 2025
CVE-2025-34351

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. At the request of the MITRE TL-Root and following the …

Nov 27, 2025
CVE-2025-13762

Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This …

Nov 27, 2025
CVE-2025-12713
6.4 MEDIUM

The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to …

Nov 27, 2025
CVE-2025-12712
6.4 MEDIUM

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up to, and including, 0.2.1 due to …

Nov 27, 2025
CVE-2025-12670
6.4 MEDIUM

The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic' shortcode in all versions up to, and including, …

Nov 27, 2025
CVE-2025-12666
6.4 MEDIUM

The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in …

Nov 27, 2025
CVE-2025-12649
6.4 MEDIUM

The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sorttablepost shortcode in all versions up to, …

Nov 27, 2025
CVE-2025-12579
5.3 MEDIUM

The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action in all …

Nov 27, 2025
CVE-2025-12578
4.3 MEDIUM

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing …

Nov 27, 2025
CVE-2025-0658

A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; after a …

Nov 27, 2025
CVE-2025-0657

A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed packets to be sent through BACnet MS/TP network causing …

Nov 27, 2025
CVE-2024-5540

The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to …

Nov 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.