CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13370
4.9 MEDIUM

The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 0.3.0 due to …

Nov 25, 2025
CVE-2025-13311
4.4 MEDIUM

The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting in all versions up to, and including, 1.0.3 …

Nov 25, 2025
CVE-2025-12645
6.4 MEDIUM

The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcode in all versions up to, and including, …

Nov 25, 2025
CVE-2025-12634
4.3 MEDIUM

The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_refund_status' function …

Nov 25, 2025
CVE-2025-12587
4.3 MEDIUM

The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Nov 25, 2025
CVE-2025-12586
4.3 MEDIUM

The Conditional Maintenance Mode for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is …

Nov 25, 2025
CVE-2025-12525
5.3 MEDIUM

The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'lockerco_submit_post' AJAX endpoint. This makes it possible for …

Nov 25, 2025
CVE-2025-12043
5.3 MEDIUM

The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint …

Nov 25, 2025
CVE-2025-12040
6.5 MEDIUM

The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.3 via several functions …

Nov 25, 2025
CVE-2025-12032
4.4 MEDIUM

The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vithanhlam_zsocial_save_messager’, 'vithanhlam_zsocial_save_zalo', 'vithanhlam_zsocial_save_hotline', and …

Nov 25, 2025
CVE-2025-12025
4.4 MEDIUM

The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.0 due to …

Nov 25, 2025
CVE-2025-12003

A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to the …

Nov 25, 2025
CVE-2025-13644
6.5 MEDIUM

MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of …

Nov 25, 2025
CVE-2025-13643
3.1 LOW

A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by …

Nov 25, 2025
CVE-2025-12742

A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Looker-hosted and …

Nov 25, 2025
CVE-2025-64730
6.1 MEDIUM

Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the …

Nov 25, 2025
CVE-2025-64304
4.0 MEDIUM

"FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptographic keys.

Nov 25, 2025
CVE-2025-62497
6.5 MEDIUM

Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logged in, unintended operations may …

Nov 25, 2025
CVE-2025-13559
9.8 CRITICAL

The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'edukart_pro_register_user_front_end' …

Nov 25, 2025
CVE-2025-13558
5.4 MEDIUM

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Nov 25, 2025
CVE-2025-13507
6.5 MEDIUM

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process …

Nov 25, 2025
CVE-2025-13068
7.2 HIGH

The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username in all versions up to, and including, …

Nov 25, 2025
CVE-2025-12893
4.2 MEDIUM

Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Extended Key Usage (EKU) …

Nov 25, 2025
CVE-2025-66187

Rejected reason: Not used

Nov 25, 2025
CVE-2025-66186

Rejected reason: Not used

Nov 25, 2025
CVE-2025-66185

Rejected reason: Not used

Nov 25, 2025
CVE-2025-66184

Rejected reason: Not used

Nov 25, 2025
CVE-2025-66183

Rejected reason: Not used

Nov 25, 2025
CVE-2025-66182

Rejected reason: Not used

Nov 25, 2025
CVE-2025-66181

Rejected reason: Not used

Nov 25, 2025
CVE-2025-66180

Rejected reason: Not used

Nov 25, 2025
CVE-2025-66179

Rejected reason: Not used

Nov 25, 2025
CVE-2025-10646
4.3 MEDIUM

The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capability check on the Base::get_rest_permission() method in all …

Nov 25, 2025
CVE-2025-6389
9.8 CRITICAL

The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pagination_callback() function. This …

Nov 25, 2025
CVE-2025-59373

A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivileged actor copies files …

Nov 25, 2025
CVE-2025-9803
8.8 HIGH

lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' …

Nov 25, 2025
CVE-2025-65951
8.7 HIGH

Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based timelock encryption system fails to enforce sequential delay …

Nov 25, 2025
CVE-2025-65944

Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js application using the Sentry SDK has sendDefaultPii: true …

Nov 25, 2025
CVE-2025-64761
7.2 HIGH

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a …

Nov 25, 2025
CVE-2025-65018
7.1 HIGH

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to …

Nov 25, 2025
CVE-2025-64720
7.1 HIGH

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to …

Nov 25, 2025
CVE-2025-64506
6.1 MEDIUM

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to …

Nov 25, 2025
CVE-2025-64505
6.1 MEDIUM

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, …

Nov 25, 2025
CVE-2025-62155
8.5 HIGH

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability …

Nov 25, 2025
CVE-2025-10144
6.5 MEDIUM

The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortcode in all versions …

Nov 24, 2025
CVE-2025-63674
6.8 MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

Nov 24, 2025
CVE-2025-54563
7.5 HIGH

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading …

Nov 24, 2025
CVE-2025-54347
9.9 CRITICAL

A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to write arbitrary …

Nov 24, 2025
CVE-2025-54341
5.3 MEDIUM

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.

Nov 24, 2025
CVE-2025-54338
7.5 HIGH

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose …

Nov 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.