CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12881
5.4 MEDIUM

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 …

Nov 21, 2025
CVE-2025-12746
6.1 MEDIUM

The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 1.0.0 due to …

Nov 21, 2025
CVE-2025-12661
6.4 MEDIUM

The Pollcaster Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the 'pollcaster' shortcode in all versions up to, …

Nov 21, 2025
CVE-2025-12660
6.4 MEDIUM

The Padlet Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'key' parameter in the 'wallwisher' shortcode in all versions up to, …

Nov 21, 2025
CVE-2025-12170
5.3 MEDIUM

The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_ajax_nopriv_checkbox_clean_log' AJAX endpoint in all …

Nov 21, 2025
CVE-2025-12138
8.8 HIGH

The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and …

Nov 21, 2025
CVE-2025-12135
7.2 HIGH

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to …

Nov 21, 2025
CVE-2025-12086
4.3 MEDIUM

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 …

Nov 21, 2025
CVE-2025-11985
8.8 HIGH

The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check …

Nov 21, 2025
CVE-2025-11885
6.1 MEDIUM

The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parameter in all versions up to, and including, 1.3.0 …

Nov 21, 2025
CVE-2025-11815
4.3 MEDIUM

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 21, 2025
CVE-2025-11802
6.4 MEDIUM

The Bulma Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' shortcode attribute in the bulma-notification shortcode in all versions up …

Nov 21, 2025
CVE-2025-11801
6.4 MEDIUM

The AudioTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' shortcode attribute of the 'audiotube' shortcode in all versions up to, …

Nov 21, 2025
CVE-2025-11800
6.4 MEDIUM

The Surbma | MiniCRM Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the 'minicrm' shortcode in all …

Nov 21, 2025
CVE-2025-11799
6.4 MEDIUM

The Affiliate AI Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'asin' shortcode attribute in the affiai_img shortcode in all versions …

Nov 21, 2025
CVE-2025-11773
4.3 MEDIUM

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 21, 2025
CVE-2025-11771
5.3 MEDIUM

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to …

Nov 21, 2025
CVE-2025-11770
6.4 MEDIUM

The BrightTALK WordPress Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attribute in the brighttalk-time shortcode in all versions …

Nov 21, 2025
CVE-2025-11768
6.4 MEDIUM

The Islamic Phrases plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phrases' shortcode attribute in all versions up to, and including, 2.12.2015. …

Nov 21, 2025
CVE-2025-11767
6.4 MEDIUM

The Tips Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tip' shortcode in all versions up to, and including, 0.2.1. This …

Nov 21, 2025
CVE-2025-11765
6.4 MEDIUM

The Stock Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_height' and 'image_width' shortcode attributes in all versions up to, and …

Nov 21, 2025
CVE-2025-11764
6.4 MEDIUM

The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the [notification] shortcode in all versions up to, …

Nov 21, 2025
CVE-2025-11763
6.4 MEDIUM

The Display Pages Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column_count' parameter in the [display-pages] shortcode in all versions up …

Nov 21, 2025
CVE-2025-11456
9.8 CRITICAL

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Nov 21, 2025
CVE-2025-11003
6.4 MEDIUM

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 21, 2025
CVE-2025-10938
6.5 MEDIUM

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing …

Nov 21, 2025
CVE-2025-64695
7.8 HIGH

Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of …

Nov 21, 2025
CVE-2025-64299
2.7 LOW

LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes.

Nov 21, 2025
CVE-2025-62687
6.5 MEDIUM

Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed.

Nov 21, 2025
CVE-2025-62189
4.3 MEDIUM

LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP …

Nov 21, 2025
CVE-2025-61949
5.4 MEDIUM

LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web …

Nov 21, 2025
CVE-2025-58097
7.8 HIGH

The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary …

Nov 21, 2025
CVE-2025-9825
5.0 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have …

Nov 21, 2025
CVE-2025-13499
7.8 HIGH

Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service

Nov 21, 2025
CVE-2025-12169
4.3 MEDIUM

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Nov 21, 2025
CVE-2025-12085
4.3 MEDIUM

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Nov 21, 2025
CVE-2025-12023
4.3 MEDIUM

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Nov 21, 2025
CVE-2025-12022
4.3 MEDIUM

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Nov 21, 2025
CVE-2025-11368
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is …

Nov 21, 2025
CVE-2025-64310
9.8 CRITICAL

EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through …

Nov 21, 2025
CVE-2025-64762
9.1 CRITICAL

The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and below, …

Nov 21, 2025
CVE-2025-64755
9.8 CRITICAL

Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the …

Nov 21, 2025
CVE-2025-64751
8.8 HIGH

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart …

Nov 21, 2025
CVE-2025-62426
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize endpoints allow a …

Nov 21, 2025
CVE-2025-62372
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving …

Nov 21, 2025
CVE-2025-62164
8.8 HIGH

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to …

Nov 21, 2025
CVE-2025-13485
7.3 HIGH

A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation …

Nov 21, 2025
CVE-2025-64660
8.0 HIGH

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

Nov 20, 2025
CVE-2025-64655
8.8 HIGH

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

Nov 20, 2025
CVE-2025-62459
8.3 HIGH

Microsoft Defender Portal Spoofing Vulnerability

Nov 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.