CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13085
4.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta Disclosure in versions up to and including …

Nov 19, 2025
CVE-2025-12535
5.3 MEDIUM

The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the …

Nov 19, 2025
CVE-2025-12056

Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.

Nov 19, 2025
CVE-2025-11243

Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allocation via network.

Nov 19, 2025
CVE-2025-13145
7.2 HIGH

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …

Nov 19, 2025
CVE-2025-13054
6.4 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 19, 2025
CVE-2025-12878
6.4 MEDIUM

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up …

Nov 19, 2025
CVE-2025-12842
5.3 MEDIUM

The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 …

Nov 19, 2025
CVE-2025-12822
4.3 MEDIUM

The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Nov 19, 2025
CVE-2025-12814
5.3 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect capability check on the siteseo_reset_settings function …

Nov 19, 2025
CVE-2025-12751
4.3 MEDIUM

The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'reset_settings' …

Nov 19, 2025
CVE-2025-12710
6.4 MEDIUM

The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shortcode in all versions up to, and including, 3.6.1 …

Nov 19, 2025
CVE-2025-12646
7.5 HIGH

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to …

Nov 19, 2025
CVE-2025-12359
5.4 MEDIUM

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' …

Nov 19, 2025
CVE-2025-12174
6.5 MEDIUM

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Nov 19, 2025
CVE-2025-12057
9.8 CRITICAL

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied …

Nov 19, 2025
CVE-2025-12426
5.3 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the …

Nov 19, 2025
CVE-2025-12349
5.3 MEDIUM

The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This …

Nov 19, 2025
CVE-2025-6251
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 …

Nov 19, 2025
CVE-2025-65941

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65940

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65939

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65938

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65937

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65936

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65935

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65934

Rejected reason: Not used

Nov 19, 2025
CVE-2025-65933

Rejected reason: Not used

Nov 19, 2025
CVE-2025-13051

When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with …

Nov 19, 2025
CVE-2025-12777
5.3 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the …

Nov 19, 2025
CVE-2025-12770
5.3 MEDIUM

The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API …

Nov 19, 2025
CVE-2025-12427
5.3 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST …

Nov 19, 2025
CVE-2025-13225
5.6 MEDIUM

Tanium addressed an arbitrary file deletion vulnerability in TanOS.

Nov 19, 2025
CVE-2025-12852

DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to cause unintended operations on the …

Nov 19, 2025
CVE-2025-65093
5.5 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application …

Nov 18, 2025
CVE-2025-65015
7.5 HIGH

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 …

Nov 18, 2025
CVE-2025-65014
3.7 LOW

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality …

Nov 18, 2025
CVE-2025-65013
6.2 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application …

Nov 18, 2025
CVE-2025-65012
5.4 MEDIUM

Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any …

Nov 18, 2025
CVE-2025-64515
4.3 MEDIUM

Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data fields are dynamically set to …

Nov 18, 2025
CVE-2025-64325
9.0 CRITICAL

Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request …

Nov 18, 2025
CVE-2025-64324
7.7 HIGH

KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user …

Nov 18, 2025
CVE-2025-62406
8.1 HIGH

Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset …

Nov 18, 2025
CVE-2025-54990
5.3 MEDIUM

XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights …

Nov 18, 2025
CVE-2025-63229
5.4 MEDIUM

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious …

Nov 18, 2025
CVE-2025-63217
9.8 CRITICAL

The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT …

Nov 18, 2025
CVE-2025-63216
10.0 CRITICAL

The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT …

Nov 18, 2025
CVE-2025-63215
7.2 HIGH

The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate …

Nov 18, 2025
CVE-2025-12119
6.8 MEDIUM

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

Nov 18, 2025
CVE-2025-63228
9.8 CRITICAL

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this …

Nov 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.