CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5317
5.5 MEDIUM

An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass …

Nov 11, 2025
CVE-2025-10714
8.4 HIGH

AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can …

Nov 11, 2025
CVE-2025-8108
6.7 MEDIUM

An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if …

Nov 11, 2025
CVE-2025-6779
6.7 MEDIUM

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if …

Nov 11, 2025
CVE-2025-6571
6.0 MEDIUM

A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.

Nov 11, 2025
CVE-2025-6298
6.7 MEDIUM

ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis …

Nov 11, 2025
CVE-2025-5718
6.8 MEDIUM

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to …

Nov 11, 2025
CVE-2025-5454
6.4 MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be …

Nov 11, 2025
CVE-2025-5452
6.6 MEDIUM

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious …

Nov 11, 2025
CVE-2025-4645
6.7 MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device …

Nov 11, 2025
CVE-2025-11855
7.5 HIGH

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin …

Nov 11, 2025
CVE-2025-11307
8.8 HIGH

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users …

Nov 11, 2025
CVE-2025-11237
5.3 MEDIUM

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, …

Nov 11, 2025
CVE-2025-12880
5.4 MEDIUM

The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 11, 2025
CVE-2025-12813
9.8 CRITICAL

The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' …

Nov 11, 2025
CVE-2025-12754
6.4 MEDIUM

The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost' shortcode in all versions up to, and …

Nov 11, 2025
CVE-2025-12753
6.4 MEDIUM

The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in all versions up to, and including, 1.0. This …

Nov 11, 2025
CVE-2025-12711
6.4 MEDIUM

The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google shortcode in all versions up to, and including, …

Nov 11, 2025
CVE-2025-12672
6.4 MEDIUM

The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the 'flickrshow' shortcode in all versions up to, …

Nov 11, 2025
CVE-2025-12671
6.4 MEDIUM

The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, …

Nov 11, 2025
CVE-2025-12668
6.4 MEDIUM

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12667
6.4 MEDIUM

The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'gist' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12665
4.3 MEDIUM

The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Nov 11, 2025
CVE-2025-12663
6.4 MEDIUM

The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the 'jeba_forkit' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12662
6.4 MEDIUM

The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the 'map' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12658
6.4 MEDIUM

The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' parameter in the 'preload_progress_bar' shortcode in all versions up …

Nov 11, 2025
CVE-2025-12652
6.4 MEDIUM

The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter in the ungapped-form shortcode in all versions up to, …

Nov 11, 2025
CVE-2025-12651
6.4 MEDIUM

The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img_src', and 'class' parameters in the livephotos_photo shortcode …

Nov 11, 2025
CVE-2025-12644
6.4 MEDIUM

The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nonaki' shortcode in …

Nov 11, 2025
CVE-2025-12637
8.8 HIGH

The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation feature in the process_theme function in …

Nov 11, 2025
CVE-2025-12632
5.5 MEDIUM

The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.4 due to insufficient …

Nov 11, 2025
CVE-2025-12631
4.4 MEDIUM

The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due …

Nov 11, 2025
CVE-2025-12590
6.1 MEDIUM

The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.1. This is …

Nov 11, 2025
CVE-2025-12589
6.1 MEDIUM

The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 0.5.3.5. This is …

Nov 11, 2025
CVE-2025-12588
4.3 MEDIUM

The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This …

Nov 11, 2025
CVE-2025-12538
4.4 MEDIUM

The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.1 due to …

Nov 11, 2025
CVE-2025-12526
4.3 MEDIUM

The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in …

Nov 11, 2025
CVE-2025-12132
4.3 MEDIUM

The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8.4. This …

Nov 11, 2025
CVE-2025-12126
5.4 MEDIUM

The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via several …

Nov 11, 2025
CVE-2025-12021
6.1 MEDIUM

The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 0.4.1 due to …

Nov 11, 2025
CVE-2025-12020
4.9 MEDIUM

The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin …

Nov 11, 2025
CVE-2025-12019
4.4 MEDIUM

The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions up to, and including, 2.1 due to …

Nov 11, 2025
CVE-2025-12010
6.5 MEDIUM

The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method …

Nov 11, 2025
CVE-2025-11999
5.3 MEDIUM

The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and …

Nov 11, 2025
CVE-2025-11997
5.3 MEDIUM

The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9. …

Nov 11, 2025
CVE-2025-11996
5.3 MEDIUM

The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() …

Nov 11, 2025
CVE-2025-11988
5.3 MEDIUM

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the …

Nov 11, 2025
CVE-2025-11986
5.3 MEDIUM

The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering …

Nov 11, 2025
CVE-2025-11894
5.3 MEDIUM

The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in …

Nov 11, 2025
CVE-2025-11891
5.3 MEDIUM

The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files. …

Nov 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.