CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11886
4.3 MEDIUM

The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to …

Nov 11, 2025
CVE-2025-11882
6.4 MEDIUM

The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortcode in versions less than, or equal to, 1.0 …

Nov 11, 2025
CVE-2025-11874
5.4 MEDIUM

The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slippy-slider' shortcode in all versions …

Nov 11, 2025
CVE-2025-11873
6.4 MEDIUM

The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 1.8.1 …

Nov 11, 2025
CVE-2025-11869
6.4 MEDIUM

The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attribute in all versions up to, and including, 1.0. …

Nov 11, 2025
CVE-2025-11863
6.4 MEDIUM

The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode in all versions up to, and including, …

Nov 11, 2025
CVE-2025-11860
6.4 MEDIUM

The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This …

Nov 11, 2025
CVE-2025-11859
6.4 MEDIUM

The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. …

Nov 11, 2025
CVE-2025-11856
6.4 MEDIUM

The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketwidget' shortcode in all versions up to, and including, 1.0. …

Nov 11, 2025
CVE-2025-11829
6.4 MEDIUM

The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the [five9-chat] shortcode in all versions up …

Nov 11, 2025
CVE-2025-11828
6.4 MEDIUM

The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, …

Nov 11, 2025
CVE-2025-11822
6.4 MEDIUM

The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcode in all versions up to, and including, 1.0.4. …

Nov 11, 2025
CVE-2025-11821
6.4 MEDIUM

The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_products_custom_tax' shortcode in all versions up to, …

Nov 11, 2025
CVE-2025-11805
6.4 MEDIUM

The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in all versions up to, and including, 1.4.4. …

Nov 11, 2025
CVE-2025-11532
5.3 MEDIUM

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validation on …

Nov 11, 2025
CVE-2025-11521
8.1 HIGH

The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs …

Nov 11, 2025
CVE-2025-11457
9.8 CRITICAL

The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.8.2. This is …

Nov 11, 2025
CVE-2025-11451
7.5 HIGH

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, …

Nov 11, 2025
CVE-2025-11170
9.8 CRITICAL

The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Import_Controller::import function in all …

Nov 11, 2025
CVE-2025-11168
8.8 HIGH

The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5. This is due to plugin not …

Nov 11, 2025
CVE-2025-11129
6.4 MEDIUM

The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'type' parameters in all versions up to, and …

Nov 11, 2025
CVE-2025-42940
7.5 HIGH

SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed …

Nov 11, 2025
CVE-2025-42924
6.1 MEDIUM

SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled …

Nov 11, 2025
CVE-2025-42919
5.3 MEDIUM

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could …

Nov 11, 2025
CVE-2025-42899
4.3 MEDIUM

SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. This has low impact on …

Nov 11, 2025
CVE-2025-42897
5.3 MEDIUM

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized …

Nov 11, 2025
CVE-2025-42895
6.9 MEDIUM

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead …

Nov 11, 2025
CVE-2025-42894
6.8 MEDIUM

Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete …

Nov 11, 2025
CVE-2025-42893
6.1 MEDIUM

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects …

Nov 11, 2025
CVE-2025-42892
6.8 MEDIUM

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted …

Nov 11, 2025
CVE-2025-42890
10.0 CRITICAL

SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code …

Nov 11, 2025
CVE-2025-42889
5.4 MEDIUM

SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this vulnerability has a low …

Nov 11, 2025
CVE-2025-42888
5.5 MEDIUM

SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during …

Nov 11, 2025
CVE-2025-42887
9.9 CRITICAL

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide …

Nov 11, 2025
CVE-2025-42886
6.1 MEDIUM

Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. …

Nov 11, 2025
CVE-2025-42885
5.8 MEDIUM

Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled function that will enable them to view information. As …

Nov 11, 2025
CVE-2025-42884
6.5 MEDIUM

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to …

Nov 11, 2025
CVE-2025-42883
2.7 LOW

Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files …

Nov 11, 2025
CVE-2025-42882
4.3 MEDIUM

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module …

Nov 11, 2025
CVE-2025-31719
5.1 MEDIUM

In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature results with low probability.

Nov 11, 2025
CVE-2025-64529
6.5 MEDIUM

SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator …

Nov 10, 2025
CVE-2025-64522
9.1 CRITICAL

Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, …

Nov 10, 2025
CVE-2025-64519
8.8 HIGH

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL injection vulnerability exists …

Nov 10, 2025
CVE-2025-63678
7.2 HIGH

An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute …

Nov 10, 2025
CVE-2025-12542

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 10, 2025
CVE-2025-11892
9.6 CRITICAL

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross-site scripting via Issues search label filter that could lead …

Nov 10, 2025
CVE-2025-11578
7.2 HIGH

A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by …

Nov 10, 2025
CVE-2021-4462
9.8 CRITICAL

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; …

Nov 10, 2025
CVE-2018-25124

PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within the web-based DICOM viewer component. Successful exploitation allows a remote …

Nov 10, 2025
CVE-2025-64518
7.5 HIGH

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version …

Nov 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.