CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12930
6.3 MEDIUM

A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument …

Nov 10, 2025
CVE-2025-12929
7.3 HIGH

A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument …

Nov 10, 2025
CVE-2025-12928
7.3 HIGH

A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument …

Nov 10, 2025
CVE-2025-12868
9.8 CRITICAL

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain administrator …

Nov 10, 2025
CVE-2025-12867
7.2 HIGH

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling …

Nov 10, 2025
CVE-2025-12927
4.7 MEDIUM

A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of …

Nov 10, 2025
CVE-2025-12926
6.3 MEDIUM

A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of …

Nov 10, 2025
CVE-2025-12866
9.8 CRITICAL

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, …

Nov 10, 2025
CVE-2025-12865
8.8 HIGH

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database …

Nov 10, 2025
CVE-2025-12864
8.8 HIGH

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database …

Nov 10, 2025
CVE-2025-12925
7.3 HIGH

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in …

Nov 10, 2025
CVE-2025-12924
4.3 MEDIUM

A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing …

Nov 10, 2025
CVE-2025-12923
2.7 LOW

A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipulation of the argument …

Nov 10, 2025
CVE-2025-12922
6.3 MEDIUM

A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data …

Nov 10, 2025
CVE-2025-12921
4.3 MEDIUM

A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknown functionality of the file /ImportCRFData?action=confirm of …

Nov 10, 2025
CVE-2025-12920
2.4 LOW

A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation …

Nov 9, 2025
CVE-2025-12919
3.7 LOW

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation …

Nov 9, 2025
CVE-2025-12918
3.1 LOW

A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file …

Nov 9, 2025
CVE-2025-12917
4.3 MEDIUM

A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file /reqproc/proc_post of the component Reboot Handler. …

Nov 9, 2025
CVE-2025-40109

In the Linux kernel, the following vulnerability has been resolved: crypto: rng - Ensure set_ent is always present Ensure that set_ent is always set since …

Nov 9, 2025
CVE-2025-40108

In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: Fix blocked task Revert commit 1afa70632c39 ("serial: qcom-geni: Enable PM runtime for serial …

Nov 9, 2025
CVE-2025-12916
6.3 MEDIUM

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component …

Nov 9, 2025
CVE-2025-12915
6.4 MEDIUM

A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init Script Handler. The manipulation results …

Nov 8, 2025
CVE-2025-12914
4.7 MEDIUM

A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The …

Nov 8, 2025
CVE-2025-12913
4.7 MEDIUM

A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument …

Nov 8, 2025
CVE-2025-12837
6.4 MEDIUM

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in versions up to, and …

Nov 8, 2025
CVE-2025-12643
6.4 MEDIUM

The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay' shortcode in all versions up to, and including, …

Nov 8, 2025
CVE-2025-12399
7.2 HIGH

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST …

Nov 8, 2025
CVE-2025-12092
6.5 MEDIUM

The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality in all versions …

Nov 8, 2025
CVE-2025-11980
4.9 MEDIUM

The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all versions up to, and including, 13.7.3 due …

Nov 8, 2025
CVE-2025-11967
7.2 HIGH

The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_contact_attribute_import function in all versions …

Nov 8, 2025
CVE-2025-11448
4.3 MEDIUM

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Nov 8, 2025
CVE-2025-12099
7.2 HIGH

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …

Nov 8, 2025
CVE-2025-12098
5.3 MEDIUM

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Nov 8, 2025
CVE-2025-12621
5.3 MEDIUM

The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on …

Nov 8, 2025
CVE-2025-12498
4.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note creation due to a missing capability check on …

Nov 8, 2025
CVE-2025-9334
8.8 HIGH

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. …

Nov 8, 2025
CVE-2025-7663
6.5 MEDIUM

The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /class-ovaem-ajax.php file …

Nov 8, 2025
CVE-2025-12353
5.3 MEDIUM

The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user …

Nov 8, 2025
CVE-2025-12193
6.1 MEDIUM

The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all versions up to, and including, 2.3.1 …

Nov 8, 2025
CVE-2025-12177
5.3 MEDIUM

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in …

Nov 8, 2025
CVE-2025-12167
4.3 MEDIUM

The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_aweber_logreset' …

Nov 8, 2025
CVE-2025-12161
8.8 HIGH

The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creation functionality …

Nov 8, 2025
CVE-2025-12125
4.4 MEDIUM

The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

Nov 8, 2025
CVE-2025-12112
6.4 MEDIUM

The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adding scripts in all versions up …

Nov 8, 2025
CVE-2025-12064
6.1 MEDIUM

The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 2.4.7 due to …

Nov 8, 2025
CVE-2025-12042
5.3 MEDIUM

The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the csv-export.php file in …

Nov 8, 2025
CVE-2025-12000
6.5 MEDIUM

The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpfnl_delete_log() function in all versions up …

Nov 8, 2025
CVE-2025-11972
4.9 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all …

Nov 8, 2025
CVE-2025-11748
4.3 MEDIUM

The Groups plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.0 via the 'group_id' parameter of …

Nov 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.