CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39466
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue …

Nov 6, 2025
CVE-2025-39465
4.3 MEDIUM

Missing Authorization vulnerability in flippercode Advanced Google Maps wp-google-map-gold allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Google Maps: from n/a through …

Nov 6, 2025
CVE-2025-39463
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Dessau dessau allows PHP Local File Inclusion.This issue …

Nov 6, 2025
CVE-2025-32222
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic allows Code Injection.This issue affects Widget Logic: from n/a through <= …

Nov 6, 2025
CVE-2025-31029
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail replymail allows Stored XSS.This issue affects replyMail: from n/a through <= …

Nov 6, 2025
CVE-2025-28953
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart SEO smartSEO allows SQL Injection.This issue affects smart SEO: …

Nov 6, 2025
CVE-2025-22288
4.1 MEDIUM

Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image …

Nov 6, 2025
CVE-2025-12556
8.8 HIGH

An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary code within the context of the host machine.

Nov 6, 2025
CVE-2025-37735
7.0 HIGH

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running …

Nov 6, 2025
CVE-2025-36054
6.1 MEDIUM

IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 …

Nov 6, 2025
CVE-2025-11956
8.9 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Stored …

Nov 6, 2025
CVE-2025-10955
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows XSS Through HTTP Query Strings.This issue …

Nov 6, 2025
CVE-2025-11268
4.3 MEDIUM

The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the …

Nov 6, 2025
CVE-2025-12360
4.3 MEDIUM

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the …

Nov 6, 2025
CVE-2025-10259
5.3 MEDIUM

Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote attacker …

Nov 6, 2025
CVE-2025-12471
6.1 MEDIUM

The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in …

Nov 6, 2025
CVE-2025-9338

A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a …

Nov 6, 2025
CVE-2025-12560
4.3 MEDIUM

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 8.6.0 …

Nov 6, 2025
CVE-2025-61994
5.4 MEDIUM

Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed …

Nov 6, 2025
CVE-2025-12563
4.3 MEDIUM

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() …

Nov 6, 2025
CVE-2025-11271
5.3 MEDIUM

The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification …

Nov 6, 2025
CVE-2025-64480

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64479

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64478

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64477

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64476

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64475

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64474

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64473

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64472

Rejected reason: Not used

Nov 6, 2025
CVE-2025-10691
4.3 MEDIUM

The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to …

Nov 6, 2025
CVE-2025-10683
4.9 MEDIUM

The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions up to, and including, 1.3 due …

Nov 6, 2025
CVE-2025-64171

MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the …

Nov 6, 2025
CVE-2025-64164
9.8 CRITICAL

Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, …

Nov 6, 2025
CVE-2025-64163
9.8 CRITICAL

DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps://. However, …

Nov 6, 2025
CVE-2025-64114
6.5 MEDIUM

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrators with plugin management privileges to execute arbitrary …

Nov 6, 2025
CVE-2025-62596
10.0 CRITICAL

Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficiently strict write-target validation, and when combined with …

Nov 6, 2025
CVE-2025-62161
10.0 CRITICAL

Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape …

Nov 6, 2025
CVE-2025-55278
8.1 HIGH

Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic …

Nov 5, 2025
CVE-2025-12779
8.8 HIGH

Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces …

Nov 5, 2025
CVE-2025-63585
6.5 MEDIUM

OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.

Nov 5, 2025
CVE-2025-60784
6.5 MEDIUM

A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.php Pay module, enabling unauthorized discounts. …

Nov 5, 2025
CVE-2025-63334
9.8 CRITICAL

PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in …

Nov 5, 2025
CVE-2025-10853
5.2 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, …

Nov 5, 2025
CVE-2025-63418
6.1 MEDIUM

A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitrary JavaScript in the context of a logged-in user's session …

Nov 5, 2025
CVE-2025-63417
7.2 HIGH

A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML …

Nov 5, 2025
CVE-2025-63416
9.1 CRITICAL

** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated low-privileged attackers to execute arbitrary …

Nov 5, 2025
CVE-2025-5770
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor …

Nov 5, 2025
CVE-2025-56232
6.8 MEDIUM

GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) …

Nov 5, 2025
CVE-2025-55343
9.9 CRITICAL

Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista.php radi_temp, Administracion/listas/formArea_ajax.php codDepe, Administracion/listas/formDepeHijo_ajax.php codDepe, Administracion/listas/formDepePadre_ajax.php codInst, …

Nov 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.