CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12192
5.3 MEDIUM

The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided …

Nov 5, 2025
CVE-2025-11987
6.4 MEDIUM

The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 …

Nov 5, 2025
CVE-2025-11820
6.4 MEDIUM

The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widgets in all versions up to, …

Nov 5, 2025
CVE-2025-55108
10.0 CRITICAL

The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled …

Nov 5, 2025
CVE-2025-12677
5.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the register_api_route() function in …

Nov 5, 2025
CVE-2025-12676
5.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin …

Nov 5, 2025
CVE-2025-12675
4.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all …

Nov 5, 2025
CVE-2025-12674
9.8 CRITICAL

The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in all versions …

Nov 5, 2025
CVE-2025-10622
8.0 HIGH

A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on …

Nov 5, 2025
CVE-2025-64151
6.7 MEDIUM

Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A user with the write permission on the root directory …

Nov 5, 2025
CVE-2025-62225
6.7 MEDIUM

Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write permission on the …

Nov 5, 2025
CVE-2025-12388
6.4 MEDIUM

The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, …

Nov 5, 2025
CVE-2025-12384
8.6 HIGH

The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up …

Nov 5, 2025
CVE-2025-12139
7.5 HIGH

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up …

Nov 5, 2025
CVE-2025-11917
6.4 MEDIUM

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() …

Nov 5, 2025
CVE-2025-11373
4.3 MEDIUM

The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for …

Nov 5, 2025
CVE-2025-6027
6.3 MEDIUM

The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, …

Nov 5, 2025
CVE-2025-21079
7.1 HIGH

Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. …

Nov 5, 2025
CVE-2025-21078
8.8 HIGH

Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications.

Nov 5, 2025
CVE-2025-21077
3.3 LOW

Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity with Samsung Email privilege.

Nov 5, 2025
CVE-2025-21076
5.5 MEDIUM

Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local attackers to access data in Samsung Account. User interaction …

Nov 5, 2025
CVE-2025-21075
4.3 MEDIUM

Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Nov 5, 2025
CVE-2025-21074
4.3 MEDIUM

Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Nov 5, 2025
CVE-2025-21073
6.8 MEDIUM

Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attackers to access user data. User interaction is required …

Nov 5, 2025
CVE-2025-21071
5.7 MEDIUM

Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Nov 5, 2025
CVE-2025-11749
9.8 CRITICAL

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API …

Nov 5, 2025
CVE-2025-11072
5.3 MEDIUM

The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker …

Nov 5, 2025
CVE-2025-10873
5.3 MEDIUM

The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses due to missing authorization on the …

Nov 5, 2025
CVE-2025-10567
6.3 MEDIUM

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to …

Nov 5, 2025
CVE-2025-12197
7.5 HIGH

The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient …

Nov 5, 2025
CVE-2025-11162
6.4 MEDIUM

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in …

Nov 5, 2025
CVE-2025-64455

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64454

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64453

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64452

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64451

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64450

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64449

Rejected reason: Not used

Nov 5, 2025
CVE-2025-64448

Rejected reason: Not used

Nov 5, 2025
CVE-2025-12580
6.1 MEDIUM

The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in all versions up to, and including, 1.1.8 …

Nov 5, 2025
CVE-2025-11835
5.3 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Nov 5, 2025
CVE-2025-8871
5.6 MEDIUM

The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted …

Nov 5, 2025
CVE-2025-12582
4.3 MEDIUM

The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'features_revert_option AJAX endpoint in all …

Nov 5, 2025
CVE-2025-12735
9.8 CRITICAL

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, …

Nov 5, 2025
CVE-2025-64110
7.5 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive …

Nov 5, 2025
CVE-2025-64109
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta allowed an attacker to …

Nov 5, 2025
CVE-2025-64108
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to …

Nov 4, 2025
CVE-2025-64107
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path …

Nov 4, 2025
CVE-2025-64106
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables …

Nov 4, 2025
CVE-2025-62722
5.4 MEDIUM

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) …

Nov 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.