CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-61994
5.4 MEDIUM

Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed …

Nov 6, 2025
CVE-2025-12563
4.3 MEDIUM

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() …

Nov 6, 2025
CVE-2025-11271
5.3 MEDIUM

The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification …

Nov 6, 2025
CVE-2025-64480

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64479

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64478

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64477

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64476

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64475

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64474

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64473

Rejected reason: Not used

Nov 6, 2025
CVE-2025-64472

Rejected reason: Not used

Nov 6, 2025
CVE-2025-10691
4.3 MEDIUM

The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to …

Nov 6, 2025
CVE-2025-10683
4.9 MEDIUM

The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions up to, and including, 1.3 due …

Nov 6, 2025
CVE-2025-64171

MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the …

Nov 6, 2025
CVE-2025-64164
9.8 CRITICAL

Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, …

Nov 6, 2025
CVE-2025-64163
9.8 CRITICAL

DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps://. However, …

Nov 6, 2025
CVE-2025-64114
6.5 MEDIUM

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrators with plugin management privileges to execute arbitrary …

Nov 6, 2025
CVE-2025-62596
10.0 CRITICAL

Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficiently strict write-target validation, and when combined with …

Nov 6, 2025
CVE-2025-62161
10.0 CRITICAL

Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape …

Nov 6, 2025
CVE-2025-55278
8.1 HIGH

Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic …

Nov 5, 2025
CVE-2025-12779
8.8 HIGH

Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces …

Nov 5, 2025
CVE-2025-63585
6.5 MEDIUM

OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.

Nov 5, 2025
CVE-2025-60784
6.5 MEDIUM

A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.php Pay module, enabling unauthorized discounts. …

Nov 5, 2025
CVE-2025-63334
9.8 CRITICAL

PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in …

Nov 5, 2025
CVE-2025-10853
5.2 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, …

Nov 5, 2025
CVE-2025-63418
6.1 MEDIUM

A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitrary JavaScript in the context of a logged-in user's session …

Nov 5, 2025
CVE-2025-63417
7.2 HIGH

A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML …

Nov 5, 2025
CVE-2025-63416
9.1 CRITICAL

** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated low-privileged attackers to execute arbitrary …

Nov 5, 2025
CVE-2025-5770
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor …

Nov 5, 2025
CVE-2025-56232
6.8 MEDIUM

GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) …

Nov 5, 2025
CVE-2025-55343
9.9 CRITICAL

Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista.php radi_temp, Administracion/listas/formArea_ajax.php codDepe, Administracion/listas/formDepeHijo_ajax.php codDepe, Administracion/listas/formDepePadre_ajax.php codInst, …

Nov 5, 2025
CVE-2025-55342
5.3 MEDIUM

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

Nov 5, 2025
CVE-2025-55341
6.5 MEDIUM

Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad.

Nov 5, 2025
CVE-2025-43418
4.6 MEDIUM

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and …

Nov 5, 2025
CVE-2025-31954
5.4 MEDIUM

HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive …

Nov 5, 2025
CVE-2025-12745
5.3 MEDIUM

A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The …

Nov 5, 2025
CVE-2025-11093
8.4 HIGH

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with …

Nov 5, 2025
CVE-2023-43000
8.8 HIGH KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS …

Nov 5, 2025
CVE-2025-56231
9.1 CRITICAL

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

Nov 5, 2025
CVE-2025-10907
8.4 HIGH

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious …

Nov 5, 2025
CVE-2025-10713
6.5 MEDIUM

An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without …

Nov 5, 2025
CVE-2025-63248
7.5 HIGH

DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another questionnaire can enable the …

Nov 5, 2025
CVE-2025-59716
5.3 MEDIUM

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds …

Nov 5, 2025
CVE-2025-57244
5.4 MEDIUM

OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts script tags and the …

Nov 5, 2025
CVE-2025-46424
6.7 MEDIUM

Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this …

Nov 5, 2025
CVE-2025-46366
6.7 MEDIUM

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database …

Nov 5, 2025
CVE-2025-46365
5.3 MEDIUM

Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected …

Nov 5, 2025
CVE-2025-46364
9.1 CRITICAL

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of …

Nov 5, 2025
CVE-2025-45379
8.4 HIGH

Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell …

Nov 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.