CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64360
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File …

Oct 31, 2025
CVE-2025-64359
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting consulting allows PHP Local File Inclusion.This issue …

Oct 31, 2025
CVE-2025-64358
4.3 MEDIUM

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Coupons for WooCommerce: from …

Oct 31, 2025
CVE-2025-64357
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allows Cross Site Request Forgery.This issue affects Advanced Database Cleaner: from n/a through …

Oct 31, 2025
CVE-2025-64356
4.3 MEDIUM

Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Insert PHP Code Snippet: from …

Oct 31, 2025
CVE-2025-64354
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through …

Oct 31, 2025
CVE-2025-64353
8.8 HIGH

Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3.

Oct 31, 2025
CVE-2025-64352
2.7 LOW

Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from …

Oct 31, 2025
CVE-2025-64351
4.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math …

Oct 31, 2025
CVE-2025-64350
3.8 LOW

Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from …

Oct 31, 2025
CVE-2025-58149
7.5 HIGH

When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a …

Oct 31, 2025
CVE-2025-58148
7.5 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of …

Oct 31, 2025
CVE-2025-58147
7.5 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of …

Oct 31, 2025
CVE-2025-40603
4.5 MEDIUM

A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view …

Oct 31, 2025
CVE-2025-11602

Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The …

Oct 31, 2025
CVE-2025-40106

In the Linux kernel, the following vulnerability has been resolved: comedi: fix divide-by-zero in comedi_buf_munge() The comedi_buf_munge() function performs a modulo operation `async->munge_chan %= async->cmd.chanlist_len` …

Oct 31, 2025
CVE-2025-12115
7.5 HIGH

The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This …

Oct 31, 2025
CVE-2025-12041
5.3 MEDIUM

The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'erifl_file' AJAX action …

Oct 31, 2025
CVE-2025-11843

Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able …

Oct 31, 2025
CVE-2025-8383
4.3 MEDIUM

The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or …

Oct 31, 2025
CVE-2025-62232
7.5 HIGH

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level …

Oct 31, 2025
CVE-2025-30191
5.4 MEDIUM

Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to …

Oct 31, 2025
CVE-2025-30189
7.4 HIGH

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. …

Oct 31, 2025
CVE-2025-30188
7.5 HIGH

Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate …

Oct 31, 2025
CVE-2025-12175
4.3 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all …

Oct 31, 2025
CVE-2025-12094
5.3 MEDIUM

The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to IP Header Spoofing in all versions up …

Oct 31, 2025
CVE-2025-8385
6.8 MEDIUM

The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is due to insufficient input validation …

Oct 31, 2025
CVE-2025-6520
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection.This issue affects BAPSIS: before …

Oct 31, 2025
CVE-2025-10897
8.6 HIGH

The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible …

Oct 31, 2025
CVE-2025-8489
9.8 CRITICAL

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 …

Oct 31, 2025
CVE-2025-7846
8.8 HIGH

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in …

Oct 31, 2025
CVE-2025-63675
6.9 MEDIUM

cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.

Oct 31, 2025
CVE-2025-5397
9.8 CRITICAL

The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() …

Oct 31, 2025
CVE-2025-58152
5.3 MEDIUM

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. …

Oct 31, 2025
CVE-2025-54763
7.2 HIGH

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web …

Oct 31, 2025
CVE-2025-11191
5.3 MEDIUM

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the …

Oct 31, 2025
CVE-2025-11975
4.3 MEDIUM

The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to unauthorized modification …

Oct 31, 2025
CVE-2025-11806
6.4 MEDIUM

The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all versions up to, and including, 1.0.1. This …

Oct 31, 2025
CVE-2025-23050
3.1 LOW

QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, …

Oct 31, 2025
CVE-2025-8849
7.5 HIGH

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` …

Oct 31, 2025
CVE-2025-6176
7.5 HIGH

Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection …

Oct 31, 2025
CVE-2025-52665
10.0 CRITICAL

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API …

Oct 31, 2025
CVE-2025-52664
8.8 HIGH

SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users

Oct 31, 2025
CVE-2025-52663
7.3 HIGH

A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to …

Oct 31, 2025
CVE-2025-48984
8.8 HIGH

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

Oct 31, 2025
CVE-2025-48983
9.9 CRITICAL

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an …

Oct 31, 2025
CVE-2025-48982
7.8 HIGH

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

Oct 31, 2025
CVE-2025-48980
6.5 MEDIUM

In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did …

Oct 31, 2025
CVE-2025-27208
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user …

Oct 31, 2025
CVE-2025-34298
8.8 HIGH

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to …

Oct 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.