CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-7320
5.3 MEDIUM

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS handling on the …

Oct 29, 2025
CVE-2025-9544
6.5 MEDIUM

The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capabilities or using a nonce. As a result, any authenticated …

Oct 29, 2025
CVE-2025-62776
7.8 HIGH

The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. …

Oct 29, 2025
CVE-2025-49042
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= …

Oct 29, 2025
CVE-2025-11705
6.5 MEDIUM

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to …

Oct 29, 2025
CVE-2025-64296
5.3 MEDIUM

Missing Authorization vulnerability in Facebook Facebook for WooCommerce facebook-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Facebook for WooCommerce: from n/a through …

Oct 29, 2025
CVE-2025-64162

Rejected reason: Not used

Oct 29, 2025
CVE-2025-64161

Rejected reason: Not used

Oct 29, 2025
CVE-2025-64160

Rejected reason: Not used

Oct 29, 2025
CVE-2025-64159

Rejected reason: Not used

Oct 29, 2025
CVE-2025-64158

Rejected reason: Not used

Oct 29, 2025
CVE-2025-57931
5.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through <= 5.5.4.

Oct 29, 2025
CVE-2025-4665
9.6 CRITICAL

WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization (PHP …

Oct 29, 2025
CVE-2025-64095
10.0 CRITICAL

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated …

Oct 28, 2025
CVE-2025-64094
6.4 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG …

Oct 28, 2025
CVE-2025-62802
4.3 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows …

Oct 28, 2025
CVE-2025-62801
7.8 HIGH

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field …

Oct 28, 2025
CVE-2025-62800
6.1 MEDIUM

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page …

Oct 28, 2025
CVE-2025-62798
5.4 MEDIUM

Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when …

Oct 28, 2025
CVE-2025-62796
5.8 MEDIUM

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow persistent HTML injection via the unsanitized …

Oct 28, 2025
CVE-2025-62794
3.8 LOW

GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token …

Oct 28, 2025
CVE-2025-62727
7.5 HIGH

Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range …

Oct 28, 2025
CVE-2025-62368
9.0 CRITICAL

Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due to …

Oct 28, 2025
CVE-2025-61598
5.3 MEDIUM

Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. …

Oct 28, 2025
CVE-2025-43017
9.8 CRITICAL

HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential …

Oct 28, 2025
CVE-2025-11375
6.5 MEDIUM

Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. …

Oct 28, 2025
CVE-2025-11374
6.5 MEDIUM

Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is …

Oct 28, 2025
CVE-2025-62367
4.8 MEDIUM

Taiga is an open source project management platform. In versions 6.8.3 and earlier, Taiga API is vulnerable to time-based blind SQL injection allowing sensitive data …

Oct 28, 2025
CVE-2025-61235
9.1 CRITICAL

An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields can contain arbitrary or …

Oct 28, 2025
CVE-2025-59837
7.2 HIGH

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed …

Oct 28, 2025
CVE-2025-27093
6.3 MEDIUM

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack …

Oct 28, 2025
CVE-2025-40843
5.9 MEDIUM

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a …

Oct 28, 2025
CVE-2025-12425
7.8 HIGH

Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Oct 28, 2025
CVE-2025-12424
9.8 CRITICAL

Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Oct 28, 2025
CVE-2025-12423
7.5 HIGH

Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Oct 28, 2025
CVE-2025-61080
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Clear2Pay Bank Visibility Application - Payment Execution 1.10.0.104 via the ID parameter in the URL.

Oct 28, 2025
CVE-2025-60805
7.5 HIGH

An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.

Oct 28, 2025
CVE-2025-60800
7.5 HIGH

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

Oct 28, 2025
CVE-2025-60355
9.8 CRITICAL

zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

Oct 28, 2025
CVE-2025-60354
7.5 HIGH

Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.

Oct 28, 2025
CVE-2025-12422
9.8 CRITICAL

Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 28, 2025
CVE-2025-54605
7.5 HIGH

Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).

Oct 28, 2025
CVE-2025-54604
7.5 HIGH

Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).

Oct 28, 2025
CVE-2025-61155
5.5 MEDIUM

The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a …

Oct 28, 2025
CVE-2025-60858
7.5 HIGH

Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing attackers to intercept or extract sensitive …

Oct 28, 2025
CVE-2025-60349
7.5 HIGH

An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver. Any …

Oct 28, 2025
CVE-2025-56399
8.8 HIGH

alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` …

Oct 28, 2025
CVE-2025-36386
9.8 CRITICAL

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to …

Oct 28, 2025
CVE-2025-34294

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the behavior originates from a documentation-published Active Response example …

Oct 28, 2025
CVE-2025-61128
9.1 CRITICAL

Stack-based buffer overflow vulnerability in WAVLINK QUANTUM D3G/WL-WN530HG3 firmware M30HG3_V240730, and possibly other wavlink models allows attackers to execute arbitrary code via crafted referrer value …

Oct 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.