CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11819
6.4 MEDIUM

The WP-Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'roboshot' shortcode in all versions up to, and including, 1.1. This is …

Oct 22, 2025
CVE-2025-11818
6.4 MEDIUM

The WP Responsive Meet The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wprm_team' shortcode in all versions up to, and …

Oct 22, 2025
CVE-2025-11817
6.4 MEDIUM

The Simple Tableau Viz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableau' shortcode in all versions up to, and including, 2.0. …

Oct 22, 2025
CVE-2025-11813
6.4 MEDIUM

The Responsive iframe GoogleMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive_map' shortcode in all versions up to, and including, 1.0.2. …

Oct 22, 2025
CVE-2025-11811
6.4 MEDIUM

The Simple Youtube Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embed_youtube' shortcode in all versions up to, and including, 1.1.3. …

Oct 22, 2025
CVE-2025-11810
6.4 MEDIUM

The Print Button Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'print-button' shortcode in all versions up to, and including, 1.0.1. …

Oct 22, 2025
CVE-2025-11809
6.4 MEDIUM

The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode in all versions up to, and including, 1.8. …

Oct 22, 2025
CVE-2025-11807
6.4 MEDIUM

The Mixlr Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mixlr' shortcode in all versions up to, and including, 1.0.1. This …

Oct 22, 2025
CVE-2025-11804
6.4 MEDIUM

The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the 'jbticker' shortcode in all versions …

Oct 22, 2025
CVE-2025-10138
6.4 MEDIUM

The This-or-That plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'thisorthat' shortcode in all versions up to, and including, 1.0.4 due …

Oct 22, 2025
CVE-2025-10047
4.9 MEDIUM

The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for WordPress is vulnerable to SQL Injection …

Oct 22, 2025
CVE-2025-41724
7.5 HIGH

An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process will not be restarted by a watchdog and a …

Oct 22, 2025
CVE-2025-41723
9.8 CRITICAL

The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.

Oct 22, 2025
CVE-2025-41722
7.5 HIGH

The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys from the Software …

Oct 22, 2025
CVE-2025-41721
2.7 LOW

A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralization of special elements when adding a password …

Oct 22, 2025
CVE-2025-41720
4.3 MEDIUM

A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the …

Oct 22, 2025
CVE-2025-41719
8.8 HIGH

A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion …

Oct 22, 2025
CVE-2025-12033
4.4 MEDIUM

The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Oct 22, 2025
CVE-2025-10588
4.3 MEDIUM

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Oct 22, 2025
CVE-2025-10570
4.3 MEDIUM

The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.38 via …

Oct 22, 2025
CVE-2025-5983
6.5 MEDIUM

The Meta Tag Manager WordPress plugin before 3.3 does not restrict which roles can create http-equiv refresh meta tags.

Oct 22, 2025
CVE-2025-10651
5.5 MEDIUM

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in versions up to, and including, 2.11.22. This is …

Oct 22, 2025
CVE-2025-10638
5.3 MEDIUM

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of …

Oct 22, 2025
CVE-2025-62775
8.0 HIGH

Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.

Oct 22, 2025
CVE-2025-62774
3.1 LOW

On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.

Oct 22, 2025
CVE-2025-62773
2.4 LOW

Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.

Oct 22, 2025
CVE-2025-62772
3.1 LOW

On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.

Oct 22, 2025
CVE-2025-62771
7.5 HIGH

Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.

Oct 22, 2025
CVE-2024-58274
8.3 HIGH

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in …

Oct 22, 2025
CVE-2023-53691
8.3 HIGH

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and …

Oct 22, 2025
CVE-2025-22167
6.5 MEDIUM

This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and …

Oct 22, 2025
CVE-2025-61756
7.5 HIGH

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are 8.0.7.9, …

Oct 21, 2025
CVE-2025-62661

Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension allows Accessing Functionality Not Properly Constrained by ACLs.This …

Oct 21, 2025
CVE-2025-62641
8.2 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows …

Oct 21, 2025
CVE-2025-62592
6.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows …

Oct 21, 2025
CVE-2025-62591
6.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows …

Oct 21, 2025
CVE-2025-62590
8.2 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows …

Oct 21, 2025
CVE-2025-62589
8.2 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows …

Oct 21, 2025
CVE-2025-62588
8.2 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows …

Oct 21, 2025
CVE-2025-62587
8.2 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows …

Oct 21, 2025
CVE-2025-62481
9.8 CRITICAL

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated …

Oct 21, 2025
CVE-2025-62480
2.7 LOW

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable …

Oct 21, 2025
CVE-2025-62479
2.7 LOW

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable …

Oct 21, 2025
CVE-2025-62478
4.9 MEDIUM

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable …

Oct 21, 2025
CVE-2025-62477
4.9 MEDIUM

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable …

Oct 21, 2025
CVE-2025-62476
4.9 MEDIUM

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable …

Oct 21, 2025
CVE-2025-62475
4.9 MEDIUM

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability …

Oct 21, 2025
CVE-2025-62290
7.2 HIGH

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable …

Oct 21, 2025
CVE-2025-62289
4.9 MEDIUM

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability …

Oct 21, 2025
CVE-2025-62288
4.9 MEDIUM

Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Logger). Supported versions that are affected are 3.4.0.1.3 and …

Oct 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.