CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11677

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback …

Oct 20, 2025
CVE-2025-61454
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoint. Unsanitized input in the /search parameter is directly reflected back …

Oct 20, 2025
CVE-2025-56224
8.1 HIGH

A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

Oct 20, 2025
CVE-2025-56223
7.5 HIGH

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive …

Oct 20, 2025
CVE-2025-56219
7.1 HIGH

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and …

Oct 20, 2025
CVE-2025-8349

Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by uploading a …

Oct 20, 2025
CVE-2025-57837
2.9 LOW

Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Oct 20, 2025
CVE-2025-41028

A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database …

Oct 20, 2025
CVE-2025-61932
9.8 CRITICAL KEV

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code …

Oct 20, 2025
CVE-2025-57839
4.0 MEDIUM

Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Oct 20, 2025
CVE-2025-57838
4.0 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Oct 20, 2025
CVE-2025-31342

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 …

Oct 20, 2025
CVE-2025-62577
8.8 HIGH

ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database …

Oct 20, 2025
CVE-2025-40004

In the Linux kernel, the following vulnerability has been resolved: net/9p: Fix buffer overflow in USB transport layer A buffer overflow vulnerability exists in the …

Oct 20, 2025
CVE-2025-11948
9.8 CRITICAL

Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby …

Oct 20, 2025
CVE-2025-11947
4.5 MEDIUM

A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. …

Oct 19, 2025
CVE-2025-11946
3.5 LOW

A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp of the …

Oct 19, 2025
CVE-2025-11945
3.5 LOW

A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the component Avatar Upload Image Endpoint. Such manipulation leads …

Oct 19, 2025
CVE-2025-11944
4.7 MEDIUM

A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the component Raw SQL Handler. …

Oct 19, 2025
CVE-2025-11943
7.3 HIGH

A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. …

Oct 19, 2025
CVE-2025-11942
7.3 HIGH

A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to …

Oct 19, 2025
CVE-2025-11941
5.4 MEDIUM

A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler. Performing …

Oct 19, 2025
CVE-2025-11940
7.0 HIGH

A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of the file assets/setup.nsi of the component …

Oct 19, 2025
CVE-2025-11939
4.7 MEDIUM

A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php of the component Backup Restore Handler. …

Oct 19, 2025
CVE-2025-11938
5.6 MEDIUM

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL …

Oct 19, 2025
CVE-2025-62672
5.3 MEDIUM

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy …

Oct 19, 2025
CVE-2025-47410
8.8 HIGH

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked …

Oct 18, 2025
CVE-2025-11926
4.4 MEDIUM

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due …

Oct 18, 2025
CVE-2025-9890
8.8 HIGH

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing …

Oct 18, 2025
CVE-2025-5555
7.8 HIGH

A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the …

Oct 18, 2025
CVE-2025-40003

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work The origin code calls cancel_delayed_work() …

Oct 18, 2025
CVE-2025-40002

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix use-after-free in tb_dp_dprx_work The original code relies on cancel_delayed_work() in tb_dp_dprx_stop(), which does …

Oct 18, 2025
CVE-2025-40001

In the Linux kernel, the following vulnerability has been resolved: scsi: mvsas: Fix use-after-free bugs in mvs_work_queue During the detaching of Marvell's SAS/SATA controller, the …

Oct 18, 2025
CVE-2025-11256
5.3 MEDIUM

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions …

Oct 18, 2025
CVE-2025-10750
5.3 MEDIUM

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to …

Oct 18, 2025
CVE-2025-9562
6.4 MEDIUM

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, …

Oct 18, 2025
CVE-2025-11741
5.3 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the …

Oct 18, 2025
CVE-2025-11703
5.3 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This …

Oct 18, 2025
CVE-2025-11691
7.5 HIGH

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() function in all versions …

Oct 18, 2025
CVE-2025-11519
4.3 MEDIUM

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure …

Oct 18, 2025
CVE-2025-11517
7.5 HIGH

The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to …

Oct 18, 2025
CVE-2025-11510
4.3 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Oct 18, 2025
CVE-2025-11391
9.8 CRITICAL

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Oct 18, 2025
CVE-2025-11372
6.5 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is …

Oct 18, 2025
CVE-2025-11270
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute …

Oct 18, 2025
CVE-2025-10187
4.9 MEDIUM

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' parameter in all versions up …

Oct 18, 2025
CVE-2025-10006
6.4 MEDIUM

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, …

Oct 18, 2025
CVE-2025-11937

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - SecurePoll Extension allows Stored XSS.This issue …

Oct 18, 2025
CVE-2025-11857
6.4 MEDIUM

The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display_embed' shortcode in all versions up to, and including, 1.9.9. …

Oct 18, 2025
CVE-2025-11742
4.3 MEDIUM

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' …

Oct 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.