CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11378
5.4 MEDIUM

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Oct 18, 2025
CVE-2020-36854
6.4 MEDIUM

The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization …

Oct 18, 2025
CVE-2020-36853
7.2 HIGH

The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient …

Oct 18, 2025
CVE-2017-20208
9.8 CRITICAL

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Oct 18, 2025
CVE-2017-20207
9.8 CRITICAL

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from …

Oct 18, 2025
CVE-2017-20206
9.8 CRITICAL

The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the …

Oct 18, 2025
CVE-2025-62640

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62639

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62638

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62637

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62636

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62635

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62634

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62633

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62632

Rejected reason: Not used

Oct 18, 2025
CVE-2025-62655

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects …

Oct 17, 2025
CVE-2025-62654

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki QuizGame extension allows Stored XSS.This issue affects …

Oct 17, 2025
CVE-2025-62653

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PollNY extension allows Stored XSS.This issue affects …

Oct 17, 2025
CVE-2025-62652

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects …

Oct 17, 2025
CVE-2025-62651
6.5 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.

Oct 17, 2025
CVE-2025-62650
8.3 HIGH

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.

Oct 17, 2025
CVE-2025-62649
5.8 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders.

Oct 17, 2025
CVE-2025-62648
6.4 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.

Oct 17, 2025
CVE-2025-62647
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to …

Oct 17, 2025
CVE-2025-62646
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.

Oct 17, 2025
CVE-2025-62645
9.9 CRITICAL

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform …

Oct 17, 2025
CVE-2025-62644
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.

Oct 17, 2025
CVE-2025-62643
3.4 LOW

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.

Oct 17, 2025
CVE-2025-62642
5.8 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, …

Oct 17, 2025
CVE-2025-62515
9.8 CRITICAL

pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() to deserialize …

Oct 17, 2025
CVE-2025-62508
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in …

Oct 17, 2025
CVE-2025-11914
4.3 MEDIUM

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function Download of the file /DeviceFileReport.do?Action=Download. Performing manipulation …

Oct 17, 2025
CVE-2025-62511
6.3 MEDIUM

yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-367) in …

Oct 17, 2025
CVE-2025-11925
6.1 MEDIUM

Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through …

Oct 17, 2025
CVE-2025-11913
4.3 MEDIUM

A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is the function Download of the file /Service.do?Action=Download. Such …

Oct 17, 2025
CVE-2025-11912
6.3 MEDIUM

A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file /DeviceState.do?Action=Query. This manipulation of the …

Oct 17, 2025
CVE-2025-11911
6.3 MEDIUM

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Action=Query. The manipulation of the argument …

Oct 17, 2025
CVE-2025-11910
6.3 MEDIUM

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /MemoryState.do?Action=Query. The manipulation of …

Oct 17, 2025
CVE-2025-62505
3.0 LOW

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. …

Oct 17, 2025
CVE-2025-56320
5.4 MEDIUM

Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary …

Oct 17, 2025
CVE-2025-56316
9.8 CRITICAL

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized …

Oct 17, 2025
CVE-2025-56221
9.8 CRITICAL

A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.

Oct 17, 2025
CVE-2025-56218
9.8 CRITICAL

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Oct 17, 2025
CVE-2025-34282
9.1 CRITICAL

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG …

Oct 17, 2025
CVE-2025-34281
5.4 MEDIUM

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting …

Oct 17, 2025
CVE-2025-11909
6.3 MEDIUM

A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. Executing manipulation …

Oct 17, 2025
CVE-2025-11908
6.3 MEDIUM

A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing …

Oct 17, 2025
CVE-2024-31573
4.0 MEDIUM

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension …

Oct 17, 2025
CVE-2025-62430
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site scripting (XSS) in multiple video and photo …

Oct 17, 2025
CVE-2025-62424
6.7 MEDIUM

ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of …

Oct 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.