CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10406
5.5 MEDIUM

The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any …

Oct 15, 2025
CVE-2025-55079
5.5 MEDIUM

In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't …

Oct 15, 2025
CVE-2025-62448

Rejected reason: Not used

Oct 15, 2025
CVE-2025-62447

Rejected reason: Not used

Oct 15, 2025
CVE-2025-62446

Rejected reason: Not used

Oct 15, 2025
CVE-2025-62445

Rejected reason: Not used

Oct 15, 2025
CVE-2025-62444

Rejected reason: Not used

Oct 15, 2025
CVE-2025-62443

Rejected reason: Not used

Oct 15, 2025
CVE-2025-62442

Rejected reason: Not used

Oct 15, 2025
CVE-2025-62441

Rejected reason: Not used

Oct 15, 2025
CVE-2025-62440

Rejected reason: Not used

Oct 15, 2025
CVE-2025-11746
8.8 HIGH

The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it …

Oct 15, 2025
CVE-2025-54278
5.5 MEDIUM

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this …

Oct 15, 2025
CVE-2025-54268
7.8 HIGH

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Oct 15, 2025
CVE-2024-13991

Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the `fullPath` parameter of the …

Oct 15, 2025
CVE-2023-7311

BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into …

Oct 15, 2025
CVE-2023-7305

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can …

Oct 15, 2025
CVE-2023-7304

Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject …

Oct 15, 2025
CVE-2018-25117

VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised …

Oct 15, 2025
CVE-2017-20205

Valve's Source SDK (source-sdk-2013)'s ragdoll model parsing logic contains a stack-based buffer overflow vulnerability.The tokenizer function `nexttoken` copies characters from an input string into a …

Oct 15, 2025
CVE-2017-20204

DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet administrative interface that allows remote authentication …

Oct 15, 2025
CVE-2011-10033

The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter …

Oct 15, 2025
CVE-2025-61804
7.8 HIGH

Animate versions 23.0.13, 24.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Oct 15, 2025
CVE-2025-54279
7.8 HIGH

Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Oct 15, 2025
CVE-2025-54270
5.5 MEDIUM

Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this …

Oct 15, 2025
CVE-2025-54269
5.5 MEDIUM

Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability …

Oct 15, 2025
CVE-2025-62376

pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoint contains an improper authentication vulnerability that allows an attacker …

Oct 14, 2025
CVE-2025-61797
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-61796
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-54272
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-54196
4.3 MEDIUM

Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to …

Oct 14, 2025
CVE-2025-49553
9.3 CRITICAL

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious …

Oct 14, 2025
CVE-2025-49552
8.1 HIGH

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute …

Oct 14, 2025
CVE-2025-54277

Rejected reason: This CVE ID was issued in error by its CVE Numbering Authority.

Oct 14, 2025
CVE-2025-54267
6.5 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability …

Oct 14, 2025
CVE-2025-54266
4.8 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by …

Oct 14, 2025
CVE-2025-54265
5.9 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to …

Oct 14, 2025
CVE-2025-54264
8.1 HIGH

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) Cross-Site Scripting (XSS) vulnerability that could …

Oct 14, 2025
CVE-2025-54263
8.1 HIGH

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability …

Oct 14, 2025
CVE-2025-62374
6.4 MEDIUM

Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to …

Oct 14, 2025
CVE-2025-61807
7.8 HIGH

Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the …

Oct 14, 2025
CVE-2025-61806
7.8 HIGH

Substance3D - Stager versions 3.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Oct 14, 2025
CVE-2025-61805
7.8 HIGH

Substance3D - Stager versions 3.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Oct 14, 2025
CVE-2025-61803
7.8 HIGH

Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the …

Oct 14, 2025
CVE-2025-61802
7.8 HIGH

Substance3D - Stager versions 3.1.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Oct 14, 2025
CVE-2025-61801
7.8 HIGH

Dimension versions 4.1.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the …

Oct 14, 2025
CVE-2025-61800
7.8 HIGH

Dimension versions 4.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of …

Oct 14, 2025
CVE-2025-61799
7.8 HIGH

Dimension versions 4.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the …

Oct 14, 2025
CVE-2025-61798
7.8 HIGH

Dimension versions 4.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the …

Oct 14, 2025
CVE-2025-61678

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to …

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.