CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6439
9.8 CRITICAL

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion …

Oct 11, 2025
CVE-2025-58301
6.2 MEDIUM

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58300
6.2 MEDIUM

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58293
5.5 MEDIUM

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58289
5.9 MEDIUM

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-11596
7.3 HIGH

A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of the file /pages/delete_order_details.php. Executing manipulation of the argument …

Oct 11, 2025
CVE-2025-11595
4.7 MEDIUM

A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing a manipulation of …

Oct 11, 2025
CVE-2025-10376
4.3 MEDIUM

The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4. This is due …

Oct 11, 2025
CVE-2025-10375
4.3 MEDIUM

The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10. This is due …

Oct 11, 2025
CVE-2025-10190
6.4 MEDIUM

The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-10175
6.5 MEDIUM

The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due …

Oct 11, 2025
CVE-2025-10167
6.4 MEDIUM

The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_stock_snapshot_restocked shortcode in all versions …

Oct 11, 2025
CVE-2025-10129
6.4 MEDIUM

The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up …

Oct 11, 2025
CVE-2025-6553
9.8 CRITICAL

The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout() function in all …

Oct 11, 2025
CVE-2025-58299
8.4 HIGH

Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58298
7.3 HIGH

Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58297
5.9 MEDIUM

Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58295
5.9 MEDIUM

Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58292
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58291
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58290
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58288
5.5 MEDIUM

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58287
7.8 HIGH

Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58286
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-11594
5.3 MEDIUM

A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file …

Oct 11, 2025
CVE-2025-11518
5.3 MEDIUM

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via …

Oct 11, 2025
CVE-2025-11254
4.3 MEDIUM

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, …

Oct 11, 2025
CVE-2025-11167
4.7 MEDIUM

The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, …

Oct 11, 2025
CVE-2025-9496
6.4 MEDIUM

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-9196
5.3 MEDIUM

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Oct 11, 2025
CVE-2025-11533
9.8 CRITICAL

The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_register() …

Oct 11, 2025
CVE-2025-11197
6.4 MEDIUM

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 …

Oct 11, 2025
CVE-2025-10185
4.9 MEDIUM

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in …

Oct 11, 2025
CVE-2025-10048
4.9 MEDIUM

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due …

Oct 11, 2025
CVE-2025-11593
6.3 MEDIUM

A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument …

Oct 11, 2025
CVE-2025-11592
6.3 MEDIUM

A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edit-equipmentform.php. The manipulation of the argument ID …

Oct 11, 2025
CVE-2025-11591
6.3 MEDIUM

A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The …

Oct 11, 2025
CVE-2025-58285
5.3 MEDIUM

Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58284
5.9 MEDIUM

Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58283
5.5 MEDIUM

Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58282
2.8 LOW

Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58278
6.2 MEDIUM

Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58277
4.0 MEDIUM

Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-9560
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-11380
5.9 MEDIUM

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a …

Oct 11, 2025
CVE-2025-54654
6.2 MEDIUM

Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality

Oct 11, 2025
CVE-2025-31718
7.5 HIGH

In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of privilege with no additional execution …

Oct 11, 2025
CVE-2025-31717
7.5 HIGH

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

Oct 11, 2025
CVE-2025-11590
6.3 MEDIUM

A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing a …

Oct 11, 2025
CVE-2025-9554
5.3 MEDIUM

Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*.

Oct 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.