CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9630
4.3 MEDIUM

The WP SinoType plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Oct 3, 2025
CVE-2025-9561
8.8 HIGH

The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insufficient file validation within the advParallaxBackAdminSaveSlider() handler in …

Oct 3, 2025
CVE-2025-9372
5.5 MEDIUM

The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.4 due to …

Oct 3, 2025
CVE-2025-9333
5.5 MEDIUM

The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to …

Oct 3, 2025
CVE-2025-9332
5.5 MEDIUM

The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

Oct 3, 2025
CVE-2025-9286
9.8 CRITICAL

The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all …

Oct 3, 2025
CVE-2025-9213
8.8 HIGH

The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonce validation …

Oct 3, 2025
CVE-2025-9212
7.5 HIGH

The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_upload() function in all versions …

Oct 3, 2025
CVE-2025-9209
9.8 CRITICAL

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the …

Oct 3, 2025
CVE-2025-9206
6.4 MEDIUM

The Meks Easy Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title field in all version up to, and including, …

Oct 3, 2025
CVE-2025-9204
6.4 MEDIUM

The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Youtube Video ID field in all versions up to, …

Oct 3, 2025
CVE-2025-9200
7.5 HIGH

The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQL Injection via the nh_ynaa_comments() …

Oct 3, 2025
CVE-2025-9199
6.5 MEDIUM

The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via the 'woo-superb-slideshow' shortcode in all versions up …

Oct 3, 2025
CVE-2025-9198
6.5 MEDIUM

The Wp cycle text announcement plugin for WordPress is vulnerable to SQL Injection via the 'cycle-text' shortcode in all versions up to, and including, 8.1 …

Oct 3, 2025
CVE-2025-9194
4.3 MEDIUM

The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clean() function in all versions …

Oct 3, 2025
CVE-2025-9130
6.4 MEDIUM

The Unify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's unify_checkout shortcode in all versions up to, and including, …

Oct 3, 2025
CVE-2025-9129
6.4 MEDIUM

The Flexi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's flexi-form-tag shortcode in all versions up to, and including, …

Oct 3, 2025
CVE-2025-9080
6.4 MEDIUM

The Generic Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget fields in version 1.2.8 and earlier. This is due to …

Oct 3, 2025
CVE-2025-9077
6.4 MEDIUM

The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated Text' field of the Typeout Widget in …

Oct 3, 2025
CVE-2025-9045
6.4 MEDIUM

The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in versions less than, or equal to, 2.2.9 …

Oct 3, 2025
CVE-2025-8776
6.4 MEDIUM

The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in all versions up to, and including, 1.0 …

Oct 3, 2025
CVE-2025-8669
4.3 MEDIUM

The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing or incorrect nonce validation on the …

Oct 3, 2025
CVE-2025-7825
6.3 MEDIUM

The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all versions up to, and including, 4.3.2 via …

Oct 3, 2025
CVE-2025-7721
9.8 CRITICAL

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up …

Oct 3, 2025
CVE-2025-49641
4.3 MEDIUM

A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve …

Oct 3, 2025
CVE-2025-40636

SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoints where …

Oct 3, 2025
CVE-2025-27237

In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and …

Oct 3, 2025
CVE-2025-27236
6.5 MEDIUM

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to …

Oct 3, 2025
CVE-2025-27231
4.9 MEDIUM

The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue …

Oct 3, 2025
CVE-2025-10726
9.1 CRITICAL

The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, and including, 2.0. This is due …

Oct 3, 2025
CVE-2025-10582
8.8 HIGH

The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.2.0 due to …

Oct 3, 2025
CVE-2025-10547
9.8 CRITICAL

An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE …

Oct 3, 2025
CVE-2025-10311
4.3 MEDIUM

The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to …

Oct 3, 2025
CVE-2025-10309
4.3 MEDIUM

The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing …

Oct 3, 2025
CVE-2025-10306
3.8 LOW

The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via …

Oct 3, 2025
CVE-2025-10302
4.3 MEDIUM

The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to …

Oct 3, 2025
CVE-2025-10212
5.3 MEDIUM

The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in …

Oct 3, 2025
CVE-2025-10192
6.4 MEDIUM

The WP Photo Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wppe_effect' shortcode in all versions up to, and including, …

Oct 3, 2025
CVE-2025-10165
6.4 MEDIUM

The AP Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adv_parallax_back' shortcode in all versions up to, and including, 3.8.2 …

Oct 3, 2025
CVE-2025-10053
4.4 MEDIUM

The TableGen – Data Table Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, …

Oct 3, 2025
CVE-2025-0876
4.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Isin Basi Advertisement Information Technologies Trade Inc. IT's Workif allows Cross-Site …

Oct 3, 2025
CVE-2025-11234
7.5 HIGH

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This …

Oct 3, 2025
CVE-2025-6388
9.8 CRITICAL

The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.2.14. This is due to the custom_actions() …

Oct 3, 2025
CVE-2025-11223
7.8 HIGH

Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead to loading a crafted DLL file in the …

Oct 3, 2025
CVE-2025-0616
8.2 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center Telecommunication Industry Trade Co. Ltd. B2B - Netsis Panel …

Oct 3, 2025
CVE-2025-61671

Rejected reason: Further research determined the issue is not an open source vulnerability.

Oct 3, 2025
CVE-2025-61599
5.4 MEDIUM

Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitter"feature of EMLOG Pro 2.5.21 and below. An …

Oct 3, 2025
CVE-2025-61597
7.6 HIGH

Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored cross‑site scripting (XSS) via the mail …

Oct 3, 2025
CVE-2025-61589
5.9 MEDIUM

Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then …

Oct 3, 2025
CVE-2025-59536
8.8 HIGH

Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. …

Oct 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.