CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9985
5.3 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly …

Sep 26, 2025
CVE-2025-9984
5.3 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_api_debug_posts() …

Sep 26, 2025
CVE-2025-10037
4.9 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_featured_image() function in all versions up to, and including, …

Sep 26, 2025
CVE-2025-10036
4.9 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function in all versions up to, and including, …

Sep 26, 2025
CVE-2025-9044
6.4 MEDIUM

The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up to, and including, 1.20.0 due to …

Sep 26, 2025
CVE-2025-11000
3.3 LOW

A vulnerability was determined in Open Babel up to 3.1.1. This affects the function PQSFormat::ReadMolecule of the file /src/formats/PQSformat.cpp. This manipulation causes null pointer dereference. …

Sep 26, 2025
CVE-2025-10745
5.3 MEDIUM

The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable to Blocking Bypass in all versions up to, and …

Sep 26, 2025
CVE-2025-10377
4.3 MEDIUM

The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.20. This is due to missing …

Sep 26, 2025
CVE-2025-10173
2.7 LOW

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability …

Sep 26, 2025
CVE-2025-60033

Rejected reason: Not used

Sep 26, 2025
CVE-2025-60032

Rejected reason: Not used

Sep 26, 2025
CVE-2025-60031

Rejected reason: Not used

Sep 26, 2025
CVE-2025-60030

Rejected reason: Not used

Sep 26, 2025
CVE-2025-60029

Rejected reason: Not used

Sep 26, 2025
CVE-2025-60028

Rejected reason: Not used

Sep 26, 2025
CVE-2025-60027

Rejected reason: Not used

Sep 26, 2025
CVE-2025-60026

Rejected reason: Not used

Sep 26, 2025
CVE-2025-10999
3.3 LOW

A vulnerability was found in Open Babel up to 3.1.1. The impacted element is the function CacaoFormat::SetHilderbrandt of the file /src/formats/cacaoformat.cpp. The manipulation results in …

Sep 26, 2025
CVE-2025-10998
3.3 LOW

A vulnerability has been found in Open Babel up to 3.1.1. The affected element is the function ChemKinFormat::ReadReactionQualifierLines of the file /src/formats/chemkinformat.cpp. The manipulation leads …

Sep 26, 2025
CVE-2025-10997
5.3 MEDIUM

A flaw has been found in Open Babel up to 3.1.1. Impacted is the function ChemKinFormat::CheckSpecies of the file /src/formats/chemkinformat.cpp. Executing manipulation can lead to …

Sep 26, 2025
CVE-2025-10996
5.3 MEDIUM

A vulnerability was detected in Open Babel up to 3.1.1. This issue affects the function OBSmilesParser::ParseSmiles of the file /src/formats/smilesformat.cpp. Performing manipulation results in heap-based …

Sep 26, 2025
CVE-2025-8906
6.4 MEDIUM

The Widgets for Tiktok Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trustindex-feed' shortcode in all versions up to, and …

Sep 26, 2025
CVE-2025-8200
6.4 MEDIUM

The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown Timer widget in all versions …

Sep 26, 2025
CVE-2025-10995
5.3 MEDIUM

A security vulnerability has been detected in Open Babel up to 3.1.1. This vulnerability affects the function zlib_stream::basic_unzip_streambuf::underflow in the library /src/zipstreamimpl.h. Such manipulation leads …

Sep 26, 2025
CVE-2025-10994
5.3 MEDIUM

A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after …

Sep 26, 2025
CVE-2025-10993
4.7 MEDIUM

A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the …

Sep 26, 2025
CVE-2025-10992
5.3 MEDIUM

A vulnerability was determined in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. Affected is an unknown function of the file /user/info/lookupList. Executing manipulation can lead to improper …

Sep 26, 2025
CVE-2025-10752
4.3 MEDIUM

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Sep 26, 2025
CVE-2025-10178
6.4 MEDIUM

The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featured_image' shortcode in all versions up to, and including, …

Sep 26, 2025
CVE-2025-60251
5.0 MEDIUM

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.

Sep 26, 2025
CVE-2025-60250
4.7 MEDIUM

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the 2841ae97419c2973296a0d4bdfe19a4f IV.

Sep 26, 2025
CVE-2025-60017
8.2 HIGH

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).

Sep 26, 2025
CVE-2025-10989
6.3 MEDIUM

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the …

Sep 26, 2025
CVE-2025-10988
6.3 MEDIUM

A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulation leads to improper authorization. …

Sep 26, 2025
CVE-2025-10987
6.3 MEDIUM

A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality of the file /crm/contact/transfer of the component …

Sep 26, 2025
CVE-2025-10981
4.3 MEDIUM

A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation results in improper authorization. The …

Sep 26, 2025
CVE-2025-10980
4.3 MEDIUM

A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manipulation leads to improper …

Sep 26, 2025
CVE-2025-56769
6.5 MEDIUM

An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code …

Sep 25, 2025
CVE-2025-10979
4.3 MEDIUM

A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulation causes improper …

Sep 25, 2025
CVE-2025-10978
4.3 MEDIUM

A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/exportXls of the component …

Sep 25, 2025
CVE-2025-10977
3.1 LOW

A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteBatch. The manipulation of the argument ids leads …

Sep 25, 2025
CVE-2025-10976
3.1 LOW

A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUserList. Executing manipulation of the argument departId …

Sep 25, 2025
CVE-2025-10975
6.3 MEDIUM

A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.robot.bridge.reasoning_server::run_reasoning_server of the file experiments/robot/bridge/reasoning_server.py of the component ZeroMQ. Performing …

Sep 25, 2025
CVE-2025-10974
6.3 MEDIUM

A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects the function pickle.loads of the file /calculate of the component Endpoint. Such …

Sep 25, 2025
CVE-2025-59408
7.3 HIGH

Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an attacker to flash modified firmware with no cryptographic protections.

Sep 25, 2025
CVE-2025-59404
7.5 HIGH

Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modification …

Sep 25, 2025
CVE-2025-59402
5.4 MEDIUM

Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access …

Sep 25, 2025
CVE-2025-26482
4.9 MEDIUM

Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this …

Sep 25, 2025
CVE-2025-11005
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through …

Sep 25, 2025
CVE-2025-10973
7.3 HIGH

A flaw has been found in JackieDYH Resume-management-system up to fb6b857d852dd796e748ce30c606fe5e61c18273. Affected by this issue is some unknown functionality of the file /admin/show.php. This manipulation …

Sep 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.