CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10759
5.3 MEDIUM

A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the …

Sep 21, 2025
CVE-2025-10758
2.4 LOW

A security vulnerability has been detected in htmly up to 3.1.0. The impacted element is an unknown function of the file /htmly/admin/field/post of the component …

Sep 21, 2025
CVE-2025-10757
8.8 HIGH

A weakness has been identified in UTT 1200GW up to 3.0.0-170831. The affected element is an unknown function of the file /goform/formConfigDnsFilterGlobal. This manipulation of …

Sep 21, 2025
CVE-2025-10756
8.8 HIGH

A security flaw has been discovered in UTT HiPER 840G up to 3.1.1-190328. Impacted is an unknown function of the file /goform/getOneApConfTempEntry. The manipulation of …

Sep 20, 2025
CVE-2024-10246

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 20, 2025
CVE-2025-10755
6.3 MEDIUM

A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component Content-Type Handler. The manipulation of the argument …

Sep 20, 2025
CVE-2025-40925
9.1 CRITICAL

Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with a counter, the epoch time, …

Sep 20, 2025
CVE-2025-10741
6.3 MEDIUM

A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile Picture Handler. …

Sep 20, 2025
CVE-2025-9887
4.3 MEDIUM

The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is …

Sep 20, 2025
CVE-2025-9883
6.1 MEDIUM

The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing …

Sep 20, 2025
CVE-2025-9882
6.1 MEDIUM

The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to …

Sep 20, 2025
CVE-2025-10658
6.5 MEDIUM

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. …

Sep 20, 2025
CVE-2025-9949
4.3 MEDIUM

The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to …

Sep 20, 2025
CVE-2025-10489
4.3 MEDIUM

The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of …

Sep 20, 2025
CVE-2025-10305
5.3 MEDIUM

The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_passkey() and passkeys_list() function in all …

Sep 20, 2025
CVE-2025-10181
6.4 MEDIUM

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6 …

Sep 20, 2025
CVE-2025-10002
4.9 MEDIUM

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via …

Sep 20, 2025
CVE-2025-59727

Rejected reason: Not used

Sep 20, 2025
CVE-2025-59726

Rejected reason: Not used

Sep 20, 2025
CVE-2025-59725

Rejected reason: Not used

Sep 20, 2025
CVE-2025-59724

Rejected reason: Not used

Sep 20, 2025
CVE-2025-59723

Rejected reason: Not used

Sep 20, 2025
CVE-2025-59722

Rejected reason: Not used

Sep 20, 2025
CVE-2025-59721

Rejected reason: Not used

Sep 20, 2025
CVE-2025-59720

Rejected reason: Not used

Sep 20, 2025
CVE-2025-10652
6.5 MEDIUM

The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore-netatmo shortcode in all versions up to, and …

Sep 20, 2025
CVE-2025-43808
5.3 MEDIUM

The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 …

Sep 19, 2025
CVE-2025-9081
3.1 LOW

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board …

Sep 19, 2025
CVE-2025-9079
8.0 HIGH

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which …

Sep 19, 2025
CVE-2025-59689
6.1 MEDIUM KEV

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. …

Sep 19, 2025
CVE-2025-59431
9.8 CRITICAL

MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It …

Sep 19, 2025
CVE-2025-57396
6.5 MEDIUM

Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User …

Sep 19, 2025
CVE-2025-56762
6.1 MEDIUM

Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.

Sep 19, 2025
CVE-2025-54815
8.8 HIGH

Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.

Sep 19, 2025
CVE-2025-54761
8.0 HIGH

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

Sep 19, 2025
CVE-2025-52159
8.8 HIGH

Hardcoded credentials in default configuration of PPress 0.0.9.

Sep 19, 2025
CVE-2025-43809
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 …

Sep 19, 2025
CVE-2025-10568
9.8 CRITICAL

HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to address the potential vulnerability.

Sep 19, 2025
CVE-2025-43803
4.3 MEDIUM

Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2023.Q4.0 …

Sep 19, 2025
CVE-2025-34206
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers …

Sep 19, 2025
CVE-2025-34205
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (VA and SaaS deployments) contains dangerous PHP dead code …

Sep 19, 2025
CVE-2025-34204
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple Docker containers that run primary application processes (for example PHP …

Sep 19, 2025
CVE-2025-34203
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior to 20.0.2614 (VA and SaaS deployments) contain multiple Docker containers …

Sep 19, 2025
CVE-2025-34202
8.8 HIGH

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker internal networks in a …

Sep 19, 2025
CVE-2025-34201
7.8 HIGH

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker containers on shared internal networks without firewalling or segmentation …

Sep 19, 2025
CVE-2025-34200
7.8 HIGH

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the appliance with the network account credentials in clear-text inside /etc/issue, …

Sep 19, 2025
CVE-2025-34199
8.1 HIGH

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 (VA and SaaS deployments) contain insecure defaults and …

Sep 19, 2025
CVE-2025-34198
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.2368 (VA and SaaS deployments) contain shared, hardcoded SSH host …

Sep 19, 2025
CVE-2025-34197
7.8 HIGH

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account …

Sep 19, 2025
CVE-2025-34195
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments) contain a remote code execution vulnerability …

Sep 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.