CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-53976
5.4 MEDIUM

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new …

Dec 22, 2025
CVE-2023-53961
4.3 MEDIUM

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages …

Dec 22, 2025
CVE-2022-50689
6.2 MEDIUM

Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can …

Dec 22, 2025
CVE-2022-50687
5.5 MEDIUM

Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers …

Dec 22, 2025
CVE-2021-47715
5.3 MEDIUM

Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit …

Dec 22, 2025
CVE-2021-47714
5.5 MEDIUM

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can …

Dec 22, 2025
CVE-2025-67291
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting …

Dec 22, 2025
CVE-2025-67290
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via …

Dec 22, 2025
CVE-2025-65837
5.4 MEDIUM

PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.

Dec 22, 2025
CVE-2025-65790
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or …

Dec 22, 2025
CVE-2024-25812
6.1 MEDIUM

MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.

Dec 22, 2025
CVE-2025-26787
4.7 MEDIUM

An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate …

Dec 22, 2025
CVE-2025-15033
6.5 MEDIUM

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This …

Dec 22, 2025
CVE-2024-35321
4.3 MEDIUM

MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parameter.

Dec 22, 2025
CVE-2024-25814
6.1 MEDIUM

MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.

Dec 22, 2025
CVE-2025-65270
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the …

Dec 22, 2025
CVE-2025-68333
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix possible deadlock in the deferred_irq_workfn() For PREEMPT_RT=y kernels, the deferred_irq_workfn() is executed in …

Dec 22, 2025
CVE-2025-67443
6.1 MEDIUM

Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in …

Dec 22, 2025
CVE-2025-8460
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Notification rules, Open tickets module) allows Stored XSS …

Dec 22, 2025
CVE-2025-54890
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hostgroup configuration page) allows Stored XSS by users …

Dec 22, 2025
CVE-2025-62880
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through <= …

Dec 22, 2025
CVE-2025-62107
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Request Forgery.This issue affects Feather Login Page: from n/a through <= …

Dec 22, 2025
CVE-2025-62094
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidthemes Void Elementor WHMCS Elements For Elementor Page Builder void-elementor-whmcs-elements.This issue affects Void …

Dec 22, 2025
CVE-2025-8305
6.5 MEDIUM

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in …

Dec 22, 2025
CVE-2025-8304
6.5 MEDIUM

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows …

Dec 22, 2025
CVE-2025-15014
6.3 MEDIUM

A security flaw has been discovered in loganhong php loganSite up to c035fb5c3edd0b2a5e32fd4051cbbc9e61a31426. This affects an unknown function of the file /includes/article_detail.php of the component …

Dec 22, 2025
CVE-2025-15013
5.3 MEDIUM

A vulnerability was identified in floooh sokol up to 5d11344150973f15e16d3ec4ee7550a73fb995e0. The impacted element is the function _sg_validate_pipeline_desc in the library sokol_gfx.h. Such manipulation leads to …

Dec 22, 2025
CVE-2025-59301
4.0 MEDIUM

Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.

Dec 22, 2025
CVE-2025-15009
6.3 MEDIUM

A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/common/upload of the component Filename …

Dec 22, 2025
CVE-2025-15004
6.3 MEDIUM

A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads …

Dec 22, 2025
CVE-2025-15003
4.7 MEDIUM

A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php. Performing a manipulation of the …

Dec 22, 2025
CVE-2025-62926
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool [Show Current Template Info] current-template-name allows Stored XSS.This issue affects TempTool …

Dec 21, 2025
CVE-2025-62901
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten WP Microdata wp-microdata allows Stored XSS.This issue affects WP Microdata: from n/a …

Dec 21, 2025
CVE-2025-62955
4.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool [Show Current Template Info] current-template-name allows Retrieve Embedded Sensitive Data.This issue …

Dec 21, 2025
CVE-2025-13693
6.4 MEDIUM

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom scripts' setting in all versions up …

Dec 21, 2025
CVE-2025-13361
4.3 MEDIUM

The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due …

Dec 21, 2025
CVE-2025-13220
6.4 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Dec 21, 2025
CVE-2025-12398
6.1 MEDIUM

The Product Table for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_key' parameter in all versions up to, and including, …

Dec 21, 2025
CVE-2025-14080
5.3 MEDIUM

The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.5. This is due …

Dec 21, 2025
CVE-2025-14054
4.4 MEDIUM

The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'heading_color' parameter (and multiple other …

Dec 21, 2025
CVE-2025-14043
5.3 MEDIUM

The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. …

Dec 21, 2025
CVE-2025-13838
6.4 MEDIUM

The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the 'wishsuite_button' shortcode in all versions up to, and …

Dec 21, 2025
CVE-2025-11496
6.1 MEDIUM

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions …

Dec 21, 2025
CVE-2023-47232
4.3 MEDIUM

Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.

Dec 21, 2025
CVE-2023-25445
5.4 MEDIUM

Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1.

Dec 21, 2025
CVE-2023-25068
4.3 MEDIUM

Missing Authorization vulnerability in Mapro Collins Magazine Edge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Edge: from n/a through 1.13.

Dec 21, 2025
CVE-2025-7733
4.3 MEDIUM

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Dec 20, 2025
CVE-2025-14298
5.4 MEDIUM

The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up …

Dec 20, 2025
CVE-2025-12492
5.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Dec 20, 2025
CVE-2025-12820
5.3 MEDIUM

The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its settings, which could allow any authenticated users …

Dec 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.