CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36756

A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.

Sep 10, 2025
CVE-2025-9979
4.3 MEDIUM

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv …

Sep 10, 2025
CVE-2025-9943
9.1 CRITICAL

An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) …

Sep 10, 2025
CVE-2025-9888
4.3 MEDIUM

The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is …

Sep 10, 2025
CVE-2025-9857
6.4 MEDIUM

The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all versions up …

Sep 10, 2025
CVE-2025-9622
4.3 MEDIUM

The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.6. …

Sep 10, 2025
CVE-2025-9463
6.5 MEDIUM

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter …

Sep 10, 2025
CVE-2025-9367
5.5 MEDIUM

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient …

Sep 10, 2025
CVE-2025-8778
4.3 MEDIUM

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions …

Sep 10, 2025
CVE-2025-7843
6.4 MEDIUM

The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the …

Sep 10, 2025
CVE-2025-7826
6.5 MEDIUM

The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient …

Sep 10, 2025
CVE-2025-7049
8.8 HIGH

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the …

Sep 10, 2025
CVE-2025-6189
6.5 MEDIUM

The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter in all versions up to, and including, …

Sep 10, 2025
CVE-2025-41714
8.8 HIGH

The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to create upload-related artifacts …

Sep 10, 2025
CVE-2025-10142
4.9 MEDIUM

The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and …

Sep 10, 2025
CVE-2025-10126
6.4 MEDIUM

The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' shortcode in all versions up to, and including, 1.0.8 …

Sep 10, 2025
CVE-2025-10049
7.2 HIGH

The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the HdnMediaSelection_image field in all …

Sep 10, 2025
CVE-2025-10040
7.7 HIGH

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability …

Sep 10, 2025
CVE-2025-10001
7.2 HIGH

The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Sep 10, 2025
CVE-2025-8388
6.4 MEDIUM

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_url’ parameter in all versions …

Sep 10, 2025
CVE-2025-10197
6.3 MEDIUM

A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability is an unknown functionality of the file …

Sep 10, 2025
CVE-2025-10195
5.3 MEDIUM

A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such …

Sep 10, 2025
CVE-2025-59046
9.8 CRITICAL

The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the branch name on …

Sep 9, 2025
CVE-2025-59044
4.4 MEDIUM

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display …

Sep 9, 2025
CVE-2025-59042

PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during the bootstrap …

Sep 9, 2025
CVE-2025-59039

Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related …

Sep 9, 2025
CVE-2025-59038

Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9.2 may have been briefly compromised …

Sep 9, 2025
CVE-2025-58750
8.2 HIGH

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0cc348b are missing a bound check in `chclif_parse_moveCharSlot` …

Sep 9, 2025
CVE-2025-58448
9.1 CRITICAL

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL Injection in the PartyBooking …

Sep 9, 2025
CVE-2025-58447
9.8 CRITICAL

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-based buffer overflow in the …

Sep 9, 2025
CVE-2025-10172
8.8 HIGH

A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/formPictureUrl. Executing manipulation of the …

Sep 9, 2025
CVE-2025-9997

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is …

Sep 9, 2025
CVE-2025-59036
5.5 MEDIUM

Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the authentication logic will cause …

Sep 9, 2025
CVE-2025-58135
5.3 MEDIUM

Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access.

Sep 9, 2025
CVE-2025-58134
4.3 MEDIUM

Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.

Sep 9, 2025
CVE-2025-58131
6.6 MEDIUM

Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective …

Sep 9, 2025
CVE-2025-54260
7.8 HIGH

Substance3D - Modeler versions 1.22.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Sep 9, 2025
CVE-2025-54259
7.8 HIGH

Substance3D - Modeler versions 1.22.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the …

Sep 9, 2025
CVE-2025-54258
7.8 HIGH

Substance3D - Modeler versions 1.22.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Sep 9, 2025
CVE-2025-49461
4.3 MEDIUM

Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

Sep 9, 2025
CVE-2025-49460
4.3 MEDIUM

Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

Sep 9, 2025
CVE-2025-49459
7.8 HIGH

Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authenticated user to conduct an escalation of …

Sep 9, 2025
CVE-2025-49458
6.5 MEDIUM

Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access.

Sep 9, 2025
CVE-2025-10171
8.8 HIGH

A vulnerability was detected in UTT 1250GW up to 3.2.2-200710. This vulnerability affects the function sub_453DC of the file /goform/formConfigApConfTemp. Performing manipulation results in buffer …

Sep 9, 2025
CVE-2025-9996

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the execution of any shell command …

Sep 9, 2025
CVE-2025-7746

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicious user potentially …

Sep 9, 2025
CVE-2025-59037

DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along …

Sep 9, 2025
CVE-2025-58768
9.6 CRITICAL

DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly …

Sep 9, 2025
CVE-2025-58765
7.1 HIGH

wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error …

Sep 9, 2025
CVE-2025-58763
8.0 HIGH

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows attackers with …

Sep 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.