CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60088
6.5 MEDIUM

Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarIgnition: from n/a through <= 4.06.04.

Dec 18, 2025
CVE-2025-60070
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This issue affects Molla: from n/a through <= 1.5.13.

Dec 18, 2025
CVE-2025-60068
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code Injection.This issue affects Javo Core: from n/a through <= …

Dec 18, 2025
CVE-2025-54748
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg allows Path Traversal.This issue affects MapSVG: from n/a through …

Dec 18, 2025
CVE-2025-54745
6.5 MEDIUM

Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects miniOrange's Google Authenticator: from n/a through …

Dec 18, 2025
CVE-2025-54743
5.8 MEDIUM

Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download After Email: from n/a through …

Dec 18, 2025
CVE-2025-54741
6.5 MEDIUM

Missing Authorization vulnerability in Tyler Moore Super Blank super-blank allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Blank: from n/a through <= …

Dec 18, 2025
CVE-2025-49919
5.8 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Retrieve Embedded Sensitive Data.This issue affects eRoom: from n/a through <= 1.5.6.

Dec 18, 2025
CVE-2025-49918
5.9 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Retrieve Embedded Sensitive Data.This issue affects VikBooking …

Dec 18, 2025
CVE-2025-49914
6.5 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Retrieve Embedded Sensitive Data.This issue affects …

Dec 18, 2025
CVE-2025-49902
6.5 MEDIUM

Missing Authorization vulnerability in A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Design customizer-login-page allows Exploiting Incorrectly Configured Access Control …

Dec 18, 2025
CVE-2025-49041
6.5 MEDIUM

Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Get Cash: from n/a through …

Dec 18, 2025
CVE-2025-14318
4.3 MEDIUM

Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module …

Dec 18, 2025
CVE-2025-13498
4.3 MEDIUM

The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due …

Dec 18, 2025
CVE-2025-12976
6.4 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all …

Dec 18, 2025
CVE-2025-10019
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: …

Dec 18, 2025
CVE-2025-68463
4.9 MEDIUM

Bio.Entrez in Biopython through 186 allows doctype XXE.

Dec 18, 2025
CVE-2025-47325
6.5 MEDIUM

Information disclosure while processing system calls with invalid parameters.

Dec 18, 2025
CVE-2025-47319
6.7 MEDIUM

Information disclosure while exposing internal TA-to-TA communication APIs to HLOS

Dec 18, 2025
CVE-2025-12885
6.4 MEDIUM

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function …

Dec 18, 2025
CVE-2025-14856
6.3 MEDIUM

A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation …

Dec 18, 2025
CVE-2025-14837
4.7 MEDIUM

A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Backend Website …

Dec 18, 2025
CVE-2025-14834
6.3 MEDIUM

A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing a manipulation of the …

Dec 17, 2025
CVE-2023-53932
5.4 MEDIUM

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with …

Dec 17, 2025
CVE-2023-53931
6.1 MEDIUM

Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a …

Dec 17, 2025
CVE-2023-53928
5.4 MEDIUM

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can …

Dec 17, 2025
CVE-2023-53927
5.4 MEDIUM

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create …

Dec 17, 2025
CVE-2023-53925
6.1 MEDIUM

UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files …

Dec 17, 2025
CVE-2023-53920
5.4 MEDIUM

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into …

Dec 17, 2025
CVE-2023-53919
5.4 MEDIUM

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into …

Dec 17, 2025
CVE-2023-53918
6.1 MEDIUM

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into …

Dec 17, 2025
CVE-2023-53917
6.5 MEDIUM

Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the …

Dec 17, 2025
CVE-2023-53916
4.6 MEDIUM

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported …

Dec 17, 2025
CVE-2023-53915
4.6 MEDIUM

Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can …

Dec 17, 2025
CVE-2023-53912
6.2 MEDIUM

USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers …

Dec 17, 2025
CVE-2023-53911
5.4 MEDIUM

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert …

Dec 17, 2025
CVE-2023-53910
5.4 MEDIUM

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through …

Dec 17, 2025
CVE-2023-53909
5.4 MEDIUM

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by uploading crafted SVG files through the media …

Dec 17, 2025
CVE-2023-53907
6.5 MEDIUM

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit …

Dec 17, 2025
CVE-2023-53906
4.8 MEDIUM

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft …

Dec 17, 2025
CVE-2023-53904
4.6 MEDIUM

Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create …

Dec 17, 2025
CVE-2025-68401
4.8 MEDIUM

ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/JS without sufficient sanitization/encoding. When other users later view this …

Dec 17, 2025
CVE-2025-68399
5.4 MEDIUM

ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of …

Dec 17, 2025
CVE-2025-68275
4.8 MEDIUM

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnerability on the pages `View Active People`, `View Inactive …

Dec 17, 2025
CVE-2025-68129
6.8 MEDIUM

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is …

Dec 17, 2025
CVE-2025-68114
4.8 MEDIUM

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or …

Dec 17, 2025
CVE-2025-67876
5.4 MEDIUM

ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user …

Dec 17, 2025
CVE-2025-67875
5.4 MEDIUM

ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to version 6.5.3. An authenticated user with specific mid-level permissions …

Dec 17, 2025
CVE-2025-67873
4.8 MEDIUM

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a user-provided skipdata callback can make cs_disasm/cs_disasm_iter memcpy more …

Dec 17, 2025
CVE-2025-67794
6.1 MEDIUM

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created …

Dec 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.