CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58799
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in themelocation Custom WooCommerce Checkout Fields Editor add-fields-to-checkout-page-woocommerce allows Cross Site Request Forgery.This issue affects Custom WooCommerce Checkout Fields Editor: …

Sep 5, 2025
CVE-2025-58798
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Bjorn Manintveld BCM Duplicate Menu bcm-duplicate-menu allows Cross Site Request Forgery.This issue affects BCM Duplicate Menu: from n/a through …

Sep 5, 2025
CVE-2025-58797
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Mahmudul Hasan Arif Ninja Charts ninja-charts allows Retrieve Embedded Sensitive Data.This issue affects …

Sep 5, 2025
CVE-2025-58796
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dudaster Elementor Element Condition ele-conditions allows Stored XSS.This issue affects Elementor Element Condition: …

Sep 5, 2025
CVE-2025-58795
4.3 MEDIUM

Missing Authorization vulnerability in Payoneer Checkout Payoneer Checkout payoneer-checkout allows Content Spoofing.This issue affects Payoneer Checkout: from n/a through <= 3.4.0.

Sep 5, 2025
CVE-2025-58794
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Cross Site Request Forgery.This issue affects Notification for Telegram: from n/a through <= …

Sep 5, 2025
CVE-2025-58793
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Elementor Addons wpb-elementor-addons allows Stored XSS.This issue affects WPB Elementor Addons: …

Sep 5, 2025
CVE-2025-58792
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List authors-list allows Cross Site Request Forgery.This issue affects Authors List: from n/a through <= 2.0.6.2.

Sep 5, 2025
CVE-2025-58791
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arjan Olsder SEO Auto Linker wpa-seo-auto-linker allows Stored XSS.This issue affects SEO Auto …

Sep 5, 2025
CVE-2025-58790
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi kiwi-social-share allows Stored XSS.This issue affects Kiwi: from n/a through <= …

Sep 5, 2025
CVE-2025-58789
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects …

Sep 5, 2025
CVE-2025-58788
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This …

Sep 5, 2025
CVE-2025-58787
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Popup themify-popup allows Stored XSS.This issue affects Themify Popup: from n/a …

Sep 5, 2025
CVE-2025-58786
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects …

Sep 5, 2025
CVE-2025-58785
5.4 MEDIUM

Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ray Enterprise Translation: from n/a …

Sep 5, 2025
CVE-2025-58784
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft ARI Fancy Lightbox ari-fancy-lightbox allows Stored XSS.This issue affects ARI Fancy Lightbox: …

Sep 5, 2025
CVE-2025-58783
4.3 MEDIUM

Missing Authorization vulnerability in gutentor Gutentor gutentor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutentor: from n/a through <= 3.5.5.

Sep 5, 2025
CVE-2025-10011
6.3 MEDIUM

A weakness has been identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /module/TabelaArredondamento/edit. This manipulation of …

Sep 5, 2025
CVE-2024-21977
3.2 LOW

Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss …

Sep 5, 2025
CVE-2025-58313
5.1 MEDIUM

Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module.

Sep 5, 2025
CVE-2025-58296
7.5 HIGH

Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect function stability.

Sep 5, 2025
CVE-2025-58281
8.4 HIGH

Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation of this vulnerability may affect availability.

Sep 5, 2025
CVE-2025-58280
8.4 HIGH

Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerability may affect availability.

Sep 5, 2025
CVE-2025-58276
6.8 MEDIUM

Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.

Sep 5, 2025
CVE-2025-48395
4.7 MEDIUM

An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the …

Sep 5, 2025
CVE-2025-8944
4.3 MEDIUM

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, …

Sep 5, 2025
CVE-2025-58400
6.7 MEDIUM

RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write …

Sep 5, 2025
CVE-2025-55671
7.8 HIGH

Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege …

Sep 5, 2025
CVE-2025-55037
9.8 CRITICAL

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is …

Sep 5, 2025
CVE-2025-41408
4.3 MEDIUM

Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may …

Sep 5, 2025
CVE-2025-58401
6.8 MEDIUM

Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on …

Sep 5, 2025
CVE-2025-8684
6.4 MEDIUM

The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, 3.20.0 due to …

Sep 5, 2025
CVE-2025-9990
8.1 HIGH

The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. …

Sep 5, 2025
CVE-2025-7445
6.5 MEDIUM

Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.

Sep 5, 2025
CVE-2025-58362
7.5 HIGH

Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath utility function …

Sep 5, 2025
CVE-2025-58359

ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce …

Sep 5, 2025
CVE-2025-58352
6.5 MEDIUM

Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The …

Sep 5, 2025
CVE-2025-58179
7.2 HIGH

Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: …

Sep 5, 2025
CVE-2025-55739

api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through …

Sep 5, 2025
CVE-2025-55305
6.1 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and …

Sep 4, 2025
CVE-2025-55244
9.0 CRITICAL

Azure Bot Service Elevation of Privilege Vulnerability

Sep 4, 2025
CVE-2025-55242
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.

Sep 4, 2025
CVE-2025-55241
10.0 CRITICAL

Azure Entra ID Elevation of Privilege Vulnerability

Sep 4, 2025
CVE-2025-55238
7.5 HIGH

Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

Sep 4, 2025
CVE-2025-55209

contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions 15.0.14 and below, 16.0.0 through …

Sep 4, 2025
CVE-2025-55190
9.9 CRITICAL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through …

Sep 4, 2025
CVE-2025-54914
10.0 CRITICAL

Azure Networking Elevation of Privilege Vulnerability

Sep 4, 2025
CVE-2025-58361
9.3 CRITICAL

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive URL scheme check that does not protect …

Sep 4, 2025
CVE-2025-58353
8.2 HIGH

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio sanitize user input using regex blacklists …

Sep 4, 2025
CVE-2025-32322
7.8 HIGH

In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recording capabilities due to improper …

Sep 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.