CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48142
8.8 HIGH

Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affects Bookify: from n/a through <= 1.0.9.

Aug 20, 2025
CVE-2025-47650
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global infility-global allows Path Traversal.This issue affects Infility Global: from …

Aug 20, 2025
CVE-2025-30975
7.5 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issue affects Add Custom Codes: from n/a …

Aug 20, 2025
CVE-2025-28977
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS. This issue affects WP Pipes: from n/a …

Aug 20, 2025
CVE-2025-9202
4.3 MEDIUM

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions …

Aug 20, 2025
CVE-2025-8618
6.4 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up …

Aug 20, 2025
CVE-2025-55706
4.3 MEDIUM

URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the …

Aug 20, 2025
CVE-2025-54551
4.3 MEDIUM

Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the …

Aug 20, 2025
CVE-2025-53522
5.3 MEDIUM

Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote …

Aug 20, 2025
CVE-2025-57791
6.5 MEDIUM

A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. …

Aug 20, 2025
CVE-2025-57790
8.8 HIGH

A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead …

Aug 20, 2025
CVE-2025-57789
5.4 MEDIUM

During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited …

Aug 20, 2025
CVE-2025-57788
6.5 MEDIUM

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does …

Aug 20, 2025
CVE-2025-57748

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57747

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57746

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57745

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57744

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57743

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57742

Rejected reason: Not used

Aug 20, 2025
CVE-2025-8289
7.5 HIGH

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization …

Aug 20, 2025
CVE-2025-8145
8.8 HIGH

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization …

Aug 20, 2025
CVE-2025-8141
8.8 HIGH

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function …

Aug 20, 2025
CVE-2025-54364

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible …

Aug 20, 2025
CVE-2025-54363

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible …

Aug 20, 2025
CVE-2025-9132
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Aug 20, 2025
CVE-2024-12223

Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim …

Aug 20, 2025
CVE-2025-9193
3.5 LOW

A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing …

Aug 20, 2025
CVE-2025-9176
5.3 MEDIUM

A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment …

Aug 20, 2025
CVE-2025-9175
5.3 MEDIUM

A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c. The manipulation leads to stack-based …

Aug 19, 2025
CVE-2025-9174
5.3 MEDIUM

A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filename Handler. …

Aug 19, 2025
CVE-2025-9171
3.5 LOW

A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component …

Aug 19, 2025
CVE-2025-9170
3.5 LOW

A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates …

Aug 19, 2025
CVE-2025-9169
3.5 LOW

A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation …

Aug 19, 2025
CVE-2025-9187
9.8 CRITICAL

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Aug 19, 2025
CVE-2025-9186
6.5 MEDIUM

Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.

Aug 19, 2025
CVE-2025-9185
8.1 HIGH

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. …

Aug 19, 2025
CVE-2025-9184
8.1 HIGH

Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption …

Aug 19, 2025
CVE-2025-9183
6.5 MEDIUM

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.

Aug 19, 2025
CVE-2025-9182
7.5 HIGH

Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.

Aug 19, 2025
CVE-2025-9181
6.5 MEDIUM

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and …

Aug 19, 2025
CVE-2025-9180
8.1 HIGH

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird …

Aug 19, 2025
CVE-2025-9179
9.8 CRITICAL

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly …

Aug 19, 2025
CVE-2025-9168
3.5 LOW

A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. …

Aug 19, 2025
CVE-2025-9167
3.5 LOW

A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. …

Aug 19, 2025
CVE-2025-8364
4.3 MEDIUM

A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue …

Aug 19, 2025
CVE-2025-8042
9.8 CRITICAL

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.

Aug 19, 2025
CVE-2025-8041
5.3 MEDIUM

In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in …

Aug 19, 2025
CVE-2025-55033
6.1 MEDIUM

Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability …

Aug 19, 2025
CVE-2025-55032
6.1 MEDIUM

Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowing for XSS attacks. This …

Aug 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.