CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48171
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Cena Store cena allows PHP Local File Inclusion.This …

Aug 20, 2025
CVE-2025-48170
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected …

Aug 20, 2025
CVE-2025-48169
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Remote Code Inclusion.This issue affects Code Engine: from n/a …

Aug 20, 2025
CVE-2025-48168
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Audio Player lbg-audio5-html5-shoutcast-sticky allows Reflected XSS.This …

Aug 20, 2025
CVE-2025-48165
8.8 HIGH

Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a through <= 2.6.0.

Aug 20, 2025
CVE-2025-48164
8.8 HIGH

Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash suredash allows Privilege Escalation.This issue affects SureDash: from n/a through <= 1.0.3.

Aug 20, 2025
CVE-2025-48163
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT - HTML5 Radio Player With Ads - ShoutCast and IceCast Support …

Aug 20, 2025
CVE-2025-48162
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business …

Aug 20, 2025
CVE-2025-48160
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris caliris-wp allows PHP Local File Inclusion.This issue …

Aug 20, 2025
CVE-2025-48159
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtube Vimeo Video Player and Slider WP Plugin video-player-youtube-vimeo allows Reflected XSS.This …

Aug 20, 2025
CVE-2025-48158
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field buddypress-xprofile-image-field allows Path Traversal.This issue …

Aug 20, 2025
CVE-2025-48157
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality formality allows PHP Local File Inclusion.This …

Aug 20, 2025
CVE-2025-48154
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder lbg_vp_youtube_vimeo_addon_visual_composer allows Reflected XSS.This …

Aug 20, 2025
CVE-2025-48152
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dimafreund Rentsyst rentsyst allows Reflected XSS.This issue affects Rentsyst: from n/a through <= …

Aug 20, 2025
CVE-2025-48151
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations cm-map-locations allows Reflected XSS.This issue affects CM Map Locations: …

Aug 20, 2025
CVE-2025-48149
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Cook&Meal cookandmeal allows PHP Local File Inclusion.This issue …

Aug 20, 2025
CVE-2025-48148
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Using Malicious Files.This issue affects StoreKeeper for WooCommerce: from …

Aug 20, 2025
CVE-2025-48142
8.8 HIGH

Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affects Bookify: from n/a through <= 1.0.9.

Aug 20, 2025
CVE-2025-47650
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global infility-global allows Path Traversal.This issue affects Infility Global: from …

Aug 20, 2025
CVE-2025-30975
7.5 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issue affects Add Custom Codes: from n/a …

Aug 20, 2025
CVE-2025-28977
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS. This issue affects WP Pipes: from n/a …

Aug 20, 2025
CVE-2025-9202
4.3 MEDIUM

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions …

Aug 20, 2025
CVE-2025-8618
6.4 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up …

Aug 20, 2025
CVE-2025-55706
4.3 MEDIUM

URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the …

Aug 20, 2025
CVE-2025-54551
4.3 MEDIUM

Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the …

Aug 20, 2025
CVE-2025-53522
5.3 MEDIUM

Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote …

Aug 20, 2025
CVE-2025-57791
6.5 MEDIUM

A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. …

Aug 20, 2025
CVE-2025-57790
8.8 HIGH

A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead …

Aug 20, 2025
CVE-2025-57789
5.4 MEDIUM

During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited …

Aug 20, 2025
CVE-2025-57788
6.5 MEDIUM

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does …

Aug 20, 2025
CVE-2025-57748

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57747

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57746

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57745

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57744

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57743

Rejected reason: Not used

Aug 20, 2025
CVE-2025-57742

Rejected reason: Not used

Aug 20, 2025
CVE-2025-8289
7.5 HIGH

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization …

Aug 20, 2025
CVE-2025-8145
8.8 HIGH

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization …

Aug 20, 2025
CVE-2025-8141
8.8 HIGH

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function …

Aug 20, 2025
CVE-2025-54364

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible …

Aug 20, 2025
CVE-2025-54363

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible …

Aug 20, 2025
CVE-2025-9132
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Aug 20, 2025
CVE-2024-12223

Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim …

Aug 20, 2025
CVE-2025-9193
3.5 LOW

A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing …

Aug 20, 2025
CVE-2025-9176
5.3 MEDIUM

A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment …

Aug 20, 2025
CVE-2025-9175
5.3 MEDIUM

A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c. The manipulation leads to stack-based …

Aug 19, 2025
CVE-2025-9174
5.3 MEDIUM

A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filename Handler. …

Aug 19, 2025
CVE-2025-9171
3.5 LOW

A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component …

Aug 19, 2025
CVE-2025-9170
3.5 LOW

A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates …

Aug 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.