CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-67734
5.4 MEDIUM

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript …

Dec 12, 2025
CVE-2025-14373
4.3 MEDIUM

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. …

Dec 12, 2025
CVE-2025-14372
6.1 MEDIUM

Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Dec 12, 2025
CVE-2025-8082
6.3 MEDIUM

Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to …

Dec 12, 2025
CVE-2025-14569
5.3 MEDIUM

A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after …

Dec 12, 2025
CVE-2025-14568
6.3 MEDIUM

A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This impacts an unknown function of the file model/User.php. The manipulation of the …

Dec 12, 2025
CVE-2025-67819
4.9 MEDIUM

An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker …

Dec 12, 2025
CVE-2025-67342
4.6 MEDIUM

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, …

Dec 12, 2025
CVE-2025-64011
4.3 MEDIUM

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files …

Dec 12, 2025
CVE-2025-67344
4.6 MEDIUM

jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.

Dec 12, 2025
CVE-2025-67341
4.6 MEDIUM

jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these …

Dec 12, 2025
CVE-2025-53960
5.9 MEDIUM

When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An attacker …

Dec 12, 2025
CVE-2025-14567
5.3 MEDIUM

A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This affects an unknown function of the file /api/employees. Executing manipulation can lead to …

Dec 12, 2025
CVE-2025-12843
5.5 MEDIUM

Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.

Dec 12, 2025
CVE-2025-36746
5.4 MEDIUM

SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a …

Dec 12, 2025
CVE-2025-36743
6.8 MEDIUM

SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of system internals and execution of debug commands.

Dec 12, 2025
CVE-2025-14442
5.3 MEDIUM

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in …

Dec 12, 2025
CVE-2025-14159
4.3 MEDIUM

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. …

Dec 12, 2025
CVE-2025-14065
4.3 MEDIUM

The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'simpbire_carica_prenotazioni' AJAX action …

Dec 12, 2025
CVE-2025-14030
6.4 MEDIUM

The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all versions up to, and including, 1.0.22 due …

Dec 12, 2025
CVE-2025-12965
6.4 MEDIUM

The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' parameter in the Magical Posts Accordion widget in all …

Dec 12, 2025
CVE-2025-12408
5.3 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 …

Dec 12, 2025
CVE-2025-12407
4.3 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 12, 2025
CVE-2025-12841
5.3 MEDIUM

The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.

Dec 12, 2025
CVE-2025-23408
6.5 MEDIUM

Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to …

Dec 12, 2025
CVE-2025-14074
4.3 MEDIUM

The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post duplication due to a missing …

Dec 12, 2025
CVE-2025-13993
5.5 MEDIUM

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_description' and 'success_message' parameters in versions up to, …

Dec 12, 2025
CVE-2025-12348
5.3 MEDIUM

The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.9.10. …

Dec 12, 2025
CVE-2025-12960
6.5 MEDIUM

The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.1 via the `href` parameter in …

Dec 12, 2025
CVE-2025-67730
5.4 MEDIUM

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious …

Dec 12, 2025
CVE-2025-4970
5.5 MEDIUM

The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.7.1 …

Dec 12, 2025
CVE-2025-14049
6.1 MEDIUM

The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'delto' parameter in all versions up to, and …

Dec 12, 2025
CVE-2025-13891
6.5 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. …

Dec 12, 2025
CVE-2025-11876
6.4 MEDIUM

The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_subscription_form' shortcode in all versions up to, and including, 1.3.1 …

Dec 12, 2025
CVE-2025-14356
4.3 MEDIUM

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Dec 12, 2025
CVE-2025-13660
5.3 MEDIUM

The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. This is due to the plugin …

Dec 12, 2025
CVE-2025-12655
5.3 MEDIUM

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, …

Dec 12, 2025
CVE-2025-67724
5.4 MEDIUM

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers …

Dec 12, 2025
CVE-2025-10684
4.3 MEDIUM

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as …

Dec 12, 2025
CVE-2025-66284
5.4 MEDIUM

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in …

Dec 12, 2025
CVE-2025-65120
6.1 MEDIUM

Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a …

Dec 12, 2025
CVE-2025-64781
4.7 MEDIUM

In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restriction" is set to …

Dec 12, 2025
CVE-2025-62192
5.4 MEDIUM

SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If exploited, information …

Dec 12, 2025
CVE-2025-61987
5.3 MEDIUM

GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a …

Dec 12, 2025
CVE-2025-61950
4.3 MEDIUM

In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted request, a …

Dec 12, 2025
CVE-2025-58576
4.3 MEDIUM

Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a …

Dec 12, 2025
CVE-2025-57883
6.1 MEDIUM

Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a …

Dec 12, 2025
CVE-2025-54407
6.1 MEDIUM

Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a …

Dec 12, 2025
CVE-2025-53523
5.4 MEDIUM

Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. A logged-in …

Dec 12, 2025
CVE-2025-14467
4.4 MEDIUM

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.4. This is due to …

Dec 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.