CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40682
9.8 CRITICAL

SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and …

Jul 29, 2025
CVE-2025-5587
6.4 MEDIUM

The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.2.6 due to …

Jul 29, 2025
CVE-2025-8216
6.4 MEDIUM

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in all versions up to, and including, 3.1.4 …

Jul 29, 2025
CVE-2025-8196
6.4 MEDIUM

The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes in all versions up to, and …

Jul 29, 2025
CVE-2025-7689
8.8 HIGH

The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to …

Jul 29, 2025
CVE-2025-6730
4.3 MEDIUM

The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jul 29, 2025
CVE-2025-6692
6.4 MEDIUM

The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all versions up to, and including, 10.3 due …

Jul 29, 2025
CVE-2025-6681
6.4 MEDIUM

The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.0.1 due …

Jul 29, 2025
CVE-2025-26400
5.3 MEDIUM

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, …

Jul 29, 2025
CVE-2025-53082
6.1 MEDIUM

An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to …

Jul 29, 2025
CVE-2025-53081
6.4 MEDIUM

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to …

Jul 29, 2025
CVE-2025-8264
9.0 CRITICAL

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious …

Jul 29, 2025
CVE-2025-6495
7.5 HIGH

The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to …

Jul 29, 2025
CVE-2025-53649
5.1 MEDIUM

"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive …

Jul 29, 2025
CVE-2025-53080
7.1 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended …

Jul 29, 2025
CVE-2025-53079
4.9 MEDIUM

Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

Jul 29, 2025
CVE-2025-53078
8.0 HIGH

Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

Jul 29, 2025
CVE-2025-53077
6.5 MEDIUM

An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the …

Jul 29, 2025
CVE-2025-4566
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element …

Jul 29, 2025
CVE-2025-4370
5.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing …

Jul 29, 2025
CVE-2025-3075
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode …

Jul 29, 2025
CVE-2025-7811
6.4 MEDIUM

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-7810
5.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-7809
6.4 MEDIUM

The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-54666

Rejected reason: Not used

Jul 29, 2025
CVE-2025-54665

Rejected reason: Not used

Jul 29, 2025
CVE-2025-54664

Rejected reason: Not used

Jul 29, 2025
CVE-2025-54663

Rejected reason: Not used

Jul 29, 2025
CVE-2025-54662

Rejected reason: Not used

Jul 29, 2025
CVE-2025-54661

Rejected reason: Not used

Jul 29, 2025
CVE-2025-54769
8.8 HIGH

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. …

Jul 29, 2025
CVE-2025-54768
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54767
6.5 MEDIUM

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

Jul 29, 2025
CVE-2025-54766
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54765
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54429

Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account address types in Frontier, e.g. precompiled contracts, smart …

Jul 28, 2025
CVE-2025-54428
9.8 CRITICAL

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below 1.0.1, a valid MongoDB Atlas …

Jul 28, 2025
CVE-2025-54427

Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_price_target is an inherent extrinsic, meaning only the block producer …

Jul 28, 2025
CVE-2025-54426

Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and Curve25519ScalarMul precompiles incorrectly …

Jul 28, 2025
CVE-2025-54423
5.4 MEDIUM

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in …

Jul 28, 2025
CVE-2025-54419
10.0 CRITICAL

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. …

Jul 28, 2025
CVE-2025-50486
7.1 HIGH

Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50485
7.1 HIGH

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-29534
8.8 HIGH

An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbitrary commands with root …

Jul 28, 2025
CVE-2025-8283
3.7 LOW

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may …

Jul 28, 2025
CVE-2025-8194
7.5 HIGH

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with …

Jul 28, 2025
CVE-2025-50487
7.1 HIGH

Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50484
7.1 HIGH

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-54299

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

Jul 28, 2025
CVE-2025-54298

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

Jul 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.