CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36005
5.9 MEDIUM

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 …

Jul 24, 2025
CVE-2025-33109
7.5 HIGH

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could …

Jul 24, 2025
CVE-2025-33013
6.2 MEDIUM

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 …

Jul 24, 2025
CVE-2025-4784
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This issue affects Tourtella: before 26.05.2025.

Jul 24, 2025
CVE-2025-45731
6.5 MEDIUM

A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other operations are pending.

Jul 24, 2025
CVE-2025-5243
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information …

Jul 24, 2025
CVE-2025-4822
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection.This issue affects ScadaWatt …

Jul 24, 2025
CVE-2025-40680

Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT session token in plain text …

Jul 24, 2025
CVE-2025-8071
6.4 MEDIUM

Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all versions up to, and including, 2.1.10 due to …

Jul 24, 2025
CVE-2025-7966
6.4 MEDIUM

The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and 'subs_count’ parameters in all versions up to, …

Jul 24, 2025
CVE-2025-7959
6.4 MEDIUM

The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter in all versions up to, and including, …

Jul 24, 2025
CVE-2025-7835
4.3 MEDIUM

The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due …

Jul 24, 2025
CVE-2025-7822
4.3 MEDIUM

The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all …

Jul 24, 2025
CVE-2025-7780
6.5 MEDIUM

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to …

Jul 24, 2025
CVE-2025-7695
8.8 HIGH

The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST endpoint in versions 2.77 through …

Jul 24, 2025
CVE-2025-7690
6.1 MEDIUM

The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing …

Jul 24, 2025
CVE-2025-7640
8.1 HIGH

The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to …

Jul 24, 2025
CVE-2025-6588
6.1 MEDIUM

The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to, and including, 1.4.3 due to …

Jul 24, 2025
CVE-2025-6539
6.4 MEDIUM

The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.5 …

Jul 24, 2025
CVE-2025-6441
9.8 CRITICAL

The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a …

Jul 24, 2025
CVE-2025-6387
6.4 MEDIUM

The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, …

Jul 24, 2025
CVE-2025-6385
6.4 MEDIUM

The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 0.4.1 due …

Jul 24, 2025
CVE-2025-6382
6.4 MEDIUM

The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortcode in all versions up to, and including, 0.1.10. …

Jul 24, 2025
CVE-2025-6380
9.8 CRITICAL

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. …

Jul 24, 2025
CVE-2025-6262
6.4 MEDIUM

The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai shortcode in all versions up to, and including, …

Jul 24, 2025
CVE-2025-5084
6.1 MEDIUM

The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and including, 3.4.13 …

Jul 24, 2025
CVE-2025-4608
6.4 MEDIUM

The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and including, 1.6.4 …

Jul 24, 2025
CVE-2025-3669
6.4 MEDIUM

The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's auto_qrcodesabb shortcode in all versions up to, …

Jul 24, 2025
CVE-2025-8107
6.3 MEDIUM

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability …

Jul 24, 2025
CVE-2025-8009
4.9 MEDIUM

The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, …

Jul 24, 2025
CVE-2025-7745
5.8 MEDIUM

Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.

Jul 24, 2025
CVE-2025-26397
7.8 HIGH

SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious …

Jul 24, 2025
CVE-2025-7852
9.8 CRITICAL

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' …

Jul 24, 2025
CVE-2025-7437
9.8 CRITICAL

The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions …

Jul 24, 2025
CVE-2025-7001
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have …

Jul 24, 2025
CVE-2025-4976
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain …

Jul 24, 2025
CVE-2025-4968
6.4 MEDIUM

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separator …

Jul 24, 2025
CVE-2025-4395
6.8 MEDIUM

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no …

Jul 24, 2025
CVE-2025-4394
6.8 MEDIUM

Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue …

Jul 24, 2025
CVE-2025-4393
6.5 MEDIUM

Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary …

Jul 24, 2025
CVE-2025-41240
10.0 CRITICAL

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this …

Jul 24, 2025
CVE-2025-1299
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions …

Jul 24, 2025
CVE-2025-0765
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have …

Jul 24, 2025
CVE-2025-54365
7.5 HIGH

fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular …

Jul 23, 2025
CVE-2016-15044

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated …

Jul 23, 2025
CVE-2025-54377
7.8 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) …

Jul 23, 2025
CVE-2025-54371

Rejected reason: This CVE is a duplicate of another CVE.

Jul 23, 2025
CVE-2025-53942
7.4 HIGH

authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as …

Jul 23, 2025
CVE-2025-53537
7.5 HIGH

LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory …

Jul 23, 2025
CVE-2025-47281
7.7 HIGH

Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerability exists due …

Jul 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.