CVE Vulnerability Database
Search and browse 394,758 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69128 | HIGH | 8.6 | 0.5% | Jun 17, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Pat... |
| CVE-2025-69127 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. |
| CVE-2025-69126 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions. |
| CVE-2025-69123 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions. |
| CVE-2025-69120 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions. |
| CVE-2025-69115 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions. |
| CVE-2025-69111 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. |
| CVE-2025-69106 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. |
| CVE-2025-68524 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions. |
| CVE-2025-66391 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write o... |
| CVE-2025-60236 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: f... |
| CVE-2025-60231 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue aff... |
| CVE-2025-60230 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects... |
| CVE-2025-60229 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: fr... |
| CVE-2025-59554 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. |
| CVE-2025-15657 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions. |
| CVE-2026-9690 | HIGH | 7.5 | 0.5% | Jun 17, 2026 | Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. |
| CVE-2026-9570 | HIGH | 7.1 | 0.1% | Jun 17, 2026 | The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline ... |
| CVE-2026-8607 | MEDIUM | 6.4 | 0.3% | Jun 17, 2026 | The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress ... |
| CVE-2026-8494 | MEDIUM | 6.4 | 0.2% | Jun 17, 2026 | The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admi... |
| CVE-2026-8383 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `e... |
| CVE-2026-8317 | — | — | — | Jun 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-8089 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin ... |
| CVE-2026-7850 | MEDIUM | 5.9 | 0.1% | Jun 17, 2026 | The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting t... |
| CVE-2026-5667 | HIGH | 7.2 | 0.2% | Jun 17, 2026 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); ... |
