CVE Vulnerability Database

Search and browse 394,827 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-69112HIGH8.1Unauthenticated Local File Inclusion in Planty <= 1.14.0 versions.
CVE-2025-69110HIGH8.1Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.
CVE-2025-69109HIGH8.1Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions.
CVE-2025-69108CRITICAL9.8Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
CVE-2025-69107HIGH8.1Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions.
CVE-2025-69105HIGH8.1Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions.
CVE-2025-69104HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions.
CVE-2025-69103HIGH7.5Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.
CVE-2025-62340MEDIUM5.3HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where ...
CVE-2025-60223HIGH7.7Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
CVE-2025-60218CRITICAL9.9Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
CVE-2025-60205CRITICAL9.8Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
CVE-2025-60085HIGH8.1Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.
CVE-2025-59872CRITICAL9.8HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t...
CVE-2025-59563HIGH8.8Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.
CVE-2025-59560HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.
CVE-2025-58954HIGH8.1Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.
CVE-2025-58953HIGH8.1Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.
CVE-2025-58952HIGH8.1Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
CVE-2025-58924HIGH8.1Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
CVE-2025-49403HIGH7.5Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.
CVE-2025-48643HIGH7.8In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local...
CVE-2025-48640HIGH8In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. T...
CVE-2025-48617HIGH7.8In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. ...
CVE-2025-48571MEDIUM4.3In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic er...