VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,982 CVE recordsPage 631 of 1333 · EPSS data 2026.08.13
ReviewCritical
CVE-2025-60218

WPLocker PT Luxa Addons

CVE-2025-60218 affects WPLocker PT Luxa Addons. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-60205

ThemeREX ThemeREX Addons

CVE-2025-60205 affects ThemeREX ThemeREX Addons. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-60085

ThemeREX Group Learnify

CVE-2025-60085 affects ThemeREX Group Learnify. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-59872

HCL Software ZIE, zie for web

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-59563

SONAAR MUSIC Sonaar

CVE-2025-59563 affects SONAAR MUSIC Sonaar. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-59560

SONAAR MUSIC Sonaar

CVE-2025-59560 affects SONAAR MUSIC Sonaar. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-58954

ThemeREX HomeRoofer

CVE-2025-58954 affects ThemeREX HomeRoofer. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-58953

ThemeREX Joly

CVE-2025-58953 affects ThemeREX Joly. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-58952

ThemeREX Neuronet

CVE-2025-58952 affects ThemeREX Neuronet. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-58924

ThemeREX Group Geya

CVE-2025-58924 affects ThemeREX Group Geya. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-48643

Google Android, android

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-48640

Google Android, android

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-48617

Google Android, android

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-31013

Themify Themify Folo

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue affects Themify Folo: from n/a through 1.9.6.

The CVSS severity warrants an early asset and exposure review.