CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10243

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 5, 2025
CVE-2024-10212

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 5, 2025
CVE-2024-0398

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 5, 2025
CVE-2023-6820

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 5, 2025
CVE-2023-6818

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 5, 2025
CVE-2023-6770

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 5, 2025
CVE-2023-6726

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 5, 2025
CVE-2023-5361

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 5, 2025
CVE-2025-7074
4.3 MEDIUM

A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation …

Jul 5, 2025
CVE-2023-50786
4.1 MEDIUM

Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an …

Jul 5, 2025
CVE-2025-47228
6.7 MEDIUM

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands …

Jul 5, 2025
CVE-2025-47227
7.5 HIGH

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST …

Jul 5, 2025
CVE-2024-58254

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-11738. Reason: This candidate is a duplicate of CVE-2024-11738. Notes: All CVE users should reference CVE-2024-11738 …

Jul 5, 2025
CVE-2025-53605
5.9 MEDIUM

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

Jul 5, 2025
CVE-2025-53604
4.0 MEDIUM

The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length …

Jul 5, 2025
CVE-2025-53603
7.5 HIGH

In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the …

Jul 5, 2025
CVE-2025-43711
8.1 HIGH

Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file …

Jul 5, 2025
CVE-2025-26850
9.3 CRITICAL

The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.

Jul 5, 2025
CVE-2025-48952
9.4 CRITICAL

NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to bypass password verification …

Jul 4, 2025
CVE-2025-7070
4.3 MEDIUM

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 4, 2025
CVE-2025-53366

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.9.4, a validation error …

Jul 4, 2025
CVE-2025-53365

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a client …

Jul 4, 2025
CVE-2025-7069
3.3 LOW

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to …

Jul 4, 2025
CVE-2025-7068
3.3 LOW

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation …

Jul 4, 2025
CVE-2025-53602
5.3 MEDIUM

Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.

Jul 4, 2025
CVE-2025-7067
3.3 LOW

A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-based …

Jul 4, 2025
CVE-2025-53485
7.5 HIGH

SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in …

Jul 4, 2025
CVE-2025-53484
9.8 CRITICAL

User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPagesTab() and getErrorsTab() (user-controllable page names) This allows attackers to inject JavaScript and …

Jul 4, 2025
CVE-2025-53483
8.8 HIGH

ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF tokens, allowing attackers to trigger sensitive actions if an admin visits a malicious site. …

Jul 4, 2025
CVE-2025-53482
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Cross-Site Scripting (XSS).This issue …

Jul 4, 2025
CVE-2025-53481
7.5 HIGH

Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Allocation.This issue affects Mediawiki - IPInfo Extension: from 1.39.X before 1.39.13, from …

Jul 4, 2025
CVE-2025-52497
4.8 MEDIUM

Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.

Jul 4, 2025
CVE-2025-52496
7.8 HIGH

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES …

Jul 4, 2025
CVE-2025-49601
4.8 MEDIUM

In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a …

Jul 4, 2025
CVE-2025-49600
4.9 MEDIUM

In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in …

Jul 4, 2025
CVE-2025-46733
7.9 HIGH

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In …

Jul 4, 2025
CVE-2025-38234
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======== When a CPU chooses to call push_rt_task and …

Jul 4, 2025
CVE-2025-38233
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix clobbered r15 during livepatching While r15 is clobbered always with PPC_FTRACE_OUT_OF_LINE, it is …

Jul 4, 2025
CVE-2025-38232
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and exports_proc As of now nfsd calls create_proc_exports_entry() at …

Jul 4, 2025
CVE-2025-38231
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: Initialize ssc before laundromat_work to prevent NULL dereference In nfs4_state_start_net(), laundromat_work may access nfsd_ssc …

Jul 4, 2025
CVE-2025-38230
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: validate AG parameters in dbMount() to prevent crashes Validate db_agheight, db_agwidth, and db_agstart in …

Jul 4, 2025
CVE-2025-38229
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: cxusb: no longer judge rbuf when the write fails syzbot reported a uninit-value in …

Jul 4, 2025
CVE-2025-38228
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: imagination: fix a potential memory leak in e5010_probe() Add video_device_release() to release the memory …

Jul 4, 2025
CVE-2025-38227
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of initialization failure syzbot reported a slab-use-after-free Read in …

Jul 4, 2025
CVE-2025-38226
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: vivid: Change the siize of the composing syzkaller found a bug: BUG: KASAN: vmalloc-out-of-bounds …

Jul 4, 2025
CVE-2025-38225
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Cleanup after an allocation error When allocation failures are not cleaned up by …

Jul 4, 2025
CVE-2025-38224
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: kvaser_pciefd: refine error prone echo_skb_max handling logic echo_skb_max should define the supported upper limit …

Jul 4, 2025
CVE-2025-38223
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid kernel BUG for encrypted inode with unaligned file size The generic/397 test hits …

Jul 4, 2025
CVE-2025-38222
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: inline: fix len overflow in ext4_prepare_inline_data When running the following code on an ext4 …

Jul 4, 2025
CVE-2025-38221
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ext4: fix out of bounds punch offset Punching a hole with a start offset that …

Jul 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.