CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46725
9.8 CRITICAL

Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas eval() through `compute_from_docs()`. As a result, …

May 20, 2025
CVE-2025-46724
9.8 CRITICAL

Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval()`. If fed by untrusted user …

May 20, 2025
CVE-2025-37991
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that on parisc a SIGFPE exception will crash …

May 20, 2025
CVE-2025-37990
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The function brcmf_usb_dl_writeimage() calls the function brcmf_usb_dl_cmd() …

May 20, 2025
CVE-2025-37989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: leds: fix memory leak A network restart test on a router led to …

May 20, 2025
CVE-2025-37988
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount() Normally do_lock_mount(path, _) is locking …

May 20, 2025
CVE-2025-37987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent possible adminq overflow/stuck condition The pds_core's adminq is protected by the adminq_lock, which …

May 20, 2025
CVE-2025-37986
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Invalidate USB device pointers on partner unregistration To avoid using invalid USB …

May 20, 2025
CVE-2025-37985
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wdm_open and wdm_wwan_port_stop Clearing WDM_WWAN_IN_USE must be the last action …

May 20, 2025
CVE-2025-37984
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow …

May 20, 2025
CVE-2025-37983
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: qibfs: fix _another_ leak failure to allocate inode => leaked dentry... this one had been …

May 20, 2025
CVE-2025-22157
8.8 HIGH

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, …

May 20, 2025
CVE-2025-44084
9.8 CRITICAL

D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and …

May 20, 2025
CVE-2025-37982
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: fix memory leak in wl1251_tx_work The skb dequeued from tx_queue is lost when …

May 20, 2025
CVE-2025-37981
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Use is_kdump_kernel() to check for kdump The smartpqi driver checks the reset_devices variable …

May 20, 2025
CVE-2025-37980
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix resource leak in blk_register_queue() error path When registering a queue fails after blk_mq_sysfs_register() …

May 20, 2025
CVE-2025-37979
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix sc7280 lpass potential buffer overflow Case values introduced in commit 5f78e1fb7a3e ("ASoC: …

May 20, 2025
CVE-2025-37978
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: integrity: Do not call set_page_dirty_lock() Placing multiple protection information buffers inside the same page …

May 20, 2025
CVE-2025-37977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set If dma-coherent property isn't set …

May 20, 2025
CVE-2025-37976

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 20, 2025
CVE-2025-37975
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv: module: Fix out-of-bounds relocation access The current code allows rel[j] to access one element …

May 20, 2025
CVE-2025-37974
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix missing check for zpci_create_device() error return The zpci_create_device() function returns an error pointer …

May 20, 2025
CVE-2025-37973
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation Currently during the multi-link element defragmentation …

May 20, 2025
CVE-2025-37972
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: mtk-pmic-keys - fix possible null pointer dereference In mtk_pmic_keys_probe, the regs parameter is only …

May 20, 2025
CVE-2025-37971
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: bcm2835-camera: Initialise dev in v4l2_dev Commit 42a2f6664e18 ("staging: vc04_services: Move global g_state to vchiq_state") …

May 20, 2025
CVE-2025-37970
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo Prevent st_lsm6dsx_read_fifo from falling in an infinite …

May 20, 2025
CVE-2025-37969
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo Prevent st_lsm6dsx_read_tagged_fifo from falling in an infinite …

May 20, 2025
CVE-2025-37968
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: light: opt3001: fix deadlock due to concurrent flag access The threaded IRQ function in …

May 20, 2025
CVE-2025-37967
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix deadlock This patch introduces the ucsi_con_mutex_lock / ucsi_con_mutex_unlock functions to …

May 20, 2025
CVE-2025-37966
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix kernel crash due to PR_SET_TAGGED_ADDR_CTRL When userspace does PR_SET_TAGGED_ADDR_CTRL, but Supm extension is …

May 20, 2025
CVE-2025-37965
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix invalid context error in dml helper [Why] "BUG: sleeping function called from invalid …

May 20, 2025
CVE-2025-48018
7.5 HIGH

An authenticated user can modify application state data.

May 20, 2025
CVE-2025-48017
9.0 CRITICAL

Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files

May 20, 2025
CVE-2025-48016
4.3 MEDIUM

OpenFlow discovery protocol can exhaust resources because it is not rate limited

May 20, 2025
CVE-2025-48015
3.7 LOW

Failed login response could be different depending on whether the username was local or central.

May 20, 2025
CVE-2025-48014
7.5 HIGH

Password guessing limits could be bypassed when using LDAP authentication.

May 20, 2025
CVE-2025-37964
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr: There is a window …

May 20, 2025
CVE-2025-37963
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users Support for eBPF programs loaded …

May 20, 2025
CVE-2025-37962
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leak in parse_lease_state() The previous patch that added bounds check for create …

May 20, 2025
CVE-2025-37961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix uninit-value for saddr in do_output_route4 syzbot reports for uninit-value for the saddr argument …

May 20, 2025
CVE-2025-37960
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memblock: Accept allocated memory before use in memblock_double_array() When increasing the array size in memblock_double_array() …

May 20, 2025
CVE-2025-37959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redirect packets to a device …

May 20, 2025
CVE-2025-37958
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix dereferencing invalid pmd migration entry When migrating a THP, concurrent access to the …

May 20, 2025
CVE-2025-37957
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception Previously, commit ed129ec9057f ("KVM: x86: forcibly …

May 20, 2025
CVE-2025-37956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to ksmbd server. …

May 20, 2025
CVE-2025-37955
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable() The selftests added to our CI by Bui …

May 20, 2025
CVE-2025-37954
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: Avoid race in open_cached_dir with lease breaks A pre-existing valid cfid returned from …

May 20, 2025
CVE-2025-37953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sch_htb: make htb_deactivate() idempotent Alan reported a NULL pointer dereference in htb_next_rb_node() after we made …

May 20, 2025
CVE-2025-37952
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file …

May 20, 2025
CVE-2025-37951
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Add job to pending list if the reset was skipped When a CL/CSD job …

May 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.