CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64319
5.3 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before …

Nov 4, 2025
CVE-2025-64318
5.3 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code …

Nov 4, 2025
CVE-2025-54334
7.5 HIGH

An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL Pointer …

Nov 4, 2025
CVE-2025-52513
7.5 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in an out-of-bounds write, leading …

Nov 4, 2025
CVE-2025-52512
7.5 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in out-of-bounds memory access, leading …

Nov 4, 2025
CVE-2025-12108

The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration wizard immediately without a login prompt or …

Nov 4, 2025
CVE-2025-10875
6.5 MEDIUM

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue affects Mulesoft Anypoint Code Builder: before …

Nov 4, 2025
CVE-2025-54333
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the …

Nov 4, 2025
CVE-2025-54325
5.3 MEDIUM

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. …

Nov 4, 2025
CVE-2025-61956
10.0 CRITICAL

Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without …

Nov 4, 2025
CVE-2025-61945
10.0 CRITICAL

Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can …

Nov 4, 2025
CVE-2025-60925
5.3 MEDIUM

codeshare v1.0.0 was discovered to contain an information leakage vulnerability.

Nov 4, 2025
CVE-2025-54863
10.0 CRITICAL

Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather …

Nov 4, 2025
CVE-2025-54332
7.5 HIGH

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.node in the …

Nov 4, 2025
CVE-2025-54331
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the …

Nov 4, 2025
CVE-2025-54330
5.3 MEDIUM

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me …

Nov 4, 2025
CVE-2025-54329
7.5 HIGH

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, …

Nov 4, 2025
CVE-2025-54323
7.5 HIGH

An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. …

Nov 4, 2025
CVE-2025-63294
6.5 MEDIUM

WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf …

Nov 4, 2025
CVE-2025-12184
4.4 MEDIUM

The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.11 due to insufficient …

Nov 4, 2025
CVE-2025-41345
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41344
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41343
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41342
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41341
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41340
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41339
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41338
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41337
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41336
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41335
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-12695
5.9 MEDIUM

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input …

Nov 4, 2025
CVE-2025-12682
9.8 CRITICAL

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' …

Nov 4, 2025
CVE-2025-41114
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41113
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41112
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-41111
7.5 HIGH

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through …

Nov 4, 2025
CVE-2025-12493
9.8 CRITICAL

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local …

Nov 4, 2025
CVE-2025-12045
6.4 MEDIUM

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 4, 2025
CVE-2025-11690
8.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue …

Nov 4, 2025
CVE-2025-20749
6.7 MEDIUM

In charger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Nov 4, 2025
CVE-2025-20748
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20747
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Nov 4, 2025
CVE-2025-20746
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Nov 4, 2025
CVE-2025-20745
4.2 MEDIUM

In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Nov 4, 2025
CVE-2025-20744
4.2 MEDIUM

In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious …

Nov 4, 2025
CVE-2025-20743
4.2 MEDIUM

In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious …

Nov 4, 2025
CVE-2025-20742
8.0 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Nov 4, 2025
CVE-2025-20741
6.7 MEDIUM

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Nov 4, 2025
CVE-2025-20740
4.7 MEDIUM

In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with …

Nov 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.