CVE Database

140743+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10880
7.5 HIGH

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol …

Sep 25, 2025
CVE-2025-10879
5.3 MEDIUM

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to retrieve the current user's username without …

Sep 25, 2025
CVE-2025-60019
3.7 LOW

glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to …

Sep 25, 2025
CVE-2025-60018
4.8 MEDIUM

glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.

Sep 25, 2025
CVE-2025-59841
9.8 CRITICAL

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated …

Sep 25, 2025
CVE-2025-57446
7.5 HIGH

An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a denial of service (DoS) via a crafted …

Sep 25, 2025
CVE-2025-55560
7.5 HIGH

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled …

Sep 25, 2025
CVE-2025-55559
7.5 HIGH

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

Sep 25, 2025
CVE-2025-55558
7.5 HIGH

A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a …

Sep 25, 2025
CVE-2025-55557
7.5 HIGH

A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service …

Sep 25, 2025
CVE-2025-55556
6.5 MEDIUM

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

Sep 25, 2025
CVE-2025-55554
5.3 MEDIUM

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

Sep 25, 2025
CVE-2025-55553
7.5 HIGH

A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

Sep 25, 2025
CVE-2025-55552
7.5 HIGH

pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

Sep 25, 2025
CVE-2025-43943
6.7 MEDIUM

Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Sep 25, 2025
CVE-2025-33116
4.4 MEDIUM

IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Sep 25, 2025
CVE-2025-26333
5.9 MEDIUM

Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, …

Sep 25, 2025
CVE-2025-20363
9.0 CRITICAL

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, …

Sep 25, 2025
CVE-2025-20362
6.5 MEDIUM KEV

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software …

Sep 25, 2025
CVE-2025-20333
9.9 CRITICAL KEV

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could …

Sep 25, 2025
CVE-2025-10953
8.8 HIGH

A security vulnerability has been detected in UTT 1200GW and 1250GW up to 3.0.0-170831/3.2.2-200710. This vulnerability affects unknown code of the file /goform/formApMail. The manipulation …

Sep 25, 2025
CVE-2025-10952
5.3 MEDIUM

A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream_handler of the file ml_logger/server.py of …

Sep 25, 2025
CVE-2025-10911
5.5 MEDIUM

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

Sep 25, 2025
CVE-2024-48014
7.5 HIGH

Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, …

Sep 25, 2025
CVE-2025-59838
5.4 MEDIUM

Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user input when loading a saved custom text results …

Sep 25, 2025
CVE-2025-59832
9.9 CRITICAL

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket …

Sep 25, 2025
CVE-2025-59830
7.5 HIGH

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting …

Sep 25, 2025
CVE-2025-59823
9.9 CRITICAL

Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers …

Sep 25, 2025
CVE-2025-55551
7.5 HIGH

An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

Sep 25, 2025
CVE-2025-46153
5.3 MEDIUM

PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, …

Sep 25, 2025
CVE-2025-46152
5.3 MEDIUM

In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.

Sep 25, 2025
CVE-2025-46150
5.3 MEDIUM

In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.

Sep 25, 2025
CVE-2025-46149
5.3 MEDIUM

In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.

Sep 25, 2025
CVE-2025-46148
5.3 MEDIUM

In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.

Sep 25, 2025
CVE-2025-40838
7.5 HIGH

Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of …

Sep 25, 2025
CVE-2025-40837
8.8 HIGH

Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than …

Sep 25, 2025
CVE-2025-40836
9.8 CRITICAL

Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.

Sep 25, 2025
CVE-2025-36857
3.3 LOW

Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place …

Sep 25, 2025
CVE-2025-36601
4.0 MEDIUM

Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit …

Sep 25, 2025
CVE-2025-27262
7.8 HIGH

Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.

Sep 25, 2025
CVE-2025-10951
7.3 HIGH

A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vulnerability is the function log_handler of the file ml_logger/server.py. Such manipulation of …

Sep 25, 2025
CVE-2025-10950
6.3 MEDIUM

A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file ml_logger/server.py of the component Ping Handler. This …

Sep 25, 2025
CVE-2025-10949
2.4 LOW

A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation …

Sep 25, 2025
CVE-2025-10542
9.8 CRITICAL

iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these …

Sep 25, 2025
CVE-2025-10541
7.8 HIGH

iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files …

Sep 25, 2025
CVE-2020-36851

Rob -- W / cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to make HTTP requests to arbitrary …

Sep 25, 2025
CVE-2025-5494
3.9 LOW

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

Sep 25, 2025
CVE-2025-59839
8.6 HIGH

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video …

Sep 25, 2025
CVE-2025-59834
9.8 CRITICAL

ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server …

Sep 25, 2025
CVE-2025-59831
8.8 HIGH

git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerability in git-commiters. …

Sep 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.