CVE Database

141173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10322
5.3 MEDIUM

A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument …

Sep 12, 2025
CVE-2025-10321
5.3 MEDIUM

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. …

Sep 12, 2025
CVE-2025-56467
6.5 MEDIUM

An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as …

Sep 12, 2025
CVE-2025-52074
6.1 MEDIUM

PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a …

Sep 12, 2025
CVE-2025-43787
5.4 MEDIUM

A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, …

Sep 12, 2025
CVE-2024-45434
9.8 CRITICAL

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack …

Sep 12, 2025
CVE-2024-45433
6.5 MEDIUM

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from …

Sep 12, 2025
CVE-2024-45432
7.5 HIGH

OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an …

Sep 12, 2025
CVE-2024-45431
5.3 MEDIUM

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the …

Sep 12, 2025
CVE-2025-57579
8.0 HIGH

An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password

Sep 12, 2025
CVE-2025-57578
8.0 HIGH

An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password

Sep 12, 2025
CVE-2025-57577
8.0 HIGH

An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their …

Sep 12, 2025
CVE-2025-55835
9.8 CRITICAL

File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.

Sep 12, 2025
CVE-2025-39799

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 12, 2025
CVE-2025-39798
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFS: Fix the setting of capabilities when automounting a new filesystem Capabilities cannot be inherited …

Sep 12, 2025
CVE-2025-39797
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI Netlink message, which …

Sep 12, 2025
CVE-2025-39796
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: lapbether: ignore ops-locked netdevs Syzkaller managed to trigger lock dependency in xsk_notify via register_netdevice. …

Sep 12, 2025
CVE-2025-39795
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors check in blk_stack_limits() In blk_stack_limits(), we check that the …

Sep 12, 2025
CVE-2025-39794
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: tegra: Use I/O memcpy to write to IRAM Kasan crashes the kernel trying to …

Sep 12, 2025
CVE-2025-39793
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring/memmap: cast nr_pages to size_t before shifting If the allocated size exceeds UINT_MAX, then it's …

Sep 12, 2025
CVE-2025-39792
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm: Always split write BIOs to zoned device limits Any zoned DM target that requires …

Sep 12, 2025
CVE-2025-10320
3.1 LOW

A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in …

Sep 12, 2025
CVE-2025-55996
6.3 MEDIUM

Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface

Sep 12, 2025
CVE-2025-10319
4.3 MEDIUM

A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the …

Sep 12, 2025
CVE-2025-9556
9.8 CRITICAL

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends …

Sep 12, 2025
CVE-2025-59139
5.3 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could …

Sep 12, 2025
CVE-2025-59058
5.9 MEDIUM

httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signature comparison is not timing-safe. This makes …

Sep 12, 2025
CVE-2025-10365

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This …

Sep 12, 2025
CVE-2025-10364

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This …

Sep 12, 2025
CVE-2025-59054

dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execution environments. In versions of dstack prior to …

Sep 12, 2025
CVE-2025-10318
6.3 MEDIUM

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket …

Sep 12, 2025
CVE-2025-8699
9.1 CRITICAL

Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards …

Sep 12, 2025
CVE-2025-6638
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is …

Sep 12, 2025
CVE-2025-27240
7.2 HIGH

A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

Sep 12, 2025
CVE-2025-27238
3.5 LOW

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to …

Sep 12, 2025
CVE-2025-27234

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 …

Sep 12, 2025
CVE-2025-27233

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be …

Sep 12, 2025
CVE-2025-10267
5.3 MEDIUM

NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass …

Sep 12, 2025
CVE-2025-10266
9.8 CRITICAL

NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete …

Sep 12, 2025
CVE-2025-10265
8.8 HIGH

Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them …

Sep 12, 2025
CVE-2025-7448

Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack

Sep 12, 2025
CVE-2025-10264
10.0 CRITICAL

Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remoter attackers to access the system configuration file and …

Sep 12, 2025
CVE-2025-21043
8.8 HIGH KEV

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

Sep 12, 2025
CVE-2025-21042
8.8 HIGH KEV

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

Sep 12, 2025
CVE-2025-9086
7.5 HIGH

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, …

Sep 12, 2025
CVE-2025-8575
7.2 HIGH

The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'lws_cl_delete_file' function in all versions …

Sep 12, 2025
CVE-2025-8280
5.8 MEDIUM

The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead …

Sep 12, 2025
CVE-2025-7337
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-6769
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-6454
8.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.