CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48610
5.5 MEDIUM

In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in the code. This could lead to local information …

Dec 8, 2025
CVE-2025-48607
5.5 MEDIUM

In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. This …

Dec 8, 2025
CVE-2025-48604
5.5 MEDIUM

In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local …

Dec 8, 2025
CVE-2025-48603
5.5 MEDIUM

In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with …

Dec 8, 2025
CVE-2025-48601
5.5 MEDIUM

In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privilege with …

Dec 8, 2025
CVE-2025-48600
5.5 MEDIUM

In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information …

Dec 8, 2025
CVE-2025-48598
6.6 MEDIUM

In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy. This could lead to …

Dec 8, 2025
CVE-2025-48591
5.5 MEDIUM

In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local …

Dec 8, 2025
CVE-2025-48590
5.5 MEDIUM

In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to resource exhaustion. …

Dec 8, 2025
CVE-2025-48584
5.5 MEDIUM

In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource exhaustion. This could lead to local denial …

Dec 8, 2025
CVE-2025-48576
5.5 MEDIUM

In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with …

Dec 8, 2025
CVE-2025-32319
6.7 MEDIUM

In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. This could lead …

Dec 8, 2025
CVE-2025-22432
6.7 MEDIUM

In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to local escalation of privilege and background …

Dec 8, 2025
CVE-2025-65798
5.4 MEDIUM

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

Dec 8, 2025
CVE-2025-65796
4.3 MEDIUM

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

Dec 8, 2025
CVE-2025-14247
6.3 MEDIUM

A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php. Executing manipulation of the argument …

Dec 8, 2025
CVE-2025-14246
6.3 MEDIUM

A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file /Customers/settings.php. Performing manipulation of the argument user_id …

Dec 8, 2025
CVE-2025-14230
6.3 MEDIUM

A vulnerability was detected in code-projects Daily Time Recording System 4.5.0. The impacted element is an unknown function of the file /admin/add_payroll.php. Performing manipulation of …

Dec 8, 2025
CVE-2025-14229
4.7 MEDIUM

A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. …

Dec 8, 2025
CVE-2025-66461
6.7 MEDIUM

FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM …

Dec 8, 2025
CVE-2025-14262
4.3 MEDIUM

A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were …

Dec 8, 2025
CVE-2025-14227
6.3 MEDIUM

A security flaw has been discovered in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This issue affects some unknown processing of the file /edit.php. The manipulation results …

Dec 8, 2025
CVE-2025-14225
6.3 MEDIUM

A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the …

Dec 8, 2025
CVE-2025-66330
4.9 MEDIUM

App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 8, 2025
CVE-2025-66329
4.0 MEDIUM

Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66325
6.2 MEDIUM

Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 8, 2025
CVE-2025-58279
4.4 MEDIUM

Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 8, 2025
CVE-2025-26489
6.5 MEDIUM

Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, thus causing a …

Dec 8, 2025
CVE-2025-14224
4.3 MEDIUM

A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File …

Dec 8, 2025
CVE-2025-66326
6.7 MEDIUM

Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66323
5.3 MEDIUM

Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66322
5.1 MEDIUM

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66321
5.1 MEDIUM

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66320
5.1 MEDIUM

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-14255
6.5 MEDIUM

Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Dec 8, 2025
CVE-2025-14254
6.5 MEDIUM

Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Dec 8, 2025
CVE-2025-14253
4.9 MEDIUM

Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary …

Dec 8, 2025
CVE-2025-14222
6.3 MEDIUM

A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file /print_personnel_report.php. This manipulation of the …

Dec 8, 2025
CVE-2025-14220
4.3 MEDIUM

A security vulnerability has been detected in ORICO CD3510 1.9.12. This affects an unknown function of the component File Upload. The manipulation leads to path …

Dec 8, 2025
CVE-2025-14219
4.7 MEDIUM

A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_running.php. Executing …

Dec 8, 2025
CVE-2025-14214
6.3 MEDIUM

A vulnerability has been found in itsourcecode Student Information System 1.0. This affects an unknown part of the file /section_edit1.php. The manipulation of the argument …

Dec 8, 2025
CVE-2025-14208
6.3 MEDIUM

A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the …

Dec 8, 2025
CVE-2025-14206
6.5 MEDIUM

A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/delete-fee.php of the component …

Dec 8, 2025
CVE-2025-14204
6.3 MEDIUM

A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthorization of the file /.well-known/oauth-authorization-server of the component OAuth Server Discovery. …

Dec 7, 2025
CVE-2025-14203
6.3 MEDIUM

A flaw has been found in code-projects Question Paper Generator up to 1.0. This vulnerability affects unknown code of the file /selectquestionuser.php. This manipulation of …

Dec 7, 2025
CVE-2025-14199
6.3 MEDIUM

A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text.txt?override=false of the component Web Administration …

Dec 7, 2025
CVE-2025-14198
5.3 MEDIUM

A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummytoken of the component Web Administration Module. Performing manipulation …

Dec 7, 2025
CVE-2025-14197
5.3 MEDIUM

A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/resources/f96956469e7be39d of the …

Dec 7, 2025
CVE-2025-14195
6.3 MEDIUM

A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/add_file_query.php. The manipulation of …

Dec 7, 2025
CVE-2025-14193
6.3 MEDIUM

A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file /view_personnel.php. Executing a manipulation of the …

Dec 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.