CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13353
5.5 MEDIUM

In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and the AES-GCM …

Dec 2, 2025
CVE-2025-13873
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which …

Dec 2, 2025
CVE-2025-13534
6.3 MEDIUM

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This …

Dec 2, 2025
CVE-2025-10543
5.3 MEDIUM

In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds …

Dec 2, 2025
CVE-2025-13696
5.3 MEDIUM

The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin exposing …

Dec 2, 2025
CVE-2025-11726
4.3 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is …

Dec 2, 2025
CVE-2025-13685
4.3 MEDIUM

The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due …

Dec 2, 2025
CVE-2025-13140
4.3 MEDIUM

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. …

Dec 2, 2025
CVE-2025-13007
6.1 MEDIUM

The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up …

Dec 2, 2025
CVE-2025-12483
6.5 MEDIUM

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'query' parameter in all versions up to, …

Dec 2, 2025
CVE-2025-13001
4.1 MEDIUM

The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such …

Dec 2, 2025
CVE-2025-13606
6.5 MEDIUM

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 2, 2025
CVE-2025-20792
5.3 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20791
6.5 MEDIUM

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20790
5.3 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20789
4.4 MEDIUM

In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional …

Dec 2, 2025
CVE-2025-20788
4.4 MEDIUM

In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of service with no …

Dec 2, 2025
CVE-2025-20777
6.7 MEDIUM

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Dec 2, 2025
CVE-2025-20776
6.7 MEDIUM

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if …

Dec 2, 2025
CVE-2025-20775
6.7 MEDIUM

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Dec 2, 2025
CVE-2025-20774
6.7 MEDIUM

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Dec 2, 2025
CVE-2025-20773
6.7 MEDIUM

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Dec 2, 2025
CVE-2025-20772
6.7 MEDIUM

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Dec 2, 2025
CVE-2025-20771
6.7 MEDIUM

In display, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious …

Dec 2, 2025
CVE-2025-20770
6.7 MEDIUM

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Dec 2, 2025
CVE-2025-20769
6.7 MEDIUM

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Dec 2, 2025
CVE-2025-20765
4.7 MEDIUM

In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious …

Dec 2, 2025
CVE-2025-20759
6.5 MEDIUM

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if …

Dec 2, 2025
CVE-2025-20758
4.9 MEDIUM

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20757
6.5 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20756
6.5 MEDIUM

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20755
5.3 MEDIUM

In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20754
5.3 MEDIUM

In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service, if a UE …

Dec 2, 2025
CVE-2025-20753
5.3 MEDIUM

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20752
6.5 MEDIUM

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE …

Dec 2, 2025
CVE-2025-20751
6.5 MEDIUM

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE …

Dec 2, 2025
CVE-2025-20750
6.5 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-13697
6.4 MEDIUM

The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Dec 2, 2025
CVE-2025-58488
4.5 MEDIUM

Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote attackers to access sensitive information. User interaction is required …

Dec 2, 2025
CVE-2025-58487
4.0 MEDIUM

Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.

Dec 2, 2025
CVE-2025-58486
4.0 MEDIUM

Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.

Dec 2, 2025
CVE-2025-58485
5.5 MEDIUM

Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script.

Dec 2, 2025
CVE-2025-58484
4.0 MEDIUM

Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access partial data in sandbox.

Dec 2, 2025
CVE-2025-58483
5.9 MEDIUM

Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy …

Dec 2, 2025
CVE-2025-58480
4.3 MEDIUM

Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58479
4.3 MEDIUM

Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58478
4.3 MEDIUM

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58477
4.3 MEDIUM

Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58476
4.2 MEDIUM

Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58475
5.6 MEDIUM

Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Dec 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.