CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-57326
7.5 HIGH

A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, …

Sep 24, 2025
CVE-2025-57325
7.5 HIGH

rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes advanced error tracking features and an intuitive interface …

Sep 24, 2025
CVE-2025-57323
7.5 HIGH

mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vulnerability in the mp.addEventHandler function of mpregular version …

Sep 24, 2025
CVE-2025-59251
7.6 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 24, 2025
CVE-2025-57349
7.5 HIGH

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key …

Sep 24, 2025
CVE-2025-57330
7.5 HIGH

The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows …

Sep 24, 2025
CVE-2025-55322
7.3 HIGH

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.

Sep 24, 2025
CVE-2025-59305
7.6 HIGH

Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to …

Sep 24, 2025
CVE-2025-57350
8.6 HIGH

The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10. …

Sep 24, 2025
CVE-2025-56241
7.5 HIGH

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows …

Sep 24, 2025
CVE-2025-52907
8.8 HIGH

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Sep 24, 2025
CVE-2025-48869
7.5 HIGH

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing …

Sep 24, 2025
CVE-2025-20352
7.7 HIGH KEV

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, …

Sep 24, 2025
CVE-2025-20327
7.7 HIGH

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service …

Sep 24, 2025
CVE-2025-20315
8.6 HIGH

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device …

Sep 24, 2025
CVE-2025-20312
7.7 HIGH

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial …

Sep 24, 2025
CVE-2025-20311
7.4 HIGH

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker …

Sep 24, 2025
CVE-2025-20160
8.1 HIGH

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to …

Sep 24, 2025
CVE-2025-56816
8.8 HIGH

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to the config/jdbc-driver-ext.yml path. …

Sep 24, 2025
CVE-2025-56815
7.1 HIGH

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to save the uploaded file to a …

Sep 24, 2025
CVE-2025-20334
8.8 HIGH

A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root …

Sep 24, 2025
CVE-2025-10892
8.8 HIGH

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10891
8.8 HIGH

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10502
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium …

Sep 24, 2025
CVE-2025-10501
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 24, 2025
CVE-2025-10500
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 24, 2025
CVE-2025-47329
7.8 HIGH

Memory corruption while handling invalid inputs in application info setup.

Sep 24, 2025
CVE-2025-47328
7.5 HIGH

Transient DOS while processing power control requests with invalid antenna or stream values.

Sep 24, 2025
CVE-2025-47327
7.8 HIGH

Memory corruption while encoding the image data.

Sep 24, 2025
CVE-2025-47326
7.5 HIGH

Transient DOS while handling command data during power control processing.

Sep 24, 2025
CVE-2025-47318
7.5 HIGH

Transient DOS while parsing the EPTM test control message to get the test pattern.

Sep 24, 2025
CVE-2025-47317
7.8 HIGH

Memory corruption due to global buffer overflow when a test command uses an invalid payload type.

Sep 24, 2025
CVE-2025-47316
7.8 HIGH

Memory corruption due to double free when multiple threads race to set the timestamp store.

Sep 24, 2025
CVE-2025-47315
7.8 HIGH

Memory corruption while handling repeated memory unmap requests from guest VM.

Sep 24, 2025
CVE-2025-47314
7.8 HIGH

Memory corruption while processing data sent by FE driver.

Sep 24, 2025
CVE-2025-27077
7.8 HIGH

Memory corruption while processing message in guest VM.

Sep 24, 2025
CVE-2025-27037
7.8 HIGH

Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.

Sep 24, 2025
CVE-2025-27032
7.8 HIGH

memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.

Sep 24, 2025
CVE-2025-21488
8.2 HIGH

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.

Sep 24, 2025
CVE-2025-21487
8.2 HIGH

Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.

Sep 24, 2025
CVE-2025-21484
8.2 HIGH

Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.

Sep 24, 2025
CVE-2025-21482
7.1 HIGH

Cryptographic issue while performing RSA PKCS padding decoding.

Sep 24, 2025
CVE-2025-21481
7.8 HIGH

Memory corruption while performing private key encryption in trusted application.

Sep 24, 2025
CVE-2025-21476
7.8 HIGH

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

Sep 24, 2025
CVE-2025-48868
7.2 HIGH

Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to …

Sep 24, 2025
CVE-2025-23354
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful …

Sep 24, 2025
CVE-2025-23353
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A …

Sep 24, 2025
CVE-2025-23349
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this …

Sep 24, 2025
CVE-2025-23348
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. …

Sep 24, 2025
CVE-2025-10906
8.4 HIGH

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the …

Sep 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.