CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-50515
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix memory leak in hpd_rx_irq_create_workqueue() If construction of the array of work queues to …

Oct 7, 2025
CVE-2022-50514
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: fix refcount leak on error path When failing to allocate report_desc, opts->refcnt …

Oct 7, 2025
CVE-2022-50513
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix a potential memory leak in rtw_init_cmd_priv() In rtw_init_cmd_priv(), if `pcmdpriv->rsp_allocated_buf` is allocated …

Oct 7, 2025
CVE-2022-50512
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix potential memory leak in ext4_fc_record_regions() As krealloc may return NULL, in this case …

Oct 7, 2025
CVE-2022-50511
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: lib/fonts: fix undefined behavior in bit shift for get_default_font Shifting signed 32-bit value by 31 …

Oct 7, 2025
CVE-2022-50510
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/smmuv3: Fix hotplug callback leak in arm_smmu_pmu_init() arm_smmu_pmu_init() won't remove the callback added by cpuhp_setup_state_multi() …

Oct 7, 2025
CVE-2022-50509
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: coda: Add check for kmalloc As the kmalloc may return NULL pointer, it should …

Oct 7, 2025
CVE-2025-11398
6.3 MEDIUM

A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unknown function of the file /profile.php of …

Oct 7, 2025
CVE-2025-53476
5.3 MEDIUM

A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A specially crafted series of network connections can lead to …

Oct 7, 2025
CVE-2025-37728
5.4 MEDIUM

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector …

Oct 7, 2025
CVE-2025-40888
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can …

Oct 7, 2025
CVE-2025-40887
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can …

Oct 7, 2025
CVE-2025-40885
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges …

Oct 7, 2025
CVE-2025-11390
4.3 MEDIUM

A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of …

Oct 7, 2025
CVE-2025-11360
4.3 MEDIUM

A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the file api/src/app.js of the component API. …

Oct 7, 2025
CVE-2025-11359
6.3 MEDIUM

A security vulnerability has been detected in code-projects Simple Banking System 1.0. The affected element is an unknown function of the file /transfermoney.php. The manipulation …

Oct 7, 2025
CVE-2025-10645
5.3 MEDIUM

The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when …

Oct 7, 2025
CVE-2025-7400
6.4 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featured Image custom fields in all versions …

Oct 7, 2025
CVE-2025-11358
6.3 MEDIUM

A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /removeuser.php. Executing manipulation of the argument …

Oct 7, 2025
CVE-2025-11357
6.3 MEDIUM

A security flaw has been discovered in code-projects Simple Banking System 1.0. This issue affects some unknown processing of the file /createuser.php. Performing manipulation of …

Oct 7, 2025
CVE-2025-11354
6.3 MEDIUM

A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/addslideexec.php. Executing manipulation of the …

Oct 7, 2025
CVE-2025-11353
6.3 MEDIUM

A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of the file /admin/addgalleryexec.php. Performing manipulation of the argument …

Oct 7, 2025
CVE-2025-11352
6.3 MEDIUM

A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown function of the file /admin/addexec.php. Such manipulation of …

Oct 7, 2025
CVE-2025-11351
6.3 MEDIUM

A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/editpicexec.php. This manipulation …

Oct 7, 2025
CVE-2025-43824
5.4 MEDIUM

The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through …

Oct 6, 2025
CVE-2025-59452
5.8 MEDIUM

The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret …

Oct 6, 2025
CVE-2025-59450
4.3 MEDIUM

The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.

Oct 6, 2025
CVE-2025-59449
4.9 MEDIUM

The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices …

Oct 6, 2025
CVE-2025-59448
4.7 MEDIUM

Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic …

Oct 6, 2025
CVE-2025-11346
6.3 MEDIUM

A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the …

Oct 6, 2025
CVE-2025-11345
5.5 MEDIUM

A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation …

Oct 6, 2025
CVE-2025-11344
6.3 MEDIUM

A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation …

Oct 6, 2025
CVE-2025-56382
6.1 MEDIUM

A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4.8. An authenticated attacker can inject arbitrary web script …

Oct 6, 2025
CVE-2025-28129
5.4 MEDIUM

Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.

Oct 6, 2025
CVE-2025-11342
4.7 MEDIUM

A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the file /admin/edit-course.php. Executing manipulation of the argument …

Oct 6, 2025
CVE-2025-61769
6.1 MEDIUM

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows authenticated remote attackers …

Oct 6, 2025
CVE-2025-61766
6.5 MEDIUM

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recursion can occur if a user queries …

Oct 6, 2025
CVE-2025-60969
5.7 MEDIUM

Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.

Oct 6, 2025
CVE-2025-60961
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and …

Oct 6, 2025
CVE-2025-0038
6.6 MEDIUM

In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or …

Oct 6, 2025
CVE-2025-61765
6.4 MEDIUM

python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers …

Oct 6, 2025
CVE-2025-61224
6.5 MEDIUM

Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter

Oct 6, 2025
CVE-2025-61198
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 …

Oct 6, 2025
CVE-2025-11337
5.3 MEDIUM

A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneReport/index.do/../../aloneReport/download.do;othersusrlogout.do. Performing manipulation of …

Oct 6, 2025
CVE-2025-11336
5.3 MEDIUM

A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown functionality of the …

Oct 6, 2025
CVE-2025-11335
4.7 MEDIUM

A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.htm?flag=qos of …

Oct 6, 2025
CVE-2025-11331
4.7 MEDIUM

A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the component Website Name …

Oct 6, 2025
CVE-2025-11330
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/sales-reports-detail.php. Such manipulation …

Oct 6, 2025
CVE-2025-0609
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Software Inc. Logo Cloud allows Cross-Site Scripting (XSS).This issue affects …

Oct 6, 2025
CVE-2025-0608
5.5 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forceful Browsing.This issue affects Logo Cloud: before 2025.R6.

Oct 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.