CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39757
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified …

Sep 11, 2025
CVE-2025-39750
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Correct tid cleanup when tid setup fails Currently, if any error occurs during …

Sep 11, 2025
CVE-2025-39749
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: rcu: Protect ->defer_qs_iw_pending from data race On kernels built with CONFIG_IRQ_WORK=y, when rcu_read_unlock() is invoked …

Sep 11, 2025
CVE-2025-39744
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: rcu: Fix rcu_read_unlock() deadloop due to IRQ work During rcu_read_unlock_special(), if this happens during irq_exit(), …

Sep 11, 2025
CVE-2025-39743
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 The fileset value of the …

Sep 11, 2025
CVE-2025-39740
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: prevent potential UAF If we hit the error path, the previous fence (if there …

Sep 11, 2025
CVE-2025-39738
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped subvolumes [BUG] There is an internal report …

Sep 11, 2025
CVE-2025-58145
7.5 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping …

Sep 11, 2025
CVE-2025-58144
7.5 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping …

Sep 11, 2025
CVE-2025-9018
8.8 HIGH

The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update_table_function' and …

Sep 11, 2025
CVE-2025-58320
7.3 HIGH

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Sep 11, 2025
CVE-2025-9874
7.5 HIGH

The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6 via the 'uclwp_dashboard' shortcode. …

Sep 11, 2025
CVE-2025-9693
8.0 HIGH

The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path …

Sep 11, 2025
CVE-2025-9073
7.5 HIGH

The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 3.2 …

Sep 11, 2025
CVE-2025-8425
8.8 HIGH

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability …

Sep 11, 2025
CVE-2025-8422
7.5 HIGH

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the …

Sep 11, 2025
CVE-2025-8417
8.1 HIGH

The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is …

Sep 11, 2025
CVE-2025-54376
7.5 HIGH

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication …

Sep 10, 2025
CVE-2025-59049
7.5 HIGH

Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach …

Sep 10, 2025
CVE-2025-10201
8.8 HIGH

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted …

Sep 10, 2025
CVE-2025-10200
8.8 HIGH

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Sep 10, 2025
CVE-2025-8696
7.5 HIGH

If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for the system …

Sep 10, 2025
CVE-2025-57392
7.8 HIGH

BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone and BUILTIN\Users groups FILE_ALL_ACCESS, allowing local users to replace or …

Sep 10, 2025
CVE-2025-55976
8.4 HIGH

Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the …

Sep 10, 2025
CVE-2025-50892
7.8 HIGH

The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges for I/O requests (IRP_MJ_READ/IRP_MJ_WRITE) sent to its device object. …

Sep 10, 2025
CVE-2025-57642
7.2 HIGH

A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to …

Sep 10, 2025
CVE-2025-43888
8.8 HIGH

Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local …

Sep 10, 2025
CVE-2025-43887
7.0 HIGH

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit …

Sep 10, 2025
CVE-2025-43885
7.8 HIGH

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. …

Sep 10, 2025
CVE-2025-43884
8.2 HIGH

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. …

Sep 10, 2025
CVE-2025-43725
7.8 HIGH

Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could …

Sep 10, 2025
CVE-2025-20340
7.4 HIGH

A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a broadcast storm, …

Sep 10, 2025
CVE-2025-56466
7.5 HIGH

Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.

Sep 10, 2025
CVE-2025-56413
8.8 HIGH

OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/ssh/operate endpoint.

Sep 10, 2025
CVE-2025-56407
8.8 HIGH

A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.php. The manipulation …

Sep 10, 2025
CVE-2025-56406
7.5 HIGH

An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position …

Sep 10, 2025
CVE-2025-56405
7.5 HIGH

An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol.

Sep 10, 2025
CVE-2025-56404
7.5 HIGH

An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.

Sep 10, 2025
CVE-2025-10231
7.0 HIGH

An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user …

Sep 10, 2025
CVE-2025-7718
8.8 HIGH

The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up …

Sep 10, 2025
CVE-2025-10225
7.5 HIGH

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier …

Sep 10, 2025
CVE-2025-10215
7.8 HIGH

DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a …

Sep 10, 2025
CVE-2025-10214
7.8 HIGH

DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a …

Sep 10, 2025
CVE-2025-10213
7.8 HIGH

DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a …

Sep 10, 2025
CVE-2025-7049
8.8 HIGH

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the …

Sep 10, 2025
CVE-2025-41714
8.8 HIGH

The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to create upload-related artifacts …

Sep 10, 2025
CVE-2025-10049
7.2 HIGH

The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the HdnMediaSelection_image field in all …

Sep 10, 2025
CVE-2025-10040
7.7 HIGH

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability …

Sep 10, 2025
CVE-2025-10001
7.2 HIGH

The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Sep 10, 2025
CVE-2025-58750
8.2 HIGH

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0cc348b are missing a bound check in `chclif_parse_moveCharSlot` …

Sep 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.