CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix linked list corruption Never leave scheduled wcid entries on the temporary on-stack …

Oct 1, 2025
CVE-2025-39916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: avoid divide-by-zero in damon_reclaim_apply_parameters() When creating a new scheme of DAMON_RECLAIM, the calculation of …

Oct 1, 2025
CVE-2025-39915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: transfer phy_config_inband() locking responsibility to phylink Problem description =================== Lockdep reports a possible …

Oct 1, 2025
CVE-2025-39914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Silence warning when chunk allocation fails in trace_pid_write Syzkaller trigger a fault injection warning: …

Oct 1, 2025
CVE-2025-39912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfs/localio: restore creds before releasing pageio data Otherwise if the nfsd filecache code releases the …

Oct 1, 2025
CVE-2025-39910
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc() kasan_populate_vmalloc() and its helpers ignore the caller's gfp_mask …

Oct 1, 2025
CVE-2025-39909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: avoid divide-by-zero in damon_lru_sort_apply_parameters() Patch series "mm/damon: avoid divide-by-zero in DAMON module's parameters application". …

Oct 1, 2025
CVE-2025-39908
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: dev_ioctl: take ops lock in hwtstamp lower paths ndo hwtstamp callbacks are expected to …

Oct 1, 2025
CVE-2025-39907
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer Avoid below overlapping mappings by using …

Oct 1, 2025
CVE-2025-39906
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: remove oem i2c adapter on finish Fixes a bug where unbinding of the GPU …

Oct 1, 2025
CVE-2025-39904
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: kexec: initialize kexec_buf struct in load_other_segments() Patch series "kexec: Fix invalid field access". The …

Oct 1, 2025
CVE-2025-39903
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: of_numa: fix uninitialized memory nodes causing kernel panic When there are memory-only nodes (nodes without …

Oct 1, 2025
CVE-2025-39902
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err() object_err() reports details of an …

Oct 1, 2025
CVE-2025-39900
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y syzbot reported a WARNING in est_timer() [1] Problem here …

Oct 1, 2025
CVE-2025-39899
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: fix kmap_local LIFO ordering for CONFIG_HIGHPTE With CONFIG_HIGHPTE on 32-bit ARM, move_pages_pte() maps PTE …

Oct 1, 2025
CVE-2025-39897
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX metadata pointer retrieval Add proper error checking …

Oct 1, 2025
CVE-2025-39895
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched: Fix sched_numa_find_nth_cpu() if mask offline sched_numa_find_nth_cpu() uses a bsearch to look for the 'closest' …

Oct 1, 2025
CVE-2025-39894
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast …

Oct 1, 2025
CVE-2025-39893
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: unregister ECC engine on probe error and device remove The on-host hardware ECC …

Oct 1, 2025
CVE-2025-39892
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: care NULL dirver name on snd_soc_lookup_component_nolocked() soc-generic-dmaengine-pcm.c uses same dev for both CPU …

Oct 1, 2025
CVE-2025-9512
6.1 MEDIUM

The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modifications, making it possible for …

Oct 1, 2025
CVE-2025-9075
6.4 MEDIUM

The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due …

Oct 1, 2025
CVE-2025-10744
5.9 MEDIUM

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Oct 1, 2025
CVE-2025-10735
4.0 MEDIUM

The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and …

Oct 1, 2025
CVE-2025-61792
6.4 MEDIUM

Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Question Mark button, the Help Button, …

Sep 30, 2025
CVE-2025-55191
6.5 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain …

Sep 30, 2025
CVE-2025-43826
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, …

Sep 30, 2025
CVE-2025-36262
4.9 MEDIUM

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access …

Sep 30, 2025
CVE-2025-36132
5.4 MEDIUM

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Sep 30, 2025
CVE-2025-43827
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, …

Sep 30, 2025
CVE-2025-57254
6.5 MEDIUM

An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allows remote attackers to execute arbitrary SQL queries via the …

Sep 30, 2025
CVE-2025-56200
6.1 MEDIUM

A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use …

Sep 30, 2025
CVE-2025-23292
4.6 MEDIUM

NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Attacker may cause an authorized action. A successful exploit of …

Sep 30, 2025
CVE-2025-56520
5.3 MEDIUM

Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720.

Sep 30, 2025
CVE-2025-56207
6.5 MEDIUM

A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Ethereum ERC721 Non-Fungible Token (NFT) project, allows …

Sep 30, 2025
CVE-2025-56676
5.4 MEDIUM

TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary password or reset token issued to one user can be …

Sep 30, 2025
CVE-2025-56018
6.1 MEDIUM

SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category Management via the category name field.

Sep 30, 2025
CVE-2025-55797
6.5 MEDIUM

An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is …

Sep 30, 2025
CVE-2025-54477
5.3 MEDIUM

Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.

Sep 30, 2025
CVE-2025-57852
6.4 MEDIUM

A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/passwd file being created with group-writable permissions during …

Sep 30, 2025
CVE-2025-28016
4.8 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows …

Sep 30, 2025
CVE-2025-9232
5.9 MEDIUM

Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the …

Sep 30, 2025
CVE-2025-9231
6.5 MEDIUM

Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM …

Sep 30, 2025
CVE-2025-52050
6.5 MEDIUM

In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by …

Sep 30, 2025
CVE-2025-52049
6.5 MEDIUM

In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by …

Sep 30, 2025
CVE-2025-52047
6.5 MEDIUM

In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by …

Sep 30, 2025
CVE-2025-52043
6.5 MEDIUM

In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which allows an attacker to extract all information from databases by …

Sep 30, 2025
CVE-2025-10859
4.0 MEDIUM

Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after …

Sep 30, 2025
CVE-2025-9948
4.3 MEDIUM

The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to …

Sep 30, 2025
CVE-2025-9946
6.1 MEDIUM

The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is …

Sep 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.