CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36326
8.4 HIGH

Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a standby state, potentially resulting in a loss …

Sep 6, 2025
CVE-2024-21947
7.5 HIGH

Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in arbitrary code execution at …

Sep 6, 2025
CVE-2023-31325
7.2 HIGH

Improper isolation of shared resources on System-on-a-chip (SOC) could a privileged attacker to tamper with the contents of the PSP reserved DRAM region potentially resulting …

Sep 6, 2025
CVE-2023-31322
8.7 HIGH

Type confusion in the ASP could allow an attacker to pass a malformed argument to the Reliability, Availability, and Serviceability trusted application (RAS TA) potentially …

Sep 6, 2025
CVE-2025-10034
8.8 HIGH

A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_response.cg of the component httpd. Performing manipulation of the …

Sep 6, 2025
CVE-2025-10033
7.3 HIGH

A vulnerability has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin. Such manipulation of the argument …

Sep 6, 2025
CVE-2025-10031
7.3 HIGH

A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. The manipulation …

Sep 6, 2025
CVE-2025-10030
7.3 HIGH

A weakness has been identified in Campcodes Grocery Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=save_receiving. Executing manipulation …

Sep 6, 2025
CVE-2025-7040
8.2 HIGH

The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings' action of …

Sep 6, 2025
CVE-2025-9515
7.2 HIGH

The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all …

Sep 6, 2025
CVE-2025-58437
8.1 HIGH

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session …

Sep 6, 2025
CVE-2025-58374
7.8 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that …

Sep 6, 2025
CVE-2025-7366
7.3 HIGH

The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Sep 6, 2025
CVE-2025-58439
8.1 HIGH

ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left …

Sep 6, 2025
CVE-2021-26383
7.9 HIGH

Insufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a command with malformed arguments leading …

Sep 6, 2025
CVE-2025-58372
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace …

Sep 5, 2025
CVE-2025-58370
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where …

Sep 5, 2025
CVE-2025-9566
8.1 HIGH

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete …

Sep 5, 2025
CVE-2025-10025
7.3 HIGH

A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument …

Sep 5, 2025
CVE-2025-39723
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix unbuffered write error handling If all the subrequests in an unbuffered write stream …

Sep 5, 2025
CVE-2025-39719
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: imu: bno055: fix OOB access of hw_xlate array Fix a potential out-of-bounds array access …

Sep 5, 2025
CVE-2025-39717
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: open_tree_attr: do not allow id-mapping changes without OPEN_TREE_CLONE As described in commit 7a54947e727b ('Merge patch …

Sep 5, 2025
CVE-2025-39711
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls Both the ACE and …

Sep 5, 2025
CVE-2025-39710
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: venus: Add a check for packet size after reading from shared memory Add a …

Sep 5, 2025
CVE-2025-39702
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to …

Sep 5, 2025
CVE-2025-39701
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version check The security-version-number check should be used rather …

Sep 5, 2025
CVE-2025-39691
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() helper There's issue as follows: BUG: KASAN: stack-out-of-bounds in …

Sep 5, 2025
CVE-2025-39689
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ftrace: Also allocate and copy hash for reading of filter files Currently the reader of …

Sep 5, 2025
CVE-2025-39687
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: light: as73211: Ensure buffer holes are zeroed Given that the buffer is copied to …

Sep 5, 2025
CVE-2025-39686
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: Make insn_rw_emulate_bits() do insn->n samples The `insn_rw_emulate_bits()` function is used as a default handler …

Sep 5, 2025
CVE-2025-39685
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: pcl726: Prevent invalid irq number The reproducer passed in an irq number(0x80008000) that was …

Sep 5, 2025
CVE-2025-39683
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: tracing: Limit access to parser->buffer when trace_get_user failed When the length of the string written …

Sep 5, 2025
CVE-2025-39682
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either …

Sep 5, 2025
CVE-2025-39680
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: Fix out-of-bounds bug in rtl9300_i2c_smbus_xfer The data->block[0] variable comes from user. Without proper …

Sep 5, 2025
CVE-2025-38736
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization Syzbot reported shift-out-of-bounds exception …

Sep 5, 2025
CVE-2025-38734
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() BPF CI testing report a UAF issue: [ …

Sep 5, 2025
CVE-2025-38731
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix vm_bind_ioctl double free bug If the argument check during an array bind fails, …

Sep 5, 2025
CVE-2025-30199
7.2 HIGH

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot …

Sep 5, 2025
CVE-2025-58214
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri indutri allows PHP Local File Inclusion.This issue …

Sep 5, 2025
CVE-2025-58206
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach maxcoach allows PHP Local File Inclusion.This issue …

Sep 5, 2025
CVE-2025-57889
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery inpost-gallery allows PHP Local File Inclusion.This …

Sep 5, 2025
CVE-2025-53307
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from …

Sep 5, 2025
CVE-2025-48317
7.5 HIGH

Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay allows Path Traversal.This issue affects WooCommerce Payment Gateway for Saferpay: from n/a …

Sep 5, 2025
CVE-2025-48104
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player allows Stored XSS.This issue affects Floating Window Music Player: from n/a through <= …

Sep 5, 2025
CVE-2025-32320
7.8 HIGH

In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of …

Sep 5, 2025
CVE-2025-32318
8.8 HIGH

In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with …

Sep 5, 2025
CVE-2025-58780
7.2 HIGH

index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately …

Sep 5, 2025
CVE-2025-58881
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery new-simple-gallery allows Blind SQL Injection.This issue affects …

Sep 5, 2025
CVE-2025-58861
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS.This issue affects Quick Event Calendar: from n/a through <= 1.4.9.

Sep 5, 2025
CVE-2025-58860
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in KaizenCoders Enable Latex enable-latex allows Stored XSS.This issue affects Enable Latex: from n/a through <= 1.2.16.

Sep 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.