CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38713
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() The hfsplus_readdir() method is capable to crash by calling …

Sep 4, 2025
CVE-2025-38708
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflicts With `two-primaries` enabled, DRBD tries to detect "concurrent" writes …

Sep 4, 2025
CVE-2025-38707
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add sanity check for file name The length of the file name should be …

Sep 4, 2025
CVE-2025-38704
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access In the preparation stage of CPU online, if …

Sep 4, 2025
CVE-2025-38703
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Make dma-fences compliant with the safe access rules Xe can free some of the …

Sep 4, 2025
CVE-2025-38702
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fbdev: fix potential buffer overflow in do_register_framebuffer() The current implementation may lead to buffer overflow …

Sep 4, 2025
CVE-2025-38699
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Double-free fix When the bfad_im_probe() function fails during initialization, the memory pointed to …

Sep 4, 2025
CVE-2025-38697
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG When computing the tree index in …

Sep 4, 2025
CVE-2025-38688
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommufd: Prevent ALIGN() overflow When allocating IOVA the candidate range gets aligned to the target …

Sep 4, 2025
CVE-2025-38685
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imageblit This issue triggers when a userspace program does …

Sep 4, 2025
CVE-2025-38682
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: core: Fix double-free of fwnode in i2c_unregister_device() Before commit df6d7277e552 ("i2c: core: Do not …

Sep 4, 2025
CVE-2025-38680
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() The buffer length check before calling uvc_parse_format() …

Sep 4, 2025
CVE-2025-38679
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload bound check Currently, The event_seq_changed() handler …

Sep 4, 2025
CVE-2025-23258
7.3 HIGH

NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker with low privileges to escalate privileges. A successful …

Sep 4, 2025
CVE-2025-23257
7.3 HIGH

NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privileges to escalate privileges. A successful exploit of …

Sep 4, 2025
CVE-2025-23256
8.7 HIGH

NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful …

Sep 4, 2025
CVE-2025-57263
7.2 HIGH

An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in …

Sep 4, 2025
CVE-2025-7388
8.4 HIGH

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS …

Sep 4, 2025
CVE-2024-34598
7.7 HIGH

Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store.

Sep 4, 2025
CVE-2025-9938
8.8 HIGH

A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the file /yyxz.asp. This manipulation of the argument …

Sep 4, 2025
CVE-2025-9935
7.3 HIGH

A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi-bin/cstecgi.cgi. Executing manipulation can lead to command injection. …

Sep 4, 2025
CVE-2025-9933
7.3 HIGH

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such …

Sep 4, 2025
CVE-2025-9932
7.3 HIGH

A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This …

Sep 4, 2025
CVE-2025-9930
7.3 HIGH

A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulation of …

Sep 4, 2025
CVE-2025-9519
7.2 HIGH

The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 via the plugin's shortcodes. This …

Sep 4, 2025
CVE-2025-9518
7.2 HIGH

The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on the 'debug_path' parameter in all versions …

Sep 4, 2025
CVE-2025-9517
7.2 HIGH

The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This …

Sep 4, 2025
CVE-2025-6984
7.5 HIGH

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. …

Sep 4, 2025
CVE-2025-6085
7.2 HIGH

The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions …

Sep 4, 2025
CVE-2025-58358
7.5 HIGH

Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain a command injection vulnerability, caused by the unsanitized …

Sep 4, 2025
CVE-2025-58355
7.7 HIGH

Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled …

Sep 4, 2025
CVE-2025-58057
7.5 HIGH

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, …

Sep 4, 2025
CVE-2025-36907
7.3 HIGH

In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36906
7.8 HIGH

In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36905
7.8 HIGH

In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36903
7.8 HIGH

In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution …

Sep 4, 2025
CVE-2025-36901
8.8 HIGH

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.

Sep 4, 2025
CVE-2025-36899
8.4 HIGH

There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with …

Sep 4, 2025
CVE-2025-36898
7.8 HIGH

There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no …

Sep 4, 2025
CVE-2025-36895
7.5 HIGH

Information disclosure

Sep 4, 2025
CVE-2025-36894
7.5 HIGH

In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no …

Sep 4, 2025
CVE-2025-36892
7.5 HIGH

Denial of service

Sep 4, 2025
CVE-2025-36891
8.8 HIGH

Elevation of privilege

Sep 4, 2025
CVE-2025-36887
7.8 HIGH

In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-2417
8.6 HIGH

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication Bypass.This issue affects e-Mutabakat: from 2.02.06 before v2.02.06.

Sep 4, 2025
CVE-2025-2411
8.6 HIGH

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass.This issue affects TaskPano: from s1.06.04 before v1.06.06.

Sep 4, 2025
CVE-2024-56190
7.8 HIGH

In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Sep 4, 2025
CVE-2025-9928
7.3 HIGH

A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation …

Sep 3, 2025
CVE-2025-9927
7.3 HIGH

A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown function of the file /viewpackage.php. Such manipulation of the …

Sep 3, 2025
CVE-2025-58056
7.5 HIGH

Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, …

Sep 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.