CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22428
7.8 HIGH

In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to …

Sep 2, 2025
CVE-2025-22427
7.3 HIGH

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic error in the code. …

Sep 2, 2025
CVE-2025-22423
7.5 HIGH

In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote …

Sep 2, 2025
CVE-2025-22422
7.8 HIGH

In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be …

Sep 2, 2025
CVE-2025-22419
7.3 HIGH

In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack. This could …

Sep 2, 2025
CVE-2025-22418
7.8 HIGH

In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution …

Sep 2, 2025
CVE-2025-22417
7.3 HIGH

In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. This could lead to local escalation …

Sep 2, 2025
CVE-2025-22416
7.8 HIGH

In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This could lead to local …

Sep 2, 2025
CVE-2024-49730
7.8 HIGH

In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional …

Sep 2, 2025
CVE-2024-49720
7.8 HIGH

In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic error in …

Sep 2, 2025
CVE-2024-40653
7.3 HIGH

In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error in the …

Sep 2, 2025
CVE-2025-9837
7.3 HIGH

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the …

Sep 2, 2025
CVE-2025-9833
7.3 HIGH

A vulnerability was detected in SourceCodester Online Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/login.php. Performing manipulation …

Sep 2, 2025
CVE-2025-9832
7.3 HIGH

A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file /routers/register-router.php. Such manipulation of …

Sep 2, 2025
CVE-2025-9831
7.3 HIGH

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the …

Sep 2, 2025
CVE-2025-9330
7.8 HIGH

Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of …

Sep 2, 2025
CVE-2025-9329
7.8 HIGH

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Sep 2, 2025
CVE-2025-9328
7.8 HIGH

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Sep 2, 2025
CVE-2025-9326
7.8 HIGH

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Sep 2, 2025
CVE-2025-9830
7.3 HIGH

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/add-customer-services.php. The manipulation of …

Sep 2, 2025
CVE-2025-9275
7.8 HIGH

Oxford Instruments Imaris Viewer IMS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Sep 2, 2025
CVE-2025-9274
7.8 HIGH

Oxford Instruments Imaris Viewer IMS File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Sep 2, 2025
CVE-2025-8614
7.8 HIGH

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must …

Sep 2, 2025
CVE-2025-8613
7.2 HIGH

Vacron Camera ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vacron Camera devices. …

Sep 2, 2025
CVE-2025-8302
8.8 HIGH

Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of …

Sep 2, 2025
CVE-2025-8301
7.8 HIGH

Realtek RTL8811AU rtwlanu.sys N6CSet_DOT11_CIPHER_DEFAULT_KEY Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Realtek RTL8811AU …

Sep 2, 2025
CVE-2025-8300
8.8 HIGH

Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of …

Sep 2, 2025
CVE-2025-8299
8.8 HIGH

Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of …

Sep 2, 2025
CVE-2025-7976
7.8 HIGH

Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Sep 2, 2025
CVE-2025-7975
7.8 HIGH

Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Anritsu …

Sep 2, 2025
CVE-2025-7974
7.5 HIGH

rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of rocket.chat. Authentication is not required to …

Sep 2, 2025
CVE-2025-6685
8.8 HIGH

ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of ATEN eco DC. Authentication is …

Sep 2, 2025
CVE-2025-9829
7.3 HIGH

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /signup.php. The manipulation of …

Sep 2, 2025
CVE-2025-9189
7.8 HIGH

There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with …

Sep 2, 2025
CVE-2025-9188
7.8 HIGH

There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to …

Sep 2, 2025
CVE-2025-57778
7.8 HIGH

There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid source address when parsing a DSB file with …

Sep 2, 2025
CVE-2025-57777
7.8 HIGH

There is an out of bounds write vulnerability due to improper bounds checking in displ2.dll when parsing a DSB file with Digilent DASYLab. This vulnerability …

Sep 2, 2025
CVE-2025-57776
7.8 HIGH

There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid address when parsing a DSB file with Digilent …

Sep 2, 2025
CVE-2025-57775
7.8 HIGH

There is a heap-based Buffer Overflow vulnerability due to improper bounds checking when parsing a DSB file with Digilent DASYLab. This vulnerability may result in …

Sep 2, 2025
CVE-2025-57774
7.8 HIGH

There is an out of bounds write vulnerability due to improper bounds checking resulting in invalid data when parsing a DSB file with Digilent DASYLab. …

Sep 2, 2025
CVE-2025-57616
7.5 HIGH

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleaved method allows an attacker to cause a denial of …

Sep 2, 2025
CVE-2025-57615
7.5 HIGH

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new constructor function allows an attacker to cause a …

Sep 2, 2025
CVE-2025-57614
7.5 HIGH

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allows an attacker to cause …

Sep 2, 2025
CVE-2025-57613
7.5 HIGH

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input() constructor function allows an attacker to cause …

Sep 2, 2025
CVE-2025-57612
7.5 HIGH

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() method allows an attacker to cause a denial …

Sep 2, 2025
CVE-2025-54599
7.5 HIGH

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim …

Sep 2, 2025
CVE-2025-9784
7.5 HIGH

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the …

Sep 2, 2025
CVE-2025-2413
8.6 HIGH

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypass.This issue affects ProKuafor: from s1.02.08 before v1.02.08.

Sep 2, 2025
CVE-2025-52550
7.2 HIGH

E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin …

Sep 2, 2025
CVE-2025-52547
7.5 HIGH

E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously …

Sep 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.