CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39865
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tee: fix NULL pointer dereference in tee_shm_put tee_shm_put have NULL pointer dereference: __optee_disable_shm_cache --> shm …

Sep 19, 2025
CVE-2025-39858
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eth: mlx4: Fix IS_ERR() vs NULL check bug in mlx4_en_create_rx_ring Replace NULL check with IS_ERR() …

Sep 19, 2025
CVE-2025-39857
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() BUG: kernel NULL pointer dereference, address: 00000000000002ec …

Sep 19, 2025
CVE-2025-39856
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix null pointer dereference for ndev In the TX completion packet …

Sep 19, 2025
CVE-2025-39852
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/tcp: Fix socket memory leak in TCP-AO failure handling for IPv6 When tcp_ao_copy_all_matching() fails in …

Sep 19, 2025
CVE-2025-39851
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix NPD when refreshing an FDB entry with a nexthop object VXLAN FDB entries …

Sep 19, 2025
CVE-2025-39850
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects When the "proxy" option is enabled …

Sep 19, 2025
CVE-2025-39848
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ax25: properly unshare skbs in ax25_kiss_rcv() Bernard Pidoux reported a regression apparently caused by commit …

Sep 19, 2025
CVE-2025-39847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ppp: fix memory leak in pad_compress_skb If alloc_skb() fails in pad_compress_skb(), it returns NULL without …

Sep 19, 2025
CVE-2025-39846
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() In __iodyn_find_io_region(), pcmcia_make_resource() is assigned to res …

Sep 19, 2025
CVE-2025-39845
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() Define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() to ensure page tables are properly …

Sep 19, 2025
CVE-2025-39844
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: move page table sync declarations to linux/pgtable.h During our internal testing, we started observing …

Sep 19, 2025
CVE-2025-39843
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: slub: avoid wake up kswapd in set_track_prepare set_track_prepare() can incur lock recursion. The issue …

Sep 19, 2025
CVE-2025-39842
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: prevent release journal inode after journal shutdown Before calling ocfs2_delete_osb(), ocfs2_journal_shutdown() has already been …

Sep 19, 2025
CVE-2025-39838
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL pointer dereference in UTF16 conversion There can be a NULL pointer dereference …

Sep 19, 2025
CVE-2025-10718
5.3 MEDIUM

A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The …

Sep 19, 2025
CVE-2025-8664
6.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management allows Cross-Site …

Sep 19, 2025
CVE-2025-8532
6.4 MEDIUM

Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing.This issue affects …

Sep 19, 2025
CVE-2025-10717
5.3 MEDIUM

A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of …

Sep 19, 2025
CVE-2025-10716
5.3 MEDIUM

A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file …

Sep 19, 2025
CVE-2025-58114
4.8 MEDIUM

Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension:CognitiveProcessDesigner) allows Cross-Site Scripting (XSS).This issue affects BlueSpice: from 5 through 5.1.1.

Sep 19, 2025
CVE-2025-57880
5.4 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

Sep 19, 2025
CVE-2025-48007
6.4 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

Sep 19, 2025
CVE-2025-46703
6.4 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

Sep 19, 2025
CVE-2025-10715
5.3 MEDIUM

A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an unknown function of …

Sep 19, 2025
CVE-2025-10711
4.3 MEDIUM

A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown code of the file /index.php/sysmanage/Login. Such manipulation of …

Sep 19, 2025
CVE-2025-10710
4.3 MEDIUM

A flaw has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This affects an unknown part of the file /index.php. This manipulation of …

Sep 19, 2025
CVE-2025-10709
5.3 MEDIUM

A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is some unknown functionality of the file /history/historyDownload.do;otheruserLogin.do;getfile. The manipulation …

Sep 19, 2025
CVE-2025-10708
5.3 MEDIUM

A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this vulnerability is an unknown functionality of the file /history/historyDownload.do;usrlogout.do. …

Sep 19, 2025
CVE-2025-10707
6.3 MEDIUM

A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper …

Sep 19, 2025
CVE-2025-8531
6.8 MEDIUM

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, Q06UDVCPU, Q13UDVCPU, Q26UDVCPU, Q04UDPVCPU, Q06UDPVCPU, Q13UDPVCPU, and Q26UDPVCPU with the …

Sep 19, 2025
CVE-2025-10719
4.3 MEDIUM

Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers with regular privilege to modify a specific parameter to access other …

Sep 19, 2025
CVE-2025-10630
4.3 MEDIUM

Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards …

Sep 19, 2025
CVE-2025-7702
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust …

Sep 19, 2025
CVE-2025-10457
4.3 MEDIUM

The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. …

Sep 19, 2025
CVE-2025-10146
6.1 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due …

Sep 19, 2025
CVE-2025-8487
5.4 MEDIUM

The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action …

Sep 19, 2025
CVE-2025-59717
5.4 MEDIUM

In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead …

Sep 19, 2025
CVE-2025-59715
4.8 MEDIUM

SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.

Sep 19, 2025
CVE-2025-59714
6.5 MEDIUM

In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.

Sep 19, 2025
CVE-2025-59713
6.8 MEDIUM

Snipe-IT before 8.1.18 allows unsafe deserialization.

Sep 19, 2025
CVE-2025-59712
6.4 MEDIUM

Snipe-IT before 8.1.18 allows XSS.

Sep 19, 2025
CVE-2025-30755
6.1 MEDIUM

OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens through improper handling of the revision parameter. The …

Sep 19, 2025
CVE-2025-10689
6.3 MEDIUM

A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads …

Sep 18, 2025
CVE-2025-47906
6.5 MEDIUM

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result …

Sep 18, 2025
CVE-2025-26503
6.7 MEDIUM

A crafted system call argument can cause memory corruption.

Sep 18, 2025
CVE-2025-36146
4.3 MEDIUM

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in further attacks against the system.

Sep 18, 2025
CVE-2025-36143
4.7 MEDIUM

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input.

Sep 18, 2025
CVE-2025-36139
5.5 MEDIUM

IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI …

Sep 18, 2025
CVE-2025-10676
4.3 MEDIUM

A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /brand/queryAll. Executing manipulation can lead to improper authorization. …

Sep 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.