CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39795
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors check in blk_stack_limits() In blk_stack_limits(), we check that the …

Sep 12, 2025
CVE-2025-39794
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: tegra: Use I/O memcpy to write to IRAM Kasan crashes the kernel trying to …

Sep 12, 2025
CVE-2025-39792
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm: Always split write BIOs to zoned device limits Any zoned DM target that requires …

Sep 12, 2025
CVE-2025-55996
6.3 MEDIUM

Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface

Sep 12, 2025
CVE-2025-10319
4.3 MEDIUM

A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the …

Sep 12, 2025
CVE-2025-59139
5.3 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could …

Sep 12, 2025
CVE-2025-59058
5.9 MEDIUM

httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signature comparison is not timing-safe. This makes …

Sep 12, 2025
CVE-2025-10318
6.3 MEDIUM

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket …

Sep 12, 2025
CVE-2025-10267
5.3 MEDIUM

NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass …

Sep 12, 2025
CVE-2025-8280
5.8 MEDIUM

The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead …

Sep 12, 2025
CVE-2025-7337
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-6769
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-58781
4.8 MEDIUM

WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.

Sep 12, 2025
CVE-2025-1250
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-10291
6.3 MEDIUM

A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. Executing manipulation of the argument …

Sep 12, 2025
CVE-2025-10148
5.3 MEDIUM

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed …

Sep 12, 2025
CVE-2025-10288
5.3 MEDIUM

A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the file /user/info/list. Performing manipulation results in …

Sep 12, 2025
CVE-2025-10094
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have …

Sep 12, 2025
CVE-2025-9881
6.1 MEDIUM

The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing …

Sep 12, 2025
CVE-2025-9880
6.1 MEDIUM

The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due …

Sep 12, 2025
CVE-2025-9879
6.4 MEDIUM

The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' shortcode in all versions up to, and including, …

Sep 12, 2025
CVE-2025-9877
6.4 MEDIUM

The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' shortcode in all versions up to, and including, …

Sep 12, 2025
CVE-2025-10278
6.3 MEDIUM

A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument …

Sep 12, 2025
CVE-2025-43789
5.3 MEDIUM

JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered …

Sep 12, 2025
CVE-2025-43788
4.3 MEDIUM

The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check …

Sep 12, 2025
CVE-2025-10277
6.3 MEDIUM

A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file /crm/receivable/submit. The manipulation of the argument …

Sep 12, 2025
CVE-2025-10276
6.3 MEDIUM

A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the …

Sep 12, 2025
CVE-2025-10275
6.3 MEDIUM

A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipulation of the argument …

Sep 12, 2025
CVE-2025-10274
4.3 MEDIUM

A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the file /trial/mvc/item. Performing manipulation of …

Sep 12, 2025
CVE-2025-10272
4.3 MEDIUM

A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. This manipulation of the argument Name causes cross …

Sep 11, 2025
CVE-2025-10271
4.3 MEDIUM

A vulnerability was found in erjinzhi 10OA 1.0. This impacts an unknown function of the file /trial/mvc/finder. The manipulation of the argument Name results in …

Sep 11, 2025
CVE-2025-9214
5.4 MEDIUM

A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via …

Sep 11, 2025
CVE-2025-59055
4.7 MEDIUM

InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability in InstantCMS up to and including 2.17.3 allows …

Sep 11, 2025
CVE-2025-58364
6.5 MEDIUM

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation …

Sep 11, 2025
CVE-2025-58065
6.5 MEDIUM

Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication methods, the password …

Sep 11, 2025
CVE-2025-43782
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.7, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through …

Sep 11, 2025
CVE-2025-40300
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that exploits insufficient branch predictor isolation …

Sep 11, 2025
CVE-2025-39791
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm: dm-crypt: Do not partially accept write BIOs with zoned targets Read and write operations …

Sep 11, 2025
CVE-2025-39789
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: x86/aegis - Add missing error checks The skcipher_walk functions can allocate memory and can …

Sep 11, 2025
CVE-2025-39787
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: mdt_loader: Ensure we don't read past the ELF header When the MDT loader …

Sep 11, 2025
CVE-2025-39785
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/hisilicon/hibmc: fix irq_request()'s irq name variable is local The local variable is passed in request_irq …

Sep 11, 2025
CVE-2025-39784
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: Fix link speed calculation on retrain failure When pcie_failed_link_retrain() fails to retrain, it tries …

Sep 11, 2025
CVE-2025-39782
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jbd2: prevent softlockup in jbd2_log_do_checkpoint() Both jbd2_log_do_checkpoint() and jbd2_journal_shrink_checkpoint_list() periodically release j_list_lock after processing a …

Sep 11, 2025
CVE-2025-39781
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: Drop WARN_ON_ONCE() from flush_cache_vmap I have observed warning to occassionally trigger.

Sep 11, 2025
CVE-2025-39780
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/ext: Fix invalid task state transitions on class switch When enabling a sched_ext scheduler, we …

Sep 11, 2025
CVE-2025-39779
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: subpage: keep TOWRITE tag until folio is cleaned btrfs_subpage_set_writeback() calls folio_start_writeback() the first time …

Sep 11, 2025
CVE-2025-39777
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: acomp - Fix CFI failure due to type punning To avoid a crash when …

Sep 11, 2025
CVE-2025-39775
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix WARN with uffd that has remap events disabled Registering userfaultd on a VMA …

Sep 11, 2025
CVE-2025-39774
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: rzg2l_adc: Set driver data before enabling runtime PM When stress-testing the system by …

Sep 11, 2025
CVE-2025-39773
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix soft lockup in br_multicast_query_expired() When set multicast_query_interval to a large value, the …

Sep 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.