CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39772
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/hisilicon/hibmc: fix the hibmc loaded failed bug When hibmc loaded failed, the driver use hibmc_unload …

Sep 11, 2025
CVE-2025-39771
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: regulator: pca9450: Use devm_register_sys_off_handler With module test, there is error dump: ------------[ cut here ]------------ …

Sep 11, 2025
CVE-2025-39770
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic …

Sep 11, 2025
CVE-2025-39769
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix lockdep warning during rmmod The commit under the Fixes tag added a netdev_assert_locked() …

Sep 11, 2025
CVE-2025-39768
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix complex rules rehash error flow Moving rules from matcher to matcher should …

Sep 11, 2025
CVE-2025-39767
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Optimize module load time by optimizing PLT/GOT counting When enabling CONFIG_KASAN, CONFIG_PREEMPT_VOLUNTARY_BUILD and CONFIG_PREEMPT_VOLUNTARY …

Sep 11, 2025
CVE-2025-39765
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: fix ida_free call while not allocated In the snd_utimer_create() function, if the kasprintf() …

Sep 11, 2025
CVE-2025-39764
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: remove refcounting in expectation dumpers Same pattern as previous patch: do not keep …

Sep 11, 2025
CVE-2025-39763
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: send SIGBUS to current task if synchronous memory error not recovered If a …

Sep 11, 2025
CVE-2025-39762
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: add null check [WHY] Prevents null pointer dereferences to enhance function robustness [HOW] Adds …

Sep 11, 2025
CVE-2025-39758
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages Ever since commit c2ff29e99a76 ("siw: Inline do_tcp_sendpages()"), …

Sep 11, 2025
CVE-2025-39756
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs: Prevent file descriptor table allocations exceeding INT_MAX When sysctl_nr_open is set to a very …

Sep 11, 2025
CVE-2025-39754
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/smaps: fix race between smaps_hugetlb_range and migration smaps_hugetlb_range() handles the pte without holdling ptl, and …

Sep 11, 2025
CVE-2025-39753
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gfs2: Set .migrate_folio in gfs2_{rgrp,meta}_aops Clears up the warning added in 7ee3647243e5 ("migrate: Remove call …

Sep 11, 2025
CVE-2025-39752
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: rockchip: fix kernel hang during smp initialization In order to bring up secondary CPUs …

Sep 11, 2025
CVE-2025-39748
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Forget ranges when refining tnum after JSET Syzbot reported a kernel warning due to …

Sep 11, 2025
CVE-2025-39747
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Add error handling for krealloc in metadata setup Function msm_ioctl_gem_info_set_metadata() now checks for krealloc …

Sep 11, 2025
CVE-2025-39746
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: shutdown driver when hardware is unreliable In rare cases, ath10k may lose connection …

Sep 11, 2025
CVE-2025-39745
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rcutorture: Fix rcutorture_one_extend_check() splat in RT kernels For built with CONFIG_PREEMPT_RT=y kernels, running rcutorture tests …

Sep 11, 2025
CVE-2025-39742
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() The function divides number of online CPUs by …

Sep 11, 2025
CVE-2025-39741
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: don't overflow max copy size With non-page aligned copy, we need to use 4 …

Sep 11, 2025
CVE-2025-39739
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-qcom: Add SM6115 MDSS compatible Add the SM6115 MDSS compatible to clients compatible list, as …

Sep 11, 2025
CVE-2025-39737
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() A soft lockup warning was observed on a relative …

Sep 11, 2025
CVE-2025-39736
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock When netpoll is enabled, calling pr_warn_once() while …

Sep 11, 2025
CVE-2025-26499
6.0 MEDIUM

Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This flaw allows one user to be granted a …

Sep 11, 2025
CVE-2025-10251
6.3 MEDIUM

A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/admin/controller/Images.php. The manipulation of the …

Sep 11, 2025
CVE-2025-40696
5.4 MEDIUM

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper …

Sep 11, 2025
CVE-2025-40695
5.4 MEDIUM

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper …

Sep 11, 2025
CVE-2025-40694
5.4 MEDIUM

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper …

Sep 11, 2025
CVE-2025-40693
5.4 MEDIUM

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack …

Sep 11, 2025
CVE-2025-10250
5.0 MEDIUM

A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry Channel. …

Sep 11, 2025
CVE-2025-9861
6.4 MEDIUM

The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'los_showposts' shortcode in all versions up to, and including, 1.8.5 …

Sep 11, 2025
CVE-2025-9860
6.4 MEDIUM

The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in all versions up to, and including, 1.1 due …

Sep 11, 2025
CVE-2025-9855
6.4 MEDIUM

The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_authors' shortcode in all versions up to, and including, 1.3.8 …

Sep 11, 2025
CVE-2025-9850
6.4 MEDIUM

The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' shortcode in all versions up to, and including, 1.3.11 due …

Sep 11, 2025
CVE-2025-9635
4.3 MEDIUM

The Analytics Reduce Bounce Rate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due …

Sep 11, 2025
CVE-2025-9634
4.3 MEDIUM

The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to …

Sep 11, 2025
CVE-2025-9633
4.3 MEDIUM

The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.83. This is due to missing …

Sep 11, 2025
CVE-2025-9632
4.3 MEDIUM

The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing …

Sep 11, 2025
CVE-2025-9631
4.3 MEDIUM

The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.4. This is due to missing or …

Sep 11, 2025
CVE-2025-9628
4.3 MEDIUM

The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is …

Sep 11, 2025
CVE-2025-9627
4.3 MEDIUM

The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.10. This is due to missing …

Sep 11, 2025
CVE-2025-9623
4.3 MEDIUM

The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is …

Sep 11, 2025
CVE-2025-9620
6.1 MEDIUM

The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.3. This is due to missing …

Sep 11, 2025
CVE-2025-9617
5.3 MEDIUM

The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing …

Sep 11, 2025
CVE-2025-9451
6.5 MEDIUM

The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, …

Sep 11, 2025
CVE-2025-9128
6.4 MEDIUM

The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.9.3 due …

Sep 11, 2025
CVE-2025-9123
6.4 MEDIUM

The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup heading and location address parameters …

Sep 11, 2025
CVE-2025-8721
6.4 MEDIUM

The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortcode in all versions up to, and including, 1.0.4 …

Sep 11, 2025
CVE-2025-8692
4.9 MEDIUM

The Coupon API plugin for WordPress is vulnerable to SQL Injection via the ‘log_duration’ parameter in all versions up to, and including, 6.2.12 due to …

Sep 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.