CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58790
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi kiwi-social-share allows Stored XSS.This issue affects Kiwi: from n/a through <= …

Sep 5, 2025
CVE-2025-58787
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Popup themify-popup allows Stored XSS.This issue affects Themify Popup: from n/a …

Sep 5, 2025
CVE-2025-58786
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects …

Sep 5, 2025
CVE-2025-58785
5.4 MEDIUM

Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ray Enterprise Translation: from n/a …

Sep 5, 2025
CVE-2025-58784
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft ARI Fancy Lightbox ari-fancy-lightbox allows Stored XSS.This issue affects ARI Fancy Lightbox: …

Sep 5, 2025
CVE-2025-58783
4.3 MEDIUM

Missing Authorization vulnerability in gutentor Gutentor gutentor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutentor: from n/a through <= 3.5.5.

Sep 5, 2025
CVE-2025-10011
6.3 MEDIUM

A weakness has been identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /module/TabelaArredondamento/edit. This manipulation of …

Sep 5, 2025
CVE-2025-58313
5.1 MEDIUM

Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module.

Sep 5, 2025
CVE-2025-58276
6.8 MEDIUM

Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.

Sep 5, 2025
CVE-2025-48395
4.7 MEDIUM

An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the …

Sep 5, 2025
CVE-2025-8944
4.3 MEDIUM

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, …

Sep 5, 2025
CVE-2025-58400
6.7 MEDIUM

RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write …

Sep 5, 2025
CVE-2025-41408
4.3 MEDIUM

Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may …

Sep 5, 2025
CVE-2025-58401
6.8 MEDIUM

Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on …

Sep 5, 2025
CVE-2025-8684
6.4 MEDIUM

The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, 3.20.0 due to …

Sep 5, 2025
CVE-2025-7445
6.5 MEDIUM

Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.

Sep 5, 2025
CVE-2025-58352
6.5 MEDIUM

Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The …

Sep 5, 2025
CVE-2025-55305
6.1 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and …

Sep 4, 2025
CVE-2025-55242
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.

Sep 4, 2025
CVE-2025-22415
4.0 MEDIUM

In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local escalation of privilege …

Sep 4, 2025
CVE-2024-49731
4.0 MEDIUM

In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new Pixel Watch due to a logic …

Sep 4, 2025
CVE-2024-40664
6.2 MEDIUM

In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logic error in the code. This …

Sep 4, 2025
CVE-2025-48562
5.0 MEDIUM

In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional …

Sep 4, 2025
CVE-2025-48561
5.5 MEDIUM

In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to …

Sep 4, 2025
CVE-2025-48560
5.5 MEDIUM

In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could lead to local information …

Sep 4, 2025
CVE-2025-48559
5.5 MEDIUM

In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to …

Sep 4, 2025
CVE-2025-48554
6.1 MEDIUM

In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the code. This could lead to local …

Sep 4, 2025
CVE-2025-48551
5.0 MEDIUM

In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused deputy. This could lead …

Sep 4, 2025
CVE-2025-48550
5.5 MEDIUM

In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This could lead to local denial of …

Sep 4, 2025
CVE-2025-48542
5.5 MEDIUM

In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service …

Sep 4, 2025
CVE-2025-48538
5.5 MEDIUM

In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local …

Sep 4, 2025
CVE-2025-48529
5.5 MEDIUM

In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused deputy. This could lead to local information disclosure …

Sep 4, 2025
CVE-2025-48528
4.0 MEDIUM

In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalation of privilege with …

Sep 4, 2025
CVE-2025-48527
6.2 MEDIUM

In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead …

Sep 4, 2025
CVE-2025-48526
4.0 MEDIUM

In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profile due to improper input validation. …

Sep 4, 2025
CVE-2025-48524
5.5 MEDIUM

In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of service with …

Sep 4, 2025
CVE-2025-32330
5.7 MEDIUM

In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to …

Sep 4, 2025
CVE-2025-26463
5.5 MEDIUM

In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a local persistent denial of service with …

Sep 4, 2025
CVE-2025-26456
5.5 MEDIUM

In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due to a logic error in the code. This could lead …

Sep 4, 2025
CVE-2025-26453
5.5 MEDIUM

In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could lead to local …

Sep 4, 2025
CVE-2025-26449
5.5 MEDIUM

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no …

Sep 4, 2025
CVE-2025-26448
5.5 MEDIUM

In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no …

Sep 4, 2025
CVE-2025-26445
5.5 MEDIUM

In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local information disclosure …

Sep 4, 2025
CVE-2025-26442
5.5 MEDIUM

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic error in the code. This …

Sep 4, 2025
CVE-2025-26441
6.5 MEDIUM

In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Sep 4, 2025
CVE-2025-26437
5.5 MEDIUM

In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information …

Sep 4, 2025
CVE-2025-26432
5.5 MEDIUM

In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial …

Sep 4, 2025
CVE-2025-26429
5.5 MEDIUM

In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of …

Sep 4, 2025
CVE-2025-26427
4.4 MEDIUM

In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no …

Sep 4, 2025
CVE-2025-26426
5.1 MEDIUM

In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead …

Sep 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.