CVE Database

52406+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0878
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft LimonDesk allows Cross-Site Scripting (XSS).This issue affects LimonDesk: from s1.02.14 …

Sep 3, 2025
CVE-2025-9901
5.9 MEDIUM

A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses …

Sep 3, 2025
CVE-2025-3701
4.3 MEDIUM

Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Malcure Malware Scanner: from …

Sep 3, 2025
CVE-2025-38678
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject duplicate device on updates A chain/flowtable update with duplicated devices in the …

Sep 3, 2025
CVE-2024-13066
4.3 MEDIUM

Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - 103 - Clickjacking.This issue affects LimonDesk: from s1.02.14 …

Sep 3, 2025
CVE-2025-9219
4.3 MEDIUM

The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES …

Sep 3, 2025
CVE-2024-13065
6.3 MEDIUM

Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows Input Data Manipulation, CAPEC - 125 - Flooding.This issue affects MyRezzta: from …

Sep 3, 2025
CVE-2024-13064
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft MyRezzta allows Cross-Site Scripting (XSS).This issue affects MyRezzta: from s2.02.02 …

Sep 3, 2025
CVE-2024-13063
6.8 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing.This issue affects MyRezzta: from s2.02.02 before v2.05.01.

Sep 3, 2025
CVE-2025-9378
6.4 MEDIUM

The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attributes in the Lottie …

Sep 3, 2025
CVE-2025-8663
6.5 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.0.0 …

Sep 3, 2025
CVE-2025-58210
5.3 MEDIUM

Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Makeaholic: from n/a through <= 1.8.5.

Sep 3, 2025
CVE-2025-21041
6.2 MEDIUM

Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.

Sep 3, 2025
CVE-2025-21040
5.1 MEDIUM

Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Sep 3, 2025
CVE-2025-21039
5.1 MEDIUM

Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Sep 3, 2025
CVE-2025-21038
5.1 MEDIUM

Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Sep 3, 2025
CVE-2025-21037
4.1 MEDIUM

Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for …

Sep 3, 2025
CVE-2025-21036
5.0 MEDIUM

Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported note files. User interaction is required for triggering …

Sep 3, 2025
CVE-2025-21035
4.6 MEDIUM

Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across …

Sep 3, 2025
CVE-2025-21034
4.0 MEDIUM

Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

Sep 3, 2025
CVE-2025-21033
4.0 MEDIUM

Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

Sep 3, 2025
CVE-2025-21032
5.9 MEDIUM

Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.

Sep 3, 2025
CVE-2025-21031
6.8 MEDIUM

Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.

Sep 3, 2025
CVE-2025-21030
4.3 MEDIUM

Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in …

Sep 3, 2025
CVE-2025-21029
4.0 MEDIUM

Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the …

Sep 3, 2025
CVE-2025-21028
5.5 MEDIUM

Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.

Sep 3, 2025
CVE-2025-21027
5.1 MEDIUM

Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.

Sep 3, 2025
CVE-2025-21026
4.0 MEDIUM

Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.

Sep 3, 2025
CVE-2025-21025
5.1 MEDIUM

Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.

Sep 3, 2025
CVE-2023-21483
6.4 MEDIUM

Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.

Sep 3, 2025
CVE-2023-21482
6.1 MEDIUM

Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to …

Sep 3, 2025
CVE-2023-21481
5.4 MEDIUM

Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.

Sep 3, 2025
CVE-2023-21479
5.3 MEDIUM

Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a …

Sep 3, 2025
CVE-2023-21478
6.0 MEDIUM

Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

Sep 3, 2025
CVE-2023-21474
6.3 MEDIUM

Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.

Sep 3, 2025
CVE-2023-21473
6.8 MEDIUM

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

Sep 3, 2025
CVE-2023-21472
6.8 MEDIUM

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

Sep 3, 2025
CVE-2023-21471
4.0 MEDIUM

Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

Sep 3, 2025
CVE-2023-21470
4.0 MEDIUM

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.

Sep 3, 2025
CVE-2023-21469
4.0 MEDIUM

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.

Sep 3, 2025
CVE-2023-21468
5.9 MEDIUM

Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.

Sep 3, 2025
CVE-2023-21467
4.6 MEDIUM

Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.

Sep 3, 2025
CVE-2023-21466
5.3 MEDIUM

PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.

Sep 3, 2025
CVE-2025-58351
6.8 MEDIUM

Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature which facilitates local file system storage capabilities …

Sep 3, 2025
CVE-2025-9847
6.3 MEDIUM

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the …

Sep 3, 2025
CVE-2025-9843
5.3 MEDIUM

A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This manipulation causes information …

Sep 3, 2025
CVE-2025-9842
5.3 MEDIUM

A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. The manipulation results in information …

Sep 3, 2025
CVE-2025-9841
6.3 MEDIUM

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of …

Sep 3, 2025
CVE-2025-9260
6.5 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 …

Sep 3, 2025
CVE-2025-9840
6.3 MEDIUM

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of …

Sep 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.