CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43204
7.5 HIGH

SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an …

Jul 10, 2025
CVE-2024-42516
7.5 HIGH

HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied …

Jul 10, 2025
CVE-2025-46788
7.4 HIGH

Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.

Jul 10, 2025
CVE-2025-7365
7.1 HIGH

A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the …

Jul 10, 2025
CVE-2025-46835
8.5 HIGH

Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked …

Jul 10, 2025
CVE-2025-46334
8.6 HIGH

Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical …

Jul 10, 2025
CVE-2025-44251
7.5 HIGH

Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.

Jul 10, 2025
CVE-2025-27614
8.6 HIGH

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social …

Jul 10, 2025
CVE-2025-7425
7.8 HIGH

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, …

Jul 10, 2025
CVE-2025-7424
7.5 HIGH

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to …

Jul 10, 2025
CVE-2025-5040
7.8 HIGH

A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause …

Jul 10, 2025
CVE-2025-5037
7.8 HIGH

A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerability. A malicious actor can leverage this …

Jul 10, 2025
CVE-2025-6948
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain …

Jul 10, 2025
CVE-2025-5023
7.1 HIGH

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the …

Jul 10, 2025
CVE-2025-38348
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback() Robert Morris reported: |If a malicious USB device pretends …

Jul 10, 2025
CVE-2025-38346
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix UAF when lookup kallsym after ftrace disabled The following issue happens with a …

Jul 10, 2025
CVE-2025-38342
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args() software_node_get_reference_args() wants to get @index-th element, so …

Jul 10, 2025
CVE-2025-38341
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: avoid double free when failing to DMA-map FW msg The semantics are that …

Jul 10, 2025
CVE-2025-38340
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUnit test KASAN reported out of bounds …

Jul 10, 2025
CVE-2025-38338
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs/nfs/read: fix double-unlock bug in nfs_return_empty_folio() Sometimes, when a file was read while it was …

Jul 10, 2025
CVE-2025-38330
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUnit test (ctl cache) KASAN reported out …

Jul 10, 2025
CVE-2025-38329
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUnit test (wmfw info) KASAN reported out …

Jul 10, 2025
CVE-2025-38323
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: atm: add lec_mutex syzbot found its way in net/atm/lec.c, and found an error path …

Jul 10, 2025
CVE-2025-38320
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth() KASAN reports a stack-out-of-bounds read in regs_get_kernel_stack_nth(). Call Trace: …

Jul 10, 2025
CVE-2025-38317
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix buffer overflow in debugfs If the user tries to write more than …

Jul 10, 2025
CVE-2025-38313
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix double-free on mc_dev The blamed commit tried to simplify how the deallocations …

Jul 10, 2025
CVE-2025-38298
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: EDAC/skx_common: Fix general protection fault After loading i10nm_edac (which automatically loads skx_edac_common), if unload only …

Jul 10, 2025
CVE-2025-38295
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: perf/amlogic: Replace smp_processor_id() with raw_smp_processor_id() in meson_ddr_pmu_create() The Amlogic DDR PMU driver meson_ddr_pmu_create() function incorrectly …

Jul 10, 2025
CVE-2025-38292
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix invalid access to memory In ath12k_dp_rx_msdu_coalesce(), rxcb is fetched from skb and …

Jul 10, 2025
CVE-2025-38289
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Avoid potential ndlp use-after-free in dev_loss_tmo_callbk Smatch detected a potential use-after-free of an …

Jul 10, 2025
CVE-2025-38288
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix smp_processor_id() call trace for preemptible kernels Correct kernel call trace when calling …

Jul 10, 2025
CVE-2025-38286
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91: Fix possible out-of-boundary access at91_gpio_probe() doesn't check that given OF alias is not …

Jul 10, 2025
CVE-2025-38280
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid __bpf_prog_ret0_warn when jit fails syzkaller reported an issue: WARNING: CPU: 3 PID: 217 …

Jul 10, 2025
CVE-2025-38279
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Do not include stack ptr register in precision backtracking bookkeeping Yi Lai reported an …

Jul 10, 2025
CVE-2025-38270
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: drv: netdevsim: don't napi_complete() from netpoll netdevsim supports netpoll. Make sure we don't call …

Jul 10, 2025
CVE-2025-38267
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun When reading a memory mapped buffer …

Jul 10, 2025
CVE-2025-6970
7.5 HIGH

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions …

Jul 9, 2025
CVE-2025-6377
7.8 HIGH

A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries …

Jul 9, 2025
CVE-2025-6376
7.8 HIGH

A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries …

Jul 9, 2025
CVE-2025-53548
7.5 HIGH

Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. …

Jul 9, 2025
CVE-2025-53645
7.5 HIGH

Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper …

Jul 9, 2025
CVE-2025-53652
8.2 HIGH

Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, …

Jul 9, 2025
CVE-2025-53650
7.3 HIGH

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to …

Jul 9, 2025
CVE-2025-44177
8.2 HIGH

A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An unauthenticated attacker can remotely read arbitrary …

Jul 9, 2025
CVE-2025-52364
7.5 HIGH

Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows …

Jul 9, 2025
CVE-2025-38259
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd9335: Fix missing free of regulator supplies Driver gets and enables all regulator …

Jul 9, 2025
CVE-2025-38257
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained …

Jul 9, 2025
CVE-2025-38250
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix use-after-free in vhci_flush() syzbot reported use-after-free in vhci_flush() without repro. [0] From …

Jul 9, 2025
CVE-2025-38249
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() In snd_usb_get_audioformat_uac3(), the length value returned from snd_usb_ctl_msg() …

Jul 9, 2025
CVE-2025-38248
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of …

Jul 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.