CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8511
3.5 LOW

A vulnerability classified as problematic was found in Portabilis i-Diario 1.5.0. This vulnerability affects unknown code of the file /diario-de-observacoes/ of the component Observações. The …

Aug 3, 2025
CVE-2025-8510
3.5 LOW

A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. This affects the function Gerar of the file ieducar/intranet/educar_matricula_lst.php. The manipulation of the …

Aug 3, 2025
CVE-2025-8509
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Aug 3, 2025
CVE-2025-8508
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Aug 3, 2025
CVE-2025-8507
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9. It has been classified as problematic. Affected is an unknown function of the file /intranet/educar_funcao_lst.php. The manipulation …

Aug 3, 2025
CVE-2025-8506
3.5 LOW

A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This issue affects some unknown processing of the file /user/editUI. The …

Aug 3, 2025
CVE-2025-8501
3.5 LOW

A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected is an unknown function of the file /insert-and-view/action.php. The …

Aug 3, 2025
CVE-2025-54350
3.7 LOW

In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

Aug 3, 2025
CVE-2025-23290
2.5 LOW

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics which may be influenced by work …

Aug 2, 2025
CVE-2025-23288
3.3 LOW

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may cause an exposure of sensitive system information with local unprivileged system access. …

Aug 2, 2025
CVE-2025-23287
3.3 LOW

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level information. A successful exploit of this vulnerability may lead …

Aug 2, 2025
CVE-2025-54781
2.8 LOW

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau in version 1.0.0, the himmelblaud_tasks service leaks …

Aug 2, 2025
CVE-2024-13978
2.5 LOW

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the …

Aug 1, 2025
CVE-2025-6011
3.7 LOW

A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially …

Aug 1, 2025
CVE-2023-44976
3.2 LOW

Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as …

Aug 1, 2025
CVE-2023-32251
3.7 LOW

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a …

Jul 31, 2025
CVE-2025-37109
3.5 LOW

Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

Jul 31, 2025
CVE-2025-37108
3.5 LOW

Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

Jul 31, 2025
CVE-2025-51385
3.5 LOW

D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.

Jul 31, 2025
CVE-2025-51384
3.5 LOW

D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.

Jul 31, 2025
CVE-2025-51383
3.5 LOW

D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.

Jul 31, 2025
CVE-2025-8380
3.5 LOW

A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/add_query_account.php. The manipulation …

Jul 31, 2025
CVE-2025-8365
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Jul 31, 2025
CVE-2025-54085
3.8 LOW

CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who …

Jul 31, 2025
CVE-2025-49082
2.7 LOW

CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who …

Jul 31, 2025
CVE-2025-8337
2.4 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the …

Jul 30, 2025
CVE-2025-36609
2.5 LOW

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit …

Jul 30, 2025
CVE-2025-53113
2.7 LOW

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses …

Jul 30, 2025
CVE-2025-54410
3.3 LOW

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. …

Jul 30, 2025
CVE-2025-52567
3.5 LOW

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through …

Jul 30, 2025
CVE-2025-8283
3.7 LOW

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may …

Jul 28, 2025
CVE-2025-54529
3.7 LOW

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

Jul 28, 2025
CVE-2025-8260
3.1 LOW

A security flaw has been discovered in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. This affects an unknown part of the file /grid/vgrid_server.php of the component Web …

Jul 28, 2025
CVE-2023-53161
2.9 LOW

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

Jul 28, 2025
CVE-2023-53160
2.9 LOW

The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.

Jul 28, 2025
CVE-2024-58266
3.2 LOW

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

Jul 27, 2025
CVE-2024-58265
3.1 LOW

The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.

Jul 27, 2025
CVE-2024-58264
3.2 LOW

The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.

Jul 27, 2025
CVE-2024-58263
3.7 LOW

The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.

Jul 27, 2025
CVE-2024-58262
2.9 LOW

The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.

Jul 27, 2025
CVE-2024-58261
2.9 LOW

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser …

Jul 27, 2025
CVE-2025-8225
3.3 LOW

A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component …

Jul 27, 2025
CVE-2025-8224
3.3 LOW

A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the …

Jul 27, 2025
CVE-2025-8222
3.5 LOW

A vulnerability, which was classified as problematic, has been found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. Affected by this issue is some unknown functionality …

Jul 27, 2025
CVE-2025-8211
3.5 LOW

A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the …

Jul 26, 2025
CVE-2025-8206
3.1 LOW

A vulnerability, which was classified as problematic, was found in Comodo Dragon up to 134.0.6998.179. This affects an unknown part of the component IP DNS …

Jul 26, 2025
CVE-2025-8205
3.7 LOW

A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by this issue is some unknown functionality of …

Jul 26, 2025
CVE-2025-8204
3.1 LOW

A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerability is an unknown functionality of the component HSTS …

Jul 26, 2025
CVE-2025-8191
3.5 LOW

A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of …

Jul 26, 2025
CVE-2025-8167
3.5 LOW

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.