CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49464
6.5 MEDIUM

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

Jul 10, 2025
CVE-2025-49463
6.5 MEDIUM

Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via …

Jul 10, 2025
CVE-2025-47813
4.3 MEDIUM KEV

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Jul 10, 2025
CVE-2025-47811
4.1 MEDIUM

In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web …

Jul 10, 2025
CVE-2025-6395
6.5 MEDIUM

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

Jul 10, 2025
CVE-2025-53364
5.3 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and …

Jul 10, 2025
CVE-2025-46789
6.5 MEDIUM

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

Jul 10, 2025
CVE-2025-36090
4.3 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be used …

Jul 10, 2025
CVE-2024-39752
6.8 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to …

Jul 10, 2025
CVE-2024-38327
6.8 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which …

Jul 10, 2025
CVE-2024-37524
5.3 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is …

Jul 10, 2025
CVE-2025-7407
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of the file diag.cgi. The manipulation of …

Jul 10, 2025
CVE-2024-36697
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via …

Jul 10, 2025
CVE-2025-6211
6.5 MEDIUM

A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document …

Jul 10, 2025
CVE-2025-32990
6.5 MEDIUM

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from …

Jul 10, 2025
CVE-2025-5022
6.5 MEDIUM

Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi …

Jul 10, 2025
CVE-2025-3396
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have …

Jul 10, 2025
CVE-2025-38347
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on ino and xnid syzbot reported a f2fs bug …

Jul 10, 2025
CVE-2025-38345
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPICA: fix acpi operand cache leak in dswstate.c ACPICA commit 987a3b5cf7175916e2a4b6ea5b8e70f830dfe732 I found an ACPI …

Jul 10, 2025
CVE-2025-38344
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPICA: fix acpi parse and parseext cache leaks ACPICA commit 8829e70e1360c81e7a5a901b5d4f48330e021ea5 I'm Seunghun Han, and …

Jul 10, 2025
CVE-2025-38343
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: drop fragments with multicast or broadcast RA IEEE 802.11 fragmentation can only …

Jul 10, 2025
CVE-2025-38339
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/bpf: fix JIT code size calculation of bpf trampoline arch_bpf_trampoline_size() provides JIT size of the …

Jul 10, 2025
CVE-2025-38337
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata() Since handle->h_transaction may be a NULL pointer, so …

Jul 10, 2025
CVE-2025-38336
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330 The controller has a hardware bug …

Jul 10, 2025
CVE-2025-38335
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT When enabling PREEMPT_RT, the gpio_keys_irq_timer() …

Jul 10, 2025
CVE-2025-38334
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Prevent attempts to reclaim poisoned pages TL;DR: SGX page reclaim touches the page to …

Jul 10, 2025
CVE-2025-38333
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to bail out in get_new_segment() ------------[ cut here ]------------ WARNING: CPU: 3 PID: …

Jul 10, 2025
CVE-2025-38332
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Use memcpy() for BIOS version The strlcat() with FORTIFY support is triggering a …

Jul 10, 2025
CVE-2025-38331
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Use TOE/TSO on all TCP It is desireable to push the hardware …

Jul 10, 2025
CVE-2025-38328
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jffs2: check jffs2_prealloc_raw_node_refs() result in few other places Fuzzing hit another invalid pointer dereference due …

Jul 10, 2025
CVE-2025-38327
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fgraph: Do not enable function_graph tracer when setting funcgraph-args When setting the funcgraph-args option when …

Jul 10, 2025
CVE-2025-38326
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: aoe: clean device rq_list in aoedev_downdev() An aoe device's rq_list contains accepted block requests that …

Jul 10, 2025
CVE-2025-38325
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add free_transport ops in ksmbd connection free_transport function for tcp connection can be called …

Jul 10, 2025
CVE-2025-38324
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). As syzbot reported [0], mpls_route_input_rcu() can be called from mpls_getroute(), …

Jul 10, 2025
CVE-2025-38322
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix crash in icl_update_topdown_event() The perf_fuzzer found a hard-lockup crash on a RaptorLake machine: …

Jul 10, 2025
CVE-2025-38321
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: Log an error when close_all_cached_dirs fails Under low-memory conditions, close_all_cached_dirs() can't move the dentries …

Jul 10, 2025
CVE-2025-38319
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pp: Fix potential NULL pointer dereference in atomctrl_initialize_mc_reg_table The function atomctrl_initialize_mc_reg_table() and atomctrl_initialize_mc_reg_table_v2_2() does not …

Jul 10, 2025
CVE-2025-38318
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf: arm-ni: Fix missing platform_set_drvdata() Add missing platform_set_drvdata in arm_ni_probe(), otherwise calling platform_get_drvdata() in remove …

Jul 10, 2025
CVE-2025-38316
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: avoid NULL pointer dereference in mt7996_set_monitor() The function mt7996_set_monitor() dereferences phy before …

Jul 10, 2025
CVE-2025-38315
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Check dsbr size from EFI variable Since the size of struct btintel_dsbr is …

Jul 10, 2025
CVE-2025-38314
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio-pci: Fix result size returned for the admin command completion The result size returned by …

Jul 10, 2025
CVE-2025-38312
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() In fb_find_mode_cvt(), iff mode->refresh somehow happens …

Jul 10, 2025
CVE-2025-38311
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iavf: get rid of the crit lock Get rid of the crit lock. That frees …

Jul 10, 2025
CVE-2025-38310
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: seg6: Fix validation of nexthop addresses The kernel currently validates that the length of the …

Jul 10, 2025
CVE-2025-38309
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: move xe_svm_init() earlier In xe_vm_close_and_put() we need to be able to call xe_svm_fini(), however …

Jul 10, 2025
CVE-2025-38308
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Fix possible null-ptr-deref when initing hw Search result of avs_dai_find_path_template() shall be …

Jul 10, 2025
CVE-2025-38307
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Verify content returned by parse_int_array() The first element of the returned array …

Jul 10, 2025
CVE-2025-38306
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/fhandle.c: fix a race in call of has_locked_children() may_decode_fh() is calling has_locked_children() while holding no …

Jul 10, 2025
CVE-2025-38305
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ptp: remove ptp->n_vclocks check logic in ptp_vclock_in_use() There is no disagreement that we should check …

Jul 10, 2025
CVE-2025-38304
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix NULL pointer deference on eir_get_service_data The len parameter is considered optional so it …

Jul 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.