CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38150
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: af_packet: move notifier's packet_dev_mc out of rcu critical section Syzkaller reports the following issue: BUG: …

Jul 3, 2025
CVE-2025-38149
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: clear phydev->devlink when the link is deleted There is a potential crash issue …

Jul 3, 2025
CVE-2025-38148
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: mscc: Fix memory leak when using one step timestamping Fix memory leak when …

Jul 3, 2025
CVE-2025-38147
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: calipso: Don't call calipso functions for AF_INET sk. syzkaller reported a null-ptr-deref in txopt_get(). [0] …

Jul 3, 2025
CVE-2025-38145
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop() devm_kasprintf() returns NULL when memory allocation fails. Currently, …

Jul 3, 2025
CVE-2025-38144
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: watchdog: lenovo_se30_wdt: Fix possible devm_ioremap() NULL pointer dereference in lenovo_se30_wdt_probe() devm_ioremap() returns NULL on error. …

Jul 3, 2025
CVE-2025-38143
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: backlight: pm8941: Add NULL check in wled_configure() devm_kasprintf() returns NULL when memory allocation fails. Currently, …

Jul 3, 2025
CVE-2025-38142
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus-ec-sensors) check sensor index in read_string() Prevent a potential invalid memory access when the …

Jul 3, 2025
CVE-2025-38140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm: limit swapping tables for devices with zone write plugs dm_revalidate_zones() only allowed new or …

Jul 3, 2025
CVE-2025-38138
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: Add NULL check in udma_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, …

Jul 3, 2025
CVE-2025-38136
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Reorder clock handling and power management in probe Reorder the initialization sequence in …

Jul 3, 2025
CVE-2025-38135
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: Fix potential null-ptr-deref in mlb_usio_probe() devm_ioremap() can return NULL on error. Currently, mlb_usio_probe() does …

Jul 3, 2025
CVE-2025-38134
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: acpi: Prevent null pointer dereference in usb_acpi_add_usb4_devlink() As demonstrated by the fix for update_port_device_state, …

Jul 3, 2025
CVE-2025-38132
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: coresight: holding cscfg_csdev_lock while removing cscfg from csdev There'll be possible race scenario for coresight …

Jul 3, 2025
CVE-2025-38130
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/connector: only call HDMI audio helper plugged cb if non-null On driver remove, sound/soc/codecs/hdmi-codec.c calls …

Jul 3, 2025
CVE-2025-38128
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: reject malformed HCI_CMD_SYNC commands In 'mgmt_hci_cmd_sync()', check whether the size of parameters passed …

Jul 3, 2025
CVE-2025-38127
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: fix Tx scheduler error handling in XDP callback When the XDP program is loaded, …

Jul 3, 2025
CVE-2025-38126
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping The stmmac platform …

Jul 3, 2025
CVE-2025-38125
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: make sure that ptp_rate is not 0 before configuring EST If the ptp_rate …

Jul 3, 2025
CVE-2025-38124
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment after pull from frag_list Commit a1e40ac5b5e9 ("net: gso: fix udp …

Jul 3, 2025
CVE-2025-38123
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: Fix napi rx poll issue When driver handles the napi rx polling …

Jul 3, 2025
CVE-2025-38122
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gve: add missing NULL check for gve_alloc_pending_packet() in TX DQO gve_alloc_pending_packet() can return NULL, but …

Jul 3, 2025
CVE-2025-38121
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: avoid panic on init failure In case of an error during init, …

Jul 3, 2025
CVE-2025-38120
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo_avx2: fix initial map fill If the first field doesn't cover the entire start …

Jul 3, 2025
CVE-2025-38119
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: core: ufs: Fix a hang in the error handler ufshcd_err_handling_prepare() calls ufshcd_rpm_get_sync(). The latter …

Jul 3, 2025
CVE-2025-38115
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: fix a potential crash on gso_skb handling SFQ has an assumption of always …

Jul 3, 2025
CVE-2025-38114
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: e1000: Move cancel_work_sync to avoid deadlock Previously, e1000_down called cancel_work_sync for the e1000 reset task …

Jul 3, 2025
CVE-2025-38113
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Fix NULL pointer dereference when nosmp is used With nosmp in cmdline, other …

Jul 3, 2025
CVE-2025-38112
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_readable() sk->sk_prot->sock_is_readable is a valid function pointer when sk resides …

Jul 3, 2025
CVE-2025-38105
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Kill timer properly at removal The USB-audio MIDI code initializes the timer, but …

Jul 3, 2025
CVE-2025-38100
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/iopl: Cure TIF_IO_BITMAP inconsistencies io_bitmap_exit() is invoked from exit_thread() when a task exists or when …

Jul 3, 2025
CVE-2025-38099
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Disable SCO support if READ_VOICE_SETTING is unsupported/broken A SCO connection without the proper voice_setting …

Jul 3, 2025
CVE-2025-38098
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Don't treat wb connector as physical in create_validate_stream_for_sink Don't try to operate on a …

Jul 3, 2025
CVE-2025-38097
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: espintcp: remove encap socket caching to avoid reference leak The current scheme for caching the …

Jul 3, 2025
CVE-2025-38096
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: don't warn when if there is a FW error iwl_trans_reclaim is warning if …

Jul 3, 2025
CVE-2025-38095
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_fences smp_store_mb() inserts memory barrier after storing operation. It …

Jul 3, 2025
CVE-2025-38094
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: cadence: macb: Fix a possible deadlock in macb_halt_tx. There is a situation where after …

Jul 3, 2025
CVE-2024-9017
6.4 MEDIUM

The PeepSo Core: Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Group Description field in all versions up to, and including, …

Jul 3, 2025
CVE-2025-5944
6.4 MEDIUM

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ attribute in all versions up to, and …

Jul 3, 2025
CVE-2025-52842
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Laundry on Linux, MacOS allows Account Takeover. This issue affects Laundry: …

Jul 2, 2025
CVE-2025-52559
6.8 MEDIUM

Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview …

Jul 2, 2025
CVE-2025-45424
5.3 MEDIUM

Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.

Jul 2, 2025
CVE-2025-20307
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks …

Jul 2, 2025
CVE-2025-53358
6.5 MEDIUM

kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/index/file/ui.py, the index_fn method accepts both URLs and local file …

Jul 2, 2025
CVE-2025-52886
5.9 MEDIUM

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to …

Jul 2, 2025
CVE-2025-20310
6.1 MEDIUM

A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting …

Jul 2, 2025
CVE-2025-20308
6.0 MEDIUM

A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as …

Jul 2, 2025
CVE-2025-6725
5.4 MEDIUM

In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a …

Jul 2, 2025
CVE-2025-53494
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TwoColConflict Extension allows Stored XSS.This issue affects …

Jul 2, 2025
CVE-2025-53493
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects …

Jul 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.