CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27804
6.5 MEDIUM

Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted message to a certain MQTT topic …

May 21, 2025
CVE-2025-27803
6.5 MEDIUM

The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately …

May 21, 2025
CVE-2024-12561
6.1 MEDIUM

The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.0. …

May 21, 2025
CVE-2025-4949
5.3 MEDIUM

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 …

May 21, 2025
CVE-2021-25262
5.4 MEDIUM

Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.

May 21, 2025
CVE-2021-25254
5.3 MEDIUM

Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.

May 21, 2025
CVE-2025-5013
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the …

May 21, 2025
CVE-2025-4969
6.5 MEDIUM

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can …

May 21, 2025
CVE-2025-5000
6.3 MEDIUM

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the …

May 20, 2025
CVE-2025-4999
6.3 MEDIUM

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function sub_4153FC of …

May 20, 2025
CVE-2025-4998
6.5 MEDIUM

A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of …

May 20, 2025
CVE-2025-4997
6.5 MEDIUM

A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function UpdateWanParams/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList/Edit_BasicSSID/Edit_GuestSSIDFor2P4G/Edit_BasicSSID_5G/SetAPInfoById of the file /goform/aspForm of …

May 20, 2025
CVE-2025-48056
5.3 MEDIUM

Hubble is a fully distributed networking and security observability platform for cloud native workloads. Prior to version 1.17.2, a network attacker could inject malicious control …

May 20, 2025
CVE-2025-47290
5.9 MEDIUM

containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially …

May 20, 2025
CVE-2025-47854
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page

May 20, 2025
CVE-2025-47853
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible

May 20, 2025
CVE-2025-47852
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible

May 20, 2025
CVE-2025-47851
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible

May 20, 2025
CVE-2025-47850
4.3 MEDIUM

In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

May 20, 2025
CVE-2025-37990
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The function brcmf_usb_dl_writeimage() calls the function brcmf_usb_dl_cmd() …

May 20, 2025
CVE-2025-37989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: leds: fix memory leak A network restart test on a router led to …

May 20, 2025
CVE-2025-37988
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount() Normally do_lock_mount(path, _) is locking …

May 20, 2025
CVE-2025-37987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent possible adminq overflow/stuck condition The pds_core's adminq is protected by the adminq_lock, which …

May 20, 2025
CVE-2025-37986
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Invalidate USB device pointers on partner unregistration To avoid using invalid USB …

May 20, 2025
CVE-2025-37985
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wdm_open and wdm_wwan_port_stop Clearing WDM_WWAN_IN_USE must be the last action …

May 20, 2025
CVE-2025-37984
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow …

May 20, 2025
CVE-2025-37983
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: qibfs: fix _another_ leak failure to allocate inode => leaked dentry... this one had been …

May 20, 2025
CVE-2025-37982
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: fix memory leak in wl1251_tx_work The skb dequeued from tx_queue is lost when …

May 20, 2025
CVE-2025-37980
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix resource leak in blk_register_queue() error path When registering a queue fails after blk_mq_sysfs_register() …

May 20, 2025
CVE-2025-37978
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: integrity: Do not call set_page_dirty_lock() Placing multiple protection information buffers inside the same page …

May 20, 2025
CVE-2025-37977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set If dma-coherent property isn't set …

May 20, 2025
CVE-2025-37974
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix missing check for zpci_create_device() error return The zpci_create_device() function returns an error pointer …

May 20, 2025
CVE-2025-37972
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: mtk-pmic-keys - fix possible null pointer dereference In mtk_pmic_keys_probe, the regs parameter is only …

May 20, 2025
CVE-2025-37971
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: bcm2835-camera: Initialise dev in v4l2_dev Commit 42a2f6664e18 ("staging: vc04_services: Move global g_state to vchiq_state") …

May 20, 2025
CVE-2025-37970
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo Prevent st_lsm6dsx_read_fifo from falling in an infinite …

May 20, 2025
CVE-2025-37969
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo Prevent st_lsm6dsx_read_tagged_fifo from falling in an infinite …

May 20, 2025
CVE-2025-37968
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: light: opt3001: fix deadlock due to concurrent flag access The threaded IRQ function in …

May 20, 2025
CVE-2025-37967
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix deadlock This patch introduces the ucsi_con_mutex_lock / ucsi_con_mutex_unlock functions to …

May 20, 2025
CVE-2025-37966
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix kernel crash due to PR_SET_TAGGED_ADDR_CTRL When userspace does PR_SET_TAGGED_ADDR_CTRL, but Supm extension is …

May 20, 2025
CVE-2025-37965
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix invalid context error in dml helper [Why] "BUG: sleeping function called from invalid …

May 20, 2025
CVE-2025-48016
4.3 MEDIUM

OpenFlow discovery protocol can exhaust resources because it is not rate limited

May 20, 2025
CVE-2025-37964
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr: There is a window …

May 20, 2025
CVE-2025-37963
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users Support for eBPF programs loaded …

May 20, 2025
CVE-2025-37962
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leak in parse_lease_state() The previous patch that added bounds check for create …

May 20, 2025
CVE-2025-37961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix uninit-value for saddr in do_output_route4 syzbot reports for uninit-value for the saddr argument …

May 20, 2025
CVE-2025-37960
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memblock: Accept allocated memory before use in memblock_double_array() When increasing the array size in memblock_double_array() …

May 20, 2025
CVE-2025-37959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redirect packets to a device …

May 20, 2025
CVE-2025-37958
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix dereferencing invalid pmd migration entry When migrating a THP, concurrent access to the …

May 20, 2025
CVE-2025-37956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to ksmbd server. …

May 20, 2025
CVE-2025-37955
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable() The selftests added to our CI by Bui …

May 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.