CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38545
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix skb size by accounting for skb_shared_info While transitioning from netdev_alloc_ip_align() …

Aug 16, 2025
CVE-2025-38544
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix bug due to prealloc collision When userspace is using AF_RXRPC to provide a …

Aug 16, 2025
CVE-2025-38543
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/tegra: nvdec: Fix dma_alloc_coherent error check Check for NULL return value with dma_alloc_coherent, in line …

Aug 16, 2025
CVE-2025-38542
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix device refcount leak in atrtr_create() When updating an existing route entry in …

Aug 16, 2025
CVE-2025-38541
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init() devm_kasprintf() returns NULL on error. Currently, mt7925_thermal_init() does …

Aug 16, 2025
CVE-2025-38540
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras The Chicony Electronics HP …

Aug 16, 2025
CVE-2025-38539
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Add down_write(trace_event_sem) when adding trace event When a module is loaded, it adds trace …

Aug 16, 2025
CVE-2025-38537
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: Don't register LEDs for genphy If a PHY has no driver, the genphy …

Aug 16, 2025
CVE-2025-38534
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix copy-to-cache so that it performs collection with ceph+fscache The netfs copy-to-cache that is …

Aug 16, 2025
CVE-2025-38532
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: libwx: properly reset Rx ring descriptor When device reset is triggered by feature changes …

Aug 16, 2025
CVE-2025-38531
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: common: st_sensors: Fix use of uninitialize device structs Throughout the various probe functions &indio_dev->dev …

Aug 16, 2025
CVE-2025-38528
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject %p% format string in bprintf-like helpers static const char fmt[] = "%p%"; bpf_trace_printk(fmt, …

Aug 16, 2025
CVE-2025-38526
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: add NULL check in eswitch lag check The function ice_lag_is_switchdev_running() is being called from …

Aug 16, 2025
CVE-2025-38525
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix irq-disabled in local_bh_enable() The rxrpc_assess_MTU_size() function calls down into the IP layer to …

Aug 16, 2025
CVE-2025-38524
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recv-recv race of completed call If a call receives an event (such as …

Aug 16, 2025
CVE-2025-38523
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix the smbd_response slab to allow usercopy The handling of received data in the …

Aug 16, 2025
CVE-2025-38522
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/ext: Prevent update_locked_rq() calls with NULL rq Avoid invoking update_locked_rq() when the runqueue (rq) pointer …

Aug 16, 2025
CVE-2025-38520
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Don't call mmput from MMU notifier callback If the process is exiting, the mmput …

Aug 16, 2025
CVE-2025-38519
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/damon: fix divide by zero in damon_get_intervals_score() The current implementation allows having zero size regions …

Aug 16, 2025
CVE-2025-38518
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Disable INVLPGB on Zen2 AMD Cyan Skillfish (Family 17h, Model 47h, Stepping 0h) has …

Aug 16, 2025
CVE-2025-38517
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: lib/alloc_tag: do not acquire non-existent lock in alloc_tag_top_users() alloc_tag_top_users() attempts to lock alloc_tag_cttype->mod_lock even when …

Aug 16, 2025
CVE-2025-38516
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: qcom: msm: mark certain pins as invalid for interrupts On some platforms, the UFS-reset …

Aug 16, 2025
CVE-2025-38515
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Increment job count before swapping tail spsc queue A small race exists between spsc_queue_push …

Aug 16, 2025
CVE-2025-38514
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix oops due to non-existence of prealloc backlog struct If an AF_RXRPC service socket …

Aug 16, 2025
CVE-2025-38513
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() There is a potential NULL pointer …

Aug 16, 2025
CVE-2025-38511
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Clear all LMTT pages on alloc Our LMEM buffer objects are not cleared by …

Aug 16, 2025
CVE-2025-38510
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: kasan: remove kasan_find_vm_area() to prevent possible deadlock find_vm_area() couldn't be called in atomic_context. If find_vm_area() …

Aug 16, 2025
CVE-2025-38509
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reject VHT opmode for unsupported channel widths VHT operating mode notifications are not …

Aug 16, 2025
CVE-2025-38508
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/sev: Use TSC_FACTOR for Secure TSC frequency calculation When using Secure TSC, the GUEST_TSC_FREQ MSR …

Aug 16, 2025
CVE-2025-38507
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: avoid bluetooth suspend/resume stalls Ensure we don't stall or panic the kernel when …

Aug 16, 2025
CVE-2025-38506
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: Allow CPU to reschedule while setting per-page memory attributes When running an SEV-SNP guest …

Aug 16, 2025
CVE-2025-38505
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: discard erroneous disassoc frames on STA interface When operating in concurrent STA/AP mode …

Aug 16, 2025
CVE-2025-38504
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix pp destruction warnings With multiple page pools and in some other cases we …

Aug 16, 2025
CVE-2025-38503
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix assertion when building free space tree When building the free space tree with …

Aug 16, 2025
CVE-2025-8719
6.4 MEDIUM

The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_lang’ parameter in all versions up to, and including, …

Aug 16, 2025
CVE-2025-8464
5.3 MEDIUM

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and …

Aug 16, 2025
CVE-2025-7499
5.3 MEDIUM

The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is …

Aug 16, 2025
CVE-2025-8896
6.4 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 16, 2025
CVE-2025-8089
5.4 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due …

Aug 16, 2025
CVE-2025-8113
6.1 MEDIUM

The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected …

Aug 16, 2025
CVE-2025-8293
6.4 MEDIUM

The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all versions up to, and including, 1.0.1 …

Aug 16, 2025
CVE-2025-7686
6.1 MEDIUM

The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or …

Aug 16, 2025
CVE-2025-7684
6.1 MEDIUM

The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due …

Aug 16, 2025
CVE-2025-7683
6.1 MEDIUM

The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1. This is due to missing or …

Aug 16, 2025
CVE-2025-7668
6.1 MEDIUM

The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to …

Aug 16, 2025
CVE-2025-7651
6.4 MEDIUM

The Earnware Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ew_hasrole' shortcode in all versions up to, and including, 1.0.74 …

Aug 16, 2025
CVE-2025-7649
6.4 MEDIUM

The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'recent-comments' shortcode in all versions up to, …

Aug 16, 2025
CVE-2025-7440
6.4 MEDIUM

The Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $item['button_link']['url'] parameter in all versions up to, and including, 1.0.1 …

Aug 16, 2025
CVE-2025-7439
6.4 MEDIUM

Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $anber_item['button_link']['url']’ parameter in all versions up to, and including, 1.0.1 to …

Aug 16, 2025
CVE-2025-6221
6.4 MEDIUM

The Embed Bokun plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 0.23 due …

Aug 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.