CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4531
6.3 MEDIUM

A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected by this issue is the …

May 11, 2025
CVE-2025-4530
4.3 MEDIUM

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. It has been declared as problematic. Affected by this vulnerability is the function handleFileDownload of …

May 11, 2025
CVE-2025-4529
4.3 MEDIUM

A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been classified as problematic. Affected is the function Download of …

May 11, 2025
CVE-2025-4528
4.3 MEDIUM

A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic. This issue affects some unknown processing. The manipulation leads to …

May 11, 2025
CVE-2025-47828
6.4 MEDIUM

Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.

May 11, 2025
CVE-2025-4526
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Dígitro NGC Explorer 3.44.15. This affects an unknown part of the component Configuration Page. The …

May 11, 2025
CVE-2025-47815
4.5 MEDIUM

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.

May 10, 2025
CVE-2025-47814
4.5 MEDIUM

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.

May 10, 2025
CVE-2025-4515
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The …

May 10, 2025
CVE-2025-4514
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Zhengzhou Jiuhua Electronic Technology mayicms up to 5.8E. Affected by this issue is some …

May 10, 2025
CVE-2025-4513
4.3 MEDIUM

A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of …

May 10, 2025
CVE-2025-4512
4.3 MEDIUM

A vulnerability classified as problematic has been found in Inetum IODAS 7.2-LTS.4.1-JDK7/7.2-RC3.2-JDK7. Affected is an unknown function of the file /astre/iodasweb/app.jsp. The manipulation of the …

May 10, 2025
CVE-2025-4511
6.3 MEDIUM

A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file …

May 10, 2025
CVE-2025-4510
6.3 MEDIUM

A vulnerability was found in Changjietong UFIDA CRM 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /optnty/optntyday.php. The …

May 10, 2025
CVE-2025-4501
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects the function searchalbum of the component Search Albums. …

May 10, 2025
CVE-2025-4500
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected by this issue is the function Edit of …

May 10, 2025
CVE-2025-4499
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component …

May 10, 2025
CVE-2025-3878
6.4 MEDIUM

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up …

May 10, 2025
CVE-2025-4498
5.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. …

May 10, 2025
CVE-2025-4497
5.3 MEDIUM

A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of …

May 10, 2025
CVE-2025-2944
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button and Countdown Widgets in all versions up …

May 10, 2025
CVE-2025-3794
5.4 MEDIUM

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 9, 2025
CVE-2025-1993
5.1 MEDIUM

IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, …

May 9, 2025
CVE-2025-4480
5.3 MEDIUM

A vulnerability was found in code-projects Simple College Management System 1.0. It has been declared as critical. This vulnerability affects the function input of the …

May 9, 2025
CVE-2025-1278
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions …

May 9, 2025
CVE-2025-0549
6.8 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 …

May 9, 2025
CVE-2024-8973
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 …

May 9, 2025
CVE-2025-4432
5.3 MEDIUM

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows …

May 9, 2025
CVE-2025-28201
6.8 MEDIUM

An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.

May 9, 2025
CVE-2025-4382
5.9 MEDIUM

A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys …

May 9, 2025
CVE-2025-3897
5.9 MEDIUM

The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' function. This makes …

May 9, 2025
CVE-2025-46392
6.5 MEDIUM

Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption …

May 9, 2025
CVE-2025-3949
4.3 MEDIUM

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of …

May 9, 2025
CVE-2025-4472
5.3 MEDIUM

A vulnerability was found in code-projects Departmental Store Management System 1.0. It has been classified as critical. Affected is the function bill. The manipulation of …

May 9, 2025
CVE-2025-4471
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Jewelery Store Management system 1.0. Affected by this issue is some unknown functionality …

May 9, 2025
CVE-2025-37889
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Consistently treat platform_max as control value This reverts commit 9bdd10d57a88 ("ASoC: ops: Shift …

May 9, 2025
CVE-2025-37888
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table() Add NULL check for mlx5_get_flow_namespace() returns in mlx5_create_inner_ttc_table() and mlx5_create_ttc_table() …

May 9, 2025
CVE-2025-37887
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result If the FW doesn't support the PDS_CORE_CMD_FW_CONTROL command the driver …

May 9, 2025
CVE-2025-37886
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: make wait_context part of q_info Make the wait_context a full part of the q_info …

May 9, 2025
CVE-2025-37884
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock between rcu_tasks_trace and event_mutex. Fix the following deadlock: CPU A _free_event() perf_kprobe_destroy() …

May 9, 2025
CVE-2025-37883
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Add check for get_zeroed_page() Add check for the return value of get_zeroed_page() in sclp_console_init() …

May 9, 2025
CVE-2025-37881
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name, returned by devm_kasprintf(), …

May 9, 2025
CVE-2025-37880
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: um: work around sched_yield not yielding in time-travel mode sched_yield by a userspace may not …

May 9, 2025
CVE-2025-37878
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init Move the get_ctx(child_ctx) call and the child_event->ctx …

May 9, 2025
CVE-2025-37877
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu: Clear iommu-dma ops on cleanup If iommu_device_register() encounters an error, it can end up …

May 9, 2025
CVE-2025-37876
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Only create /proc/fs/netfs with CONFIG_PROC_FS When testing a special config: CONFIG_NETFS_SUPPORTS=y CONFIG_PROC_FS=n The system …

May 9, 2025
CVE-2025-37875
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igc: fix PTM cycle trigger logic Writing to clear the PTM status 'valid' bit while …

May 9, 2025
CVE-2025-37874
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ngbe: fix memory leak in ngbe_probe() error path When ngbe_sw_init() is called, memory is …

May 9, 2025
CVE-2025-37873
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix missing ring index trim on error path Commit under Fixes converted tx_prod …

May 9, 2025
CVE-2025-37872
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix memory leak in txgbe_probe() error path When txgbe_sw_init() is called, memory is …

May 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.