CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20970
6.2 MEDIUM

Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to …

May 7, 2025
CVE-2025-20969
5.5 MEDIUM

Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows …

May 7, 2025
CVE-2025-20967
5.1 MEDIUM

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows …

May 7, 2025
CVE-2025-20966
4.6 MEDIUM

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows …

May 7, 2025
CVE-2025-20965
6.2 MEDIUM

Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.

May 7, 2025
CVE-2025-20964
6.6 MEDIUM

Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

May 7, 2025
CVE-2025-20963
6.6 MEDIUM

Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

May 7, 2025
CVE-2025-20962
4.0 MEDIUM

Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

May 7, 2025
CVE-2025-20961
5.5 MEDIUM

Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system …

May 7, 2025
CVE-2025-20960
4.0 MEDIUM

Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

May 7, 2025
CVE-2025-20959
5.1 MEDIUM

Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.

May 7, 2025
CVE-2025-20958
4.4 MEDIUM

Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.

May 7, 2025
CVE-2025-20956
4.3 MEDIUM

Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.

May 7, 2025
CVE-2025-20955
5.5 MEDIUM

Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.

May 7, 2025
CVE-2025-20954
5.5 MEDIUM

Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is …

May 7, 2025
CVE-2025-20953
5.1 MEDIUM

Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.

May 7, 2025
CVE-2025-20949
5.1 MEDIUM

Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.

May 7, 2025
CVE-2025-20937
6.7 MEDIUM

Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

May 7, 2025
CVE-2025-4171
6.4 MEDIUM

The WZ Followed Posts – Display what visitors are reading plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wfp' shortcode in …

May 7, 2025
CVE-2025-0667
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.

May 7, 2025
CVE-2025-0666
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.

May 7, 2025
CVE-2024-12120
5.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up …

May 7, 2025
CVE-2025-32404
4.8 MEDIUM

An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by …

May 7, 2025
CVE-2025-32403
4.8 MEDIUM

An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by …

May 7, 2025
CVE-2025-32401
4.8 MEDIUM

An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library …

May 7, 2025
CVE-2025-32399
5.3 MEDIUM

An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices that use the library to …

May 7, 2025
CVE-2025-3766
5.4 MEDIUM

The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in …

May 7, 2025
CVE-2025-4220
6.4 MEDIUM

The Xavin's List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls' shortcode in all versions up to, and including, …

May 7, 2025
CVE-2025-4055
6.4 MEDIUM

The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' shortcode in all versions up to, and …

May 7, 2025
CVE-2025-4054
6.1 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and …

May 7, 2025
CVE-2025-3924
5.3 MEDIUM

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password endpoint. The plugin looks up …

May 7, 2025
CVE-2025-3860
6.4 MEDIUM

The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in all versions up to, and including, 6.8.2505.00 due to …

May 7, 2025
CVE-2025-3853
6.5 MEDIUM

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.6.0 via the callback_generate_api_key() due to …

May 7, 2025
CVE-2025-3851
4.3 MEDIUM

The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 1.1.0 to …

May 7, 2025
CVE-2025-2821
5.3 MEDIUM

The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_rest_permission function in all …

May 7, 2025
CVE-2025-3218
5.4 MEDIUM

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A …

May 7, 2025
CVE-2025-47256
5.6 MEDIUM

Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.

May 6, 2025
CVE-2025-4388
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, …

May 6, 2025
CVE-2025-44900
6.5 MEDIUM

In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter mac leads to stack overflow.

May 6, 2025
CVE-2025-37730
6.5 MEDIUM

Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not …

May 6, 2025
CVE-2025-46736
5.3 MEDIUM

Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of …

May 6, 2025
CVE-2025-45250
5.5 MEDIUM

MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.

May 6, 2025
CVE-2025-32022
4.6 MEDIUM

Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot which leads to it overwriting other parts …

May 6, 2025
CVE-2025-26262
6.5 MEDIUM

An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a …

May 6, 2025
CVE-2025-22476
5.5 MEDIUM

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

May 6, 2025
CVE-2023-33770
5.1 MEDIUM

Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php.

May 6, 2025
CVE-2025-4374
6.5 MEDIUM

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been …

May 6, 2025
CVE-2025-4373
4.8 MEDIUM

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the …

May 6, 2025
CVE-2025-4357
4.7 MEDIUM

A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /goform/telnet. The …

May 6, 2025
CVE-2025-4353
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424. Affected is an unknown function of the …

May 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.