CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21018
4.4 MEDIUM

Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.

Aug 6, 2025
CVE-2025-21017
6.3 MEDIUM

Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

Aug 6, 2025
CVE-2025-21016
4.3 MEDIUM

Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allows local attackers to use the …

Aug 6, 2025
CVE-2025-21015
4.0 MEDIUM

Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

Aug 6, 2025
CVE-2025-21014
4.3 MEDIUM

Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.

Aug 6, 2025
CVE-2025-21013
6.2 MEDIUM

Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise …

Aug 6, 2025
CVE-2025-21012
5.5 MEDIUM

Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.

Aug 6, 2025
CVE-2025-21011
5.5 MEDIUM

Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and …

Aug 6, 2025
CVE-2025-21010
6.0 MEDIUM

Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.

Aug 6, 2025
CVE-2025-20990
4.0 MEDIUM

Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.

Aug 6, 2025
CVE-2025-8100
5.4 MEDIUM

The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and …

Aug 6, 2025
CVE-2025-7498
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, …

Aug 6, 2025
CVE-2025-7399
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all versions up to, and including, 28.1.3 due …

Aug 6, 2025
CVE-2025-54651
4.8 MEDIUM

Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54650
4.2 MEDIUM

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

Aug 6, 2025
CVE-2025-54649
4.5 MEDIUM

Vulnerability of using incompatible types to access resources in the location service. Impact: Successful exploitation of this vulnerability may cause some location information attributes to …

Aug 6, 2025
CVE-2025-54648
5.4 MEDIUM

Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54647
5.4 MEDIUM

Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54646
5.1 MEDIUM

Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance.

Aug 6, 2025
CVE-2025-54645
5.0 MEDIUM

Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54644
6.6 MEDIUM

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54643
6.6 MEDIUM

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54642
6.7 MEDIUM

Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54641
6.7 MEDIUM

Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54640
5.5 MEDIUM

ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.

Aug 6, 2025
CVE-2025-54639
5.5 MEDIUM

ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.

Aug 6, 2025
CVE-2025-8595
4.3 MEDIUM

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up …

Aug 6, 2025
CVE-2025-54638
5.5 MEDIUM

Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability may affect the availability of the ad service.

Aug 6, 2025
CVE-2025-54637
4.4 MEDIUM

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54636
4.4 MEDIUM

Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54635
5.9 MEDIUM

Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54633
6.7 MEDIUM

Out-of-bounds read vulnerability in the register configuration of the DMA module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54632
6.8 MEDIUM

Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Aug 6, 2025
CVE-2025-54631
6.7 MEDIUM

Vulnerability of insufficient data length verification in the partition module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54630
6.8 MEDIUM

:Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54629
6.7 MEDIUM

Race condition issue occurring in the physical page import process of the memory management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Aug 6, 2025
CVE-2025-54628
5.3 MEDIUM

Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54626
4.4 MEDIUM

Pointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect function stability.

Aug 6, 2025
CVE-2025-54625
6.7 MEDIUM

Race condition vulnerability in the kernel file system module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54624
5.7 MEDIUM

Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-8656
6.8 MEDIUM

Kenwood DMX958XR Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows physically present attackers to downgrade software on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8655
6.8 MEDIUM

Kenwood DMX958XR libSystemLib Command injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR …

Aug 6, 2025
CVE-2025-8652
6.8 MEDIUM

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR …

Aug 6, 2025
CVE-2025-8651
6.8 MEDIUM

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR …

Aug 6, 2025
CVE-2025-8650
6.8 MEDIUM

Kenwood DMX958XR libSystemLib Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR …

Aug 6, 2025
CVE-2025-8649
6.8 MEDIUM

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR …

Aug 6, 2025
CVE-2025-8648
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8647
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8646
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8645
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.