CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23151
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix race between unprepare and queue_buf A client driver may use mhi_unprepare_from_transfer() …

May 1, 2025
CVE-2025-23150
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix off-by-one error in do_split Syzkaller detected a use-after-free issue in ext4_insert_dentry that was …

May 1, 2025
CVE-2025-23149
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tpm: do not start chip while suspended Checking TPM_CHIP_FLAG_SUSPENDED after the call to tpm_find_get_ops() can …

May 1, 2025
CVE-2025-23148
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: samsung: exynos-chipid: Add NULL pointer check in exynos_chipid_probe() soc_dev_attr->revision could be NULL, thus, a …

May 1, 2025
CVE-2025-23147
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i3c: Add NULL pointer check in i3c_master_queue_ibi() The I3C master driver may receive an IBI …

May 1, 2025
CVE-2025-23146
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mfd: ene-kb3930: Fix a potential NULL pointer dereference The off_gpios could be NULL. Add missing …

May 1, 2025
CVE-2025-23145
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_accept_new_subflow When testing valkey benchmark tool with MPTCP, the kernel …

May 1, 2025
CVE-2025-23144
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() Lockdep detects the following issue on led-backlight …

May 1, 2025
CVE-2025-23143
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. When I ran the repro [0] and waited …

May 1, 2025
CVE-2025-23141
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses Acquire a lock on …

May 1, 2025
CVE-2025-23140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error After devm_request_irq() fails with error …

May 1, 2025
CVE-2023-46669
6.2 MEDIUM

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint …

May 1, 2025
CVE-2025-4163
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. This issue affects some unknown processing of the file …

May 1, 2025
CVE-2025-3890
6.4 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and …

May 1, 2025
CVE-2025-3889
5.3 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the …

May 1, 2025
CVE-2025-3874
6.5 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to …

May 1, 2025
CVE-2025-1529
6.4 MEDIUM

The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all versions up to, and including, 3.5.3 due …

May 1, 2025
CVE-2025-4157
6.3 MEDIUM

A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-details.php. The …

May 1, 2025
CVE-2025-4156
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-image.php. The …

May 1, 2025
CVE-2025-4155
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/edit-boat.php. The …

May 1, 2025
CVE-2025-4154
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this issue is some unknown functionality of …

May 1, 2025
CVE-2025-4100
6.4 MEDIUM

The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_map' shortcode in all versions up to, and including, 2.0 …

May 1, 2025
CVE-2025-47153
6.5 MEDIUM

Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent …

May 1, 2025
CVE-2025-3521
6.4 MEDIUM

The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 1, 2025
CVE-2025-3504
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-3503
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-3502
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2024-13381
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-4099
6.4 MEDIUM

The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' shortcode in all versions up to, and including, 2.1 …

May 1, 2025
CVE-2024-13845
5.5 MEDIUM

The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'process_feed' method …

May 1, 2025
CVE-2025-2168
4.3 MEDIUM

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to …

May 1, 2025
CVE-2025-4143
6.1 MEDIUM

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of …

May 1, 2025
CVE-2024-30146
4.1 MEDIUM

Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

Apr 30, 2025
CVE-2024-30145
6.5 MEDIUM

Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

Apr 30, 2025
CVE-2024-30115
6.3 MEDIUM

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

Apr 30, 2025
CVE-2023-45721
5.3 MEDIUM

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

Apr 30, 2025
CVE-2022-42450
4.6 MEDIUM

Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

Apr 30, 2025
CVE-2025-30422
6.5 MEDIUM

A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker …

Apr 30, 2025
CVE-2025-24132
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on …

Apr 30, 2025
CVE-2022-42449
4.6 MEDIUM

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

Apr 30, 2025
CVE-2022-27562
4.6 MEDIUM

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

Apr 30, 2025
CVE-2025-4136
5.4 MEDIUM

A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the component Sale Endpoint. The …

Apr 30, 2025
CVE-2024-6029
5.0 MEDIUM

Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected …

Apr 30, 2025
CVE-2025-46554
5.3 MEDIUM

XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and …

Apr 30, 2025
CVE-2025-24887
6.3 MEDIUM

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user …

Apr 30, 2025
CVE-2024-9877
4.3 MEDIUM

: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through …

Apr 30, 2025
CVE-2025-4135
6.3 MEDIUM

A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The manipulation of …

Apr 30, 2025
CVE-2025-39413
4.3 MEDIUM

Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This issue affects Simple Sitemap – Create a Responsive HTML Sitemap: …

Apr 30, 2025
CVE-2025-24091
5.5 MEDIUM

An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An …

Apr 30, 2025
CVE-2025-3859
6.1 MEDIUM

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into …

Apr 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.