CVE Database

46169+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6238
8.0 HIGH

The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' …

Jul 4, 2025
CVE-2025-5953
8.8 HIGH

The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and update_empoyee() functions in versions …

Jul 4, 2025
CVE-2025-5322
7.2 HIGH

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the do_updatecar and …

Jul 3, 2025
CVE-2025-49826
7.5 HIGH

Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading to a Denial of …

Jul 3, 2025
CVE-2025-53370
8.6 HIGH

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, short descriptions set via the ShortDescription …

Jul 3, 2025
CVE-2025-53369
8.6 HIGH

Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized before being inserted as …

Jul 3, 2025
CVE-2025-53368
8.6 HIGH

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw …

Jul 3, 2025
CVE-2025-34088
8.8 HIGH

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands …

Jul 3, 2025
CVE-2025-34087
8.8 HIGH

An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain …

Jul 3, 2025
CVE-2025-34086
8.8 HIGH

Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with …

Jul 3, 2025
CVE-2025-6926
8.8 HIGH

Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from …

Jul 3, 2025
CVE-2025-6073
7.5 HIGH

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to …

Jul 3, 2025
CVE-2025-6072
7.5 HIGH

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to …

Jul 3, 2025
CVE-2025-53501
8.8 HIGH

Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto …

Jul 3, 2025
CVE-2025-5961
7.2 HIGH

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

Jul 3, 2025
CVE-2025-50263
8.1 HIGH

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.

Jul 3, 2025
CVE-2025-50262
7.5 HIGH

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.

Jul 3, 2025
CVE-2025-50260
7.5 HIGH

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.

Jul 3, 2025
CVE-2025-50258
8.1 HIGH

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.

Jul 3, 2025
CVE-2025-2932
8.8 HIGH

The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' function in all versions up …

Jul 3, 2025
CVE-2025-27461
7.6 HIGH

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

Jul 3, 2025
CVE-2025-27460
7.6 HIGH

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access …

Jul 3, 2025
CVE-2025-27456
7.5 HIGH

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to …

Jul 3, 2025
CVE-2025-27449
7.5 HIGH

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

Jul 3, 2025
CVE-2025-27447
7.4 HIGH

The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is …

Jul 3, 2025
CVE-2025-1710
7.5 HIGH

The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force …

Jul 3, 2025
CVE-2025-1708
8.6 HIGH

The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content.

Jul 3, 2025
CVE-2025-38172
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: erofs: avoid using multiple devices with different type For multiple devices, both primary and extra …

Jul 3, 2025
CVE-2025-38159
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds Set the …

Jul 3, 2025
CVE-2025-38157
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k_htc: Abort software beacon handling if disabled A malicious USB device can send a …

Jul 3, 2025
CVE-2025-38154
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Avoid using sk_socket after free when sending The sk->sk_socket is not locked or …

Jul 3, 2025
CVE-2025-38153
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: fix error handling of usbnet read calls Syzkaller, courtesy of syzbot, identified …

Jul 3, 2025
CVE-2025-38146
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix the dead loop of MPLS parse The unexpected MPLS packet may not …

Jul 3, 2025
CVE-2025-38141
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm: fix dm_blk_report_zones If dm_get_live_table() returned NULL, dm_put_live_table() was never called. Also, it is possible …

Jul 3, 2025
CVE-2025-38139
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix oops in write-retry from mis-resetting the subreq iterator Fix the resetting of the …

Jul 3, 2025
CVE-2025-38137
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: Cancel outstanding rescan work when unregistering It's possible to trigger use-after-free here by: (a) …

Jul 3, 2025
CVE-2025-38133
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad4851: fix ad4858 chan pointer handling The pointer returned from ad4851_parse_channels_common() is incremented …

Jul 3, 2025
CVE-2025-38131
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: coresight: prevent deactivate active config while enabling the config While enable active config via cscfg_csdev_enable_active_config(), …

Jul 3, 2025
CVE-2025-38129
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix use-after-free in page_pool_recycle_in_ring syzbot reported a uaf in page_pool_recycle_in_ring: BUG: KASAN: slab-use-after-free in …

Jul 3, 2025
CVE-2025-38118
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete This reworks MGMT_OP_REMOVE_ADV_MONITOR to not use mgmt_pending_add to avoid …

Jul 3, 2025
CVE-2025-38117
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Protect mgmt_pending list with its own lock This uses a mutex to protect …

Jul 3, 2025
CVE-2025-38116
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix uaf in ath12k_core_init() When the execution of ath12k_core_hw_group_assign() or ath12k_core_hw_group_create() fails, the …

Jul 3, 2025
CVE-2025-38111
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mdiobus: Fix potential out-of-bounds read/write access When using publicly available tools like 'mdio-tools' to read/write …

Jul 3, 2025
CVE-2025-38110
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mdiobus: Fix potential out-of-bounds clause 45 read/write access When using publicly available tools like 'mdio-tools' …

Jul 3, 2025
CVE-2025-38109
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix ECVF vports unload on shutdown flow Fix shutdown flow UAF when a virtual …

Jul 3, 2025
CVE-2025-38108
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerrard Tai reported a race condition in RED, …

Jul 3, 2025
CVE-2025-38107
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: fix a race in ets_qdisc_change() Gerrard Tai reported a race condition in ETS, …

Jul 3, 2025
CVE-2025-38106
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix use-after-free of sq->thread in __io_uring_show_fdinfo() syzbot reports: BUG: KASAN: slab-use-after-free in getrusage+0x1109/0x1a60 Read …

Jul 3, 2025
CVE-2025-38103
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() Update struct hid_descriptor to better reflect the …

Jul 3, 2025
CVE-2025-38102
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify During our test, it is found that a …

Jul 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.