CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38242
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: userfaultfd: fix race of userfaultfd_move and swap cache This commit fixes two kinds of …

Jul 9, 2025
CVE-2025-38241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/shmem, swap: fix softlockup with mTHP swapin Following softlockup can be easily reproduced on my …

Jul 9, 2025
CVE-2025-38238
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out When both the RHBA and …

Jul 9, 2025
CVE-2025-27028
6.8 MEDIUM

The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging …

Jul 9, 2025
CVE-2025-27027
4.1 MEDIUM

A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of …

Jul 9, 2025
CVE-2025-7059
6.4 MEDIUM

The Simple Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slideshow’ parameter in all versions up to, and including, 1.3.1 …

Jul 9, 2025
CVE-2025-7213
6.4 MEDIUM

A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The …

Jul 9, 2025
CVE-2025-7212
6.3 MEDIUM

A vulnerability was found in itsourcecode Insurance Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing of …

Jul 9, 2025
CVE-2025-7210
6.3 MEDIUM

A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 9, 2025
CVE-2025-5678
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘redirectURL’ parameter …

Jul 9, 2025
CVE-2025-7208
5.5 MEDIUM

A vulnerability was found in 9fans plan9port up to 9da5b44. It has been classified as critical. This affects the function edump in the library /src/plan9port/src/libsec/port/x509.c. …

Jul 9, 2025
CVE-2025-3780
6.5 MEDIUM

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to …

Jul 9, 2025
CVE-2025-7200
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in krishna9772 Pharmacy Management System up to a2efc8442931ec9308f3b4cf4778e5701153f4e5. Affected is an unknown function of the file …

Jul 8, 2025
CVE-2025-47120
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. Exploitation of …

Jul 8, 2025
CVE-2025-47119
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

Jul 8, 2025
CVE-2025-49547
5.4 MEDIUM

Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jul 8, 2025
CVE-2025-49534
5.4 MEDIUM

Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jul 8, 2025
CVE-2025-49525
5.5 MEDIUM

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue …

Jul 8, 2025
CVE-2025-49524
5.5 MEDIUM

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this …

Jul 8, 2025
CVE-2025-30313
5.5 MEDIUM

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue …

Jul 8, 2025
CVE-2025-27165
5.5 MEDIUM

Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Jul 8, 2025
CVE-2025-7031
5.3 MEDIUM

Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from …

Jul 8, 2025
CVE-2025-7030
6.5 MEDIUM

Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from …

Jul 8, 2025
CVE-2025-49545
6.2 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A …

Jul 8, 2025
CVE-2025-49544
6.8 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a …

Jul 8, 2025
CVE-2025-49543
4.3 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to …

Jul 8, 2025
CVE-2025-49542
5.2 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a …

Jul 8, 2025
CVE-2025-49541
4.3 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to …

Jul 8, 2025
CVE-2025-49540
4.3 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to …

Jul 8, 2025
CVE-2025-49539
4.5 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a …

Jul 8, 2025
CVE-2025-43584
5.5 MEDIUM

Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Jul 8, 2025
CVE-2025-43583
5.5 MEDIUM

Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

Jul 8, 2025
CVE-2025-7192
6.3 MEDIUM

A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of …

Jul 8, 2025
CVE-2025-7190
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The …

Jul 8, 2025
CVE-2025-48386
6.3 MEDIUM

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. …

Jul 8, 2025
CVE-2025-27369
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST …

Jul 8, 2025
CVE-2025-27367
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness …

Jul 8, 2025
CVE-2024-49784
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If …

Jul 8, 2025
CVE-2024-49783
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If an authenticated remote attacker with access …

Jul 8, 2025
CVE-2023-43039
6.1 MEDIUM

IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jul 8, 2025
CVE-2025-7363
5.4 MEDIUM

The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an …

Jul 8, 2025
CVE-2025-7362
5.4 MEDIUM

The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted into the DOM without proper sanitization. The …

Jul 8, 2025
CVE-2025-7189
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the …

Jul 8, 2025
CVE-2025-7188
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The …

Jul 8, 2025
CVE-2025-53479
5.4 MEDIUM

The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. This message is rendered without proper escaping, making it possible to …

Jul 8, 2025
CVE-2025-4663
4.9 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service …

Jul 8, 2025
CVE-2025-47135
5.5 MEDIUM

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Jul 8, 2025
CVE-2025-7187
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The manipulation of …

Jul 8, 2025
CVE-2025-7186
6.3 MEDIUM

A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_chat.php. …

Jul 8, 2025
CVE-2025-53512
6.5 MEDIUM

The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.