CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dpll: fix xa_alloc_cyclic() error handling In case of returning 1 from xa_alloc_cyclic() (wrapping) ERR_PTR(1) will …

Apr 8, 2025
CVE-2025-22015
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/migrate: fix shmem xarray update during migration A shmem folio can be either in page …

Apr 8, 2025
CVE-2025-22014
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: Fix the potential deadlock When some client process A call pdr_add_lookup() to …

Apr 8, 2025
CVE-2025-22013
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state There are several problems with the way hyp …

Apr 8, 2025
CVE-2025-22012
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: dts: qcom: sdm845: Affirm IDR0.CCTW on apps_smmu" There are reports that the pagetable …

Apr 8, 2025
CVE-2025-22011
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: dts: bcm2711: Fix xHCI power-domain During s2idle tests on the Raspberry CM4 the VPU …

Apr 8, 2025
CVE-2025-22010
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup during bt pages loop Driver runs a for-loop when allocating bt …

Apr 8, 2025
CVE-2025-22009
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: regulator: dummy: force synchronous probing Sometimes I get a NULL pointer dereference at boot time …

Apr 8, 2025
CVE-2025-22008
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: regulator: check that dummy regulator has been probed before using it Due to asynchronous driver …

Apr 8, 2025
CVE-2024-41796
6.5 MEDIUM

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password …

Apr 8, 2025
CVE-2024-41795
6.5 MEDIUM

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices is vulnerable to Cross-Site Request Forgery …

Apr 8, 2025
CVE-2025-31333
4.3 MEDIUM

SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact …

Apr 8, 2025
CVE-2025-31332
6.6 MEDIUM

Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting …

Apr 8, 2025
CVE-2025-31331
4.3 MEDIUM

SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged …

Apr 8, 2025
CVE-2025-30017
4.4 MEDIUM

Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After …

Apr 8, 2025
CVE-2025-30015
4.1 MEDIUM

Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could …

Apr 8, 2025
CVE-2025-30013
6.7 MEDIUM

SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle …

Apr 8, 2025
CVE-2025-2882
5.3 MEDIUM

The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between 3.0.0 and 3.0.9 through the publicly accessible phpinfo.php script. …

Apr 8, 2025
CVE-2025-27437
4.3 MEDIUM

A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a …

Apr 8, 2025
CVE-2025-27435
4.2 MEDIUM

Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP …

Apr 8, 2025
CVE-2025-26657
5.3 MEDIUM

SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information causing low impact on …

Apr 8, 2025
CVE-2025-26654
6.8 MEDIUM

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 …

Apr 8, 2025
CVE-2025-26653
4.7 MEDIUM

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any …

Apr 8, 2025
CVE-2025-3430
4.9 MEDIUM

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up to, and including, 2.1.3.6 due to …

Apr 8, 2025
CVE-2025-3429
4.9 MEDIUM

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to …

Apr 8, 2025
CVE-2025-3428
4.9 MEDIUM

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up to, and including, 2.1.3.6 due to …

Apr 8, 2025
CVE-2025-3427
4.9 MEDIUM

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up to, and including, 2.1.3.6 due to …

Apr 8, 2025
CVE-2019-25223
4.9 MEDIUM

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and …

Apr 8, 2025
CVE-2025-3413
6.3 MEDIUM

A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function code of the …

Apr 8, 2025
CVE-2025-3412
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown function of the file 2_training_platform/train-platform/src/main/java/top/aias/training/controller/InferController.java. The manipulation of …

Apr 8, 2025
CVE-2025-0361
4.3 MEDIUM

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated …

Apr 8, 2025
CVE-2024-47261
4.3 MEDIUM

51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow …

Apr 8, 2025
CVE-2025-3411
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some unknown processing of the file 3_api_platform/api-platform/src/main/java/top/aias/platform/controller/AsrController.java. The …

Apr 8, 2025
CVE-2025-3410
6.3 MEDIUM

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java. The manipulation of the argument …

Apr 8, 2025
CVE-2025-3409
6.3 MEDIUM

A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argument path_to_includes …

Apr 8, 2025
CVE-2025-20951
5.1 MEDIUM

Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege …

Apr 8, 2025
CVE-2025-20950
4.0 MEDIUM

Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.

Apr 8, 2025
CVE-2025-20948
5.5 MEDIUM

Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

Apr 8, 2025
CVE-2025-20947
5.5 MEDIUM

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. …

Apr 8, 2025
CVE-2025-20945
4.0 MEDIUM

Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

Apr 8, 2025
CVE-2025-20944
6.2 MEDIUM

Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.

Apr 8, 2025
CVE-2025-20943
6.4 MEDIUM

Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.

Apr 8, 2025
CVE-2025-20942
4.4 MEDIUM

Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.

Apr 8, 2025
CVE-2025-20941
6.2 MEDIUM

Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.

Apr 8, 2025
CVE-2025-20940
4.0 MEDIUM

Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.

Apr 8, 2025
CVE-2025-20939
5.4 MEDIUM

Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch …

Apr 8, 2025
CVE-2025-20938
5.5 MEDIUM

Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.

Apr 8, 2025
CVE-2025-20935
5.5 MEDIUM

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User …

Apr 8, 2025
CVE-2025-20934
5.5 MEDIUM

Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.

Apr 8, 2025
CVE-2024-13820
5.3 MEDIUM

The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.15.11 via the 'run' function, which …

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.