CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3408
6.3 MEDIUM

A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The …

Apr 8, 2025
CVE-2025-3407
6.3 MEDIUM

A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerability is the function stbhw_build_tileset_from_image. The …

Apr 8, 2025
CVE-2025-3406
4.3 MEDIUM

A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function stbhw_build_tileset_from_image of the component Header …

Apr 8, 2025
CVE-2025-3405
4.3 MEDIUM

A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Apr 8, 2025
CVE-2025-3402
6.3 MEDIUM

A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform 5.5.2 and classified as critical. This issue affects some unknown processing of the …

Apr 8, 2025
CVE-2025-3364
6.7 MEDIUM

The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire …

Apr 8, 2025
CVE-2025-32414
5.6 MEDIUM

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. …

Apr 8, 2025
CVE-2025-32413
6.4 MEDIUM

Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.

Apr 8, 2025
CVE-2025-3398
6.3 MEDIUM

A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang/config/WebSecurityConfig.java. …

Apr 8, 2025
CVE-2025-3397
4.3 MEDIUM

A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument …

Apr 8, 2025
CVE-2025-2519
6.5 MEDIUM

The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file …

Apr 8, 2025
CVE-2025-3388
4.3 MEDIUM

A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the …

Apr 7, 2025
CVE-2025-3382
6.3 MEDIUM

A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and classified as critical. This vulnerability affects the function update of the file /api/user/update. …

Apr 7, 2025
CVE-2025-3381
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component …

Apr 7, 2025
CVE-2025-29769
5.5 MEDIUM

libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when …

Apr 7, 2025
CVE-2025-29594
6.1 MEDIUM

A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter …

Apr 7, 2025
CVE-2025-29482
6.2 MEDIUM

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.

Apr 7, 2025
CVE-2025-29481
6.2 MEDIUM

Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by …

Apr 7, 2025
CVE-2025-29480
5.5 MEDIUM

Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that …

Apr 7, 2025
CVE-2025-29478
5.5 MEDIUM

An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.

Apr 7, 2025
CVE-2024-46494
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter …

Apr 7, 2025
CVE-2024-38797
4.6 MEDIUM

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent …

Apr 7, 2025
CVE-2025-28401
6.7 MEDIUM

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter

Apr 7, 2025
CVE-2025-28400
6.7 MEDIUM

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method

Apr 7, 2025
CVE-2025-31476
4.8 MEDIUM

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source …

Apr 7, 2025
CVE-2025-31475
5.5 MEDIUM

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom …

Apr 7, 2025
CVE-2025-31138
5.5 MEDIUM

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and …

Apr 7, 2025
CVE-2025-30373
6.5 MEDIUM

Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present …

Apr 7, 2025
CVE-2025-3369
6.3 MEDIUM

A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Apr 7, 2025
CVE-2025-2251
6.2 MEDIUM

A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted …

Apr 7, 2025
CVE-2025-3359
6.2 MEDIUM

A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.

Apr 7, 2025
CVE-2025-0050
5.9 MEDIUM

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, …

Apr 7, 2025
CVE-2025-3348
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerability affects unknown code of the file /edit_dpatient.php. The manipulation …

Apr 7, 2025
CVE-2025-21431
5.5 MEDIUM

Information disclosure may be there when a guest VM is connected.

Apr 7, 2025
CVE-2024-49848
6.7 MEDIUM

Memory corruption while processing multiple IOCTL calls from HLOS to DSP.

Apr 7, 2025
CVE-2024-45556
6.5 MEDIUM

Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.

Apr 7, 2025
CVE-2024-45551
6.2 MEDIUM

Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.

Apr 7, 2025
CVE-2024-45544
6.6 MEDIUM

Memory corruption while processing IOCTL calls to add route entry in the HW.

Apr 7, 2025
CVE-2024-45543
6.6 MEDIUM

Memory corruption while accessing MSM channel map and mixer functions.

Apr 7, 2025
CVE-2024-45540
6.6 MEDIUM

Memory corruption while invoking IOCTL map buffer request from userspace.

Apr 7, 2025
CVE-2024-43046
5.5 MEDIUM

There may be information disclosure during memory re-allocation in TZ Secure OS.

Apr 7, 2025
CVE-2025-3347
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_pending.php. The …

Apr 7, 2025
CVE-2025-31174
6.8 MEDIUM

Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 7, 2025
CVE-2025-31171
6.8 MEDIUM

File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 7, 2025
CVE-2025-20662
6.7 MEDIUM

In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege …

Apr 7, 2025
CVE-2025-20661
6.7 MEDIUM

In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege …

Apr 7, 2025
CVE-2025-20660
6.7 MEDIUM

In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege …

Apr 7, 2025
CVE-2025-20659
6.5 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Apr 7, 2025
CVE-2025-20658
6.0 MEDIUM

In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has …

Apr 7, 2025
CVE-2025-20657
6.7 MEDIUM

In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor …

Apr 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.