CVE Database

46388+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5006
7.3 HIGH

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/category.php. …

May 20, 2025
CVE-2025-5004
7.3 HIGH

A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add_course.php. …

May 20, 2025
CVE-2025-5003
7.3 HIGH

A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /semester_ajax.php. …

May 20, 2025
CVE-2025-5002
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. …

May 20, 2025
CVE-2025-48391
7.7 HIGH

In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

May 20, 2025
CVE-2025-37991
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that on parisc a SIGFPE exception will crash …

May 20, 2025
CVE-2025-22157
8.8 HIGH

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, …

May 20, 2025
CVE-2025-37981
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Use is_kdump_kernel() to check for kdump The smartpqi driver checks the reset_devices variable …

May 20, 2025
CVE-2025-37979
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix sc7280 lpass potential buffer overflow Case values introduced in commit 5f78e1fb7a3e ("ASoC: …

May 20, 2025
CVE-2025-37975
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv: module: Fix out-of-bounds relocation access The current code allows rel[j] to access one element …

May 20, 2025
CVE-2025-37973
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation Currently during the multi-link element defragmentation …

May 20, 2025
CVE-2025-48018
7.5 HIGH

An authenticated user can modify application state data.

May 20, 2025
CVE-2025-48014
7.5 HIGH

Password guessing limits could be bypassed when using LDAP authentication.

May 20, 2025
CVE-2025-37957
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception Previously, commit ed129ec9057f ("KVM: x86: forcibly …

May 20, 2025
CVE-2025-37952
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file …

May 20, 2025
CVE-2025-37947
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write …

May 20, 2025
CVE-2025-37946
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs With commit bcb5d6c76903 ("s390/pci: …

May 20, 2025
CVE-2025-37944
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process Currently, ath12k_dp_mon_srng_process uses ath12k_hal_srng_src_get_next_entry to fetch the …

May 20, 2025
CVE-2025-37943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets …

May 20, 2025
CVE-2025-37934
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Fix pointer check in graph_util_parse_link_direction Actually check if the passed pointers are valid, …

May 20, 2025
CVE-2025-37928
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and …

May 20, 2025
CVE-2025-37927
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid There is a string parsing logic error which …

May 20, 2025
CVE-2025-37926
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_session_rpc_open A UAF issue can occur due to a race condition …

May 20, 2025
CVE-2025-37923
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix oob write in trace_seq_to_buffer() syzbot reported this bug: ================================================================== BUG: KASAN: slab-out-of-bounds in …

May 20, 2025
CVE-2025-37921
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vxlan: vnifilter: Fix unlocked deletion of default FDB entry When a VNI is deleted from …

May 20, 2025
CVE-2025-37916
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: pds_core: remove write-after-free of client_id A use-after-free error popped up in stress testing: [Mon Apr …

May 20, 2025
CVE-2025-37915
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: net_sched: drr: Fix double list add in class with netem as child qdisc As described …

May 20, 2025
CVE-2025-37914
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: Fix double list add in class with netem as child qdisc As described …

May 20, 2025
CVE-2025-37913
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net_sched: qfq: Fix double list add in class with netem as child qdisc As described …

May 20, 2025
CVE-2025-37908
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm, slab: clean up slab->obj_exts always When memory allocation profiling is disabled at runtime or …

May 20, 2025
CVE-2025-37903
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix slab-use-after-free in hdcp The HDCP code in amdgpu_dm_hdcp.c copies pointers to amdgpu_dm_connector objects …

May 20, 2025
CVE-2025-37899
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by …

May 20, 2025
CVE-2025-41225
8.8 HIGH

The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this …

May 20, 2025
CVE-2025-26086
7.5 HIGH

An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely …

May 20, 2025
CVE-2025-47941
7.2 HIGH

TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch …

May 20, 2025
CVE-2025-47940
7.2 HIGH

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, …

May 20, 2025
CVE-2024-53359
7.5 HIGH

An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.

May 20, 2025
CVE-2025-41231
7.3 HIGH

VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised …

May 20, 2025
CVE-2025-41230
7.5 HIGH

VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue …

May 20, 2025
CVE-2025-41229
8.2 HIGH

VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue …

May 20, 2025
CVE-2025-30193
7.5 HIGH

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker …

May 20, 2025
CVE-2025-37892
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mtd: inftlcore: Add error check for inftl_read_oob() In INFTL_findwriteunit(), the return value of inftl_read_oob() need …

May 20, 2025
CVE-2025-2929
7.1 HIGH

The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 20, 2025
CVE-2025-3079
8.7 HIGH

A passback vulnerability which relates to office/small office multifunction printers and laser printers.

May 20, 2025
CVE-2025-3078
8.7 HIGH

A passback vulnerability which relates to production printers and office multifunction printers.

May 20, 2025
CVE-2025-47949
7.5 HIGH

samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker …

May 19, 2025
CVE-2025-47944
7.5 HIGH

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.0 allows an attacker …

May 19, 2025
CVE-2025-47935
7.5 HIGH

Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource exhaustion and memory leak issue due to improper …

May 19, 2025
CVE-2025-39393
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital Management System hospital-management allows Reflected XSS.This issue affects Hospital Management System: …

May 19, 2025
CVE-2025-39392
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS apartment-management allows Reflected XSS.This issue affects WPAMS: from n/a through <= …

May 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.