CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31179
6.2 MEDIUM

A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

Mar 27, 2025
CVE-2025-31178
6.2 MEDIUM

A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-31176
6.2 MEDIUM

A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.

Mar 27, 2025
CVE-2025-30221
4.3 MEDIUM

Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with …

Mar 27, 2025
CVE-2025-2854
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file update_employee.php. …

Mar 27, 2025
CVE-2025-29497
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.

Mar 27, 2025
CVE-2025-29496
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29494
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29493
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29492
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.

Mar 27, 2025
CVE-2025-29491
6.5 MEDIUM

An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.

Mar 27, 2025
CVE-2025-29490
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29489
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.

Mar 27, 2025
CVE-2025-29488
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.

Mar 27, 2025
CVE-2025-29486
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.

Mar 27, 2025
CVE-2025-29485
6.5 MEDIUM

libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via …

Mar 27, 2025
CVE-2025-29483
6.5 MEDIUM

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.

Mar 27, 2025
CVE-2025-22671
4.3 MEDIUM

Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation disable-elementor-editor-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from …

Mar 27, 2025
CVE-2025-22670
6.5 MEDIUM

Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VikBooking Hotel Booking …

Mar 27, 2025
CVE-2025-22669
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Cross Site Request Forgery.This issue affects Awesome Event Booking: from n/a through <= …

Mar 27, 2025
CVE-2025-22668
6.5 MEDIUM

Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Event Booking: from n/a through …

Mar 27, 2025
CVE-2025-22667
4.3 MEDIUM

Missing Authorization vulnerability in Creative Werk Designs Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets wpsyncsheets-woocommerce.This issue affects Export Order, Product, Customer …

Mar 27, 2025
CVE-2025-22665
4.3 MEDIUM

Missing Authorization vulnerability in Shakeeb Sadikeen RapidLoad unusedcss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RapidLoad: from n/a through <= 2.4.4.

Mar 27, 2025
CVE-2025-22660
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wolfgang Include Mastodon Feed include-mastodon-feed allows DOM-Based XSS.This issue affects Include Mastodon Feed: …

Mar 27, 2025
CVE-2025-22659
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle themeisle-companion allows Stored XSS.This issue affects Orbit Fox …

Mar 27, 2025
CVE-2025-22649
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: …

Mar 27, 2025
CVE-2025-22648
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Blog, Posts and Category Filter for Elementor blog-posts-and-category-for-elementor allows Stored XSS.This …

Mar 27, 2025
CVE-2025-22647
4.3 MEDIUM

Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …

Mar 27, 2025
CVE-2025-22646
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite allows Stored XSS.This issue affects aThemes …

Mar 27, 2025
CVE-2025-22644
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce vayu-blocks allows Stored …

Mar 27, 2025
CVE-2025-21892
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix the recovery flow of the UMR QP This patch addresses an issue in …

Mar 27, 2025
CVE-2025-21891
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipvlan: ensure network headers are in skb linear part syzbot found that ipvlan_process_v6_outbound() was assuming …

Mar 27, 2025
CVE-2025-21890
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: idpf: fix checksums set in idpf_rx_rsc() idpf_rx_rsc() uses skb_transport_offset(skb) while the transport header is not …

Mar 27, 2025
CVE-2025-21889
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/core: Add RCU read lock protection to perf_iterate_ctx() The perf_iterate_ctx() function performs RCU list traversal …

Mar 27, 2025
CVE-2025-21888
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix a WARN during dereg_mr for DM type Memory regions (MR) of type DM …

Mar 27, 2025
CVE-2025-21886
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix implicit ODP hang on parent deregistration Fix the destroy_unused_implicit_child_mr() to prevent hanging during …

Mar 27, 2025
CVE-2025-21885
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix the page details for the srq created by kernel consumers While using nvme …

Mar 27, 2025
CVE-2025-21884
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: better track kernel sockets lifetime While kernel sockets are dismantled during pernet_operations->exit(), their freeing …

Mar 27, 2025
CVE-2025-21882
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix vport QoS cleanup on error When enabling vport QoS fails, the scheduling node …

Mar 27, 2025
CVE-2025-21881
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: uprobes: Reject the shared zeropage in uprobe_write_opcode() We triggered the following crash in syzkaller tests: …

Mar 27, 2025
CVE-2025-21880
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/userptr: fix EFAULT handling Currently we treat EFAULT from hmm_range_fault() as a non-fatal error when …

Mar 27, 2025
CVE-2025-21878
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: npcm: disable interrupt enable bit before devm_request_irq The customer reports that there is a …

Mar 27, 2025
CVE-2025-21877
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix endpoint checking in genelink_bind() Syzbot reports [1] a warning in usb_submit_urb() triggered …

Mar 27, 2025
CVE-2025-21876
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix suspicious RCU usage Commit <d74169ceb0d2> ("iommu/vt-d: Allocate DMAR fault interrupts locally") moved the …

Mar 27, 2025
CVE-2025-21875
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: always handle address removal under msk socket lock Syzkaller reported a lockdep splat in …

Mar 27, 2025
CVE-2025-21874
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm-integrity: Avoid divide by zero in table status in Inline mode In Inline mode, the …

Mar 27, 2025
CVE-2025-21873
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: bsg: Fix crash when arpmb command fails If the device doesn't support …

Mar 27, 2025
CVE-2025-21872
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efi: Don't map the entire mokvar table to determine its size Currently, when validating the …

Mar 27, 2025
CVE-2025-1998
5.5 MEDIUM

IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores …

Mar 27, 2025
CVE-2025-1997
5.4 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and …

Mar 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.