CVE Database

5223+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5200
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDLImporter::InternReadFile_Quake1 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. …

May 26, 2025
CVE-2025-46804
3.3 LOW

A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. …

May 26, 2025
CVE-2025-5183
3.5 LOW

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as problematic. This issue affects some unknown processing …

May 26, 2025
CVE-2025-5181
3.5 LOW

A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. This affects an unknown part …

May 26, 2025
CVE-2025-5179
2.4 LOW

A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by this vulnerability is an unknown functionality of …

May 26, 2025
CVE-2025-5169
3.3 LOW

A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The …

May 26, 2025
CVE-2025-5168
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 …

May 26, 2025
CVE-2025-5167
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 …

May 26, 2025
CVE-2025-5166
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file …

May 26, 2025
CVE-2025-5165
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. …

May 26, 2025
CVE-2025-5164
3.7 LOW

A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation …

May 26, 2025
CVE-2025-5154
2.3 LOW

A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of …

May 25, 2025
CVE-2025-5153
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown processing of the component Design …

May 25, 2025
CVE-2025-5138
3.5 LOW

A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

May 25, 2025
CVE-2025-5136
3.7 LOW

A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of …

May 25, 2025
CVE-2025-5135
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionality of …

May 24, 2025
CVE-2025-5134
3.5 LOW

A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the component Buy …

May 24, 2025
CVE-2025-5127
3.5 LOW

A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. Executing manipulation of the …

May 24, 2025
CVE-2025-48756
2.9 LOW

In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits …

May 24, 2025
CVE-2025-48755
2.9 LOW

In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).

May 24, 2025
CVE-2025-48754
2.9 LOW

In the memory_pages crate 0.1.0 for Rust, division by zero can occur.

May 24, 2025
CVE-2025-48753
2.9 LOW

In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.

May 24, 2025
CVE-2025-48752
2.9 LOW

In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.

May 24, 2025
CVE-2025-48751
2.9 LOW

The process_lock crate 0.1.0 for Rust allows data races in unlock.

May 24, 2025
CVE-2025-48376
3.5 LOW

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft …

May 23, 2025
CVE-2023-53154
2.9 LOW

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

May 23, 2025
CVE-2024-9163
3.5 LOW

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 …

May 23, 2025
CVE-2025-1110
2.7 LOW

An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access …

May 22, 2025
CVE-2023-47466
2.9 LOW

TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the …

May 22, 2025
CVE-2025-48070
3.5 LOW

Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to …

May 21, 2025
CVE-2025-48064
3.3 LOW

GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file …

May 21, 2025
CVE-2025-5031
3.1 LOW

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the component …

May 21, 2025
CVE-2025-48009
3.1 LOW

Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.

May 21, 2025
CVE-2025-5011
2.4 LOW

A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List …

May 21, 2025
CVE-2025-5010
2.4 LOW

A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog …

May 21, 2025
CVE-2025-5007
3.5 LOW

A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the …

May 20, 2025
CVE-2025-5001
3.3 LOW

A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The …

May 20, 2025
CVE-2025-4996
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add …

May 20, 2025
CVE-2025-48015
3.7 LOW

Failed login response could be different depending on whether the username was local or central.

May 20, 2025
CVE-2025-47938
3.8 LOW

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, …

May 20, 2025
CVE-2025-47937
3.7 LOW

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, …

May 20, 2025
CVE-2025-47936
3.3 LOW

TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch …

May 20, 2025
CVE-2025-4945
3.7 LOW

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when …

May 19, 2025
CVE-2025-31185
3.3 LOW

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may …

May 19, 2025
CVE-2025-27566
3.8 LOW

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path …

May 19, 2025
CVE-2025-23165
3.7 LOW

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when …

May 19, 2025
CVE-2025-4894
3.7 LOW

A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation …

May 18, 2025
CVE-2025-48219
3.5 LOW

O2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) call and then reading …

May 18, 2025
CVE-2025-4860
2.4 LOW

A vulnerability classified as problematic has been found in D-Link DAP-2695 120b36r137_ALL_en_20210528. Affected is an unknown function of the file /adv_dhcps.php of the component Static …

May 18, 2025
CVE-2025-4859
2.4 LOW

A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been rated as problematic. This issue affects some unknown processing of the file /adv_macbypass.php of …

May 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.