CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11720
8.1 HIGH

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied …

Oct 14, 2025
CVE-2025-11719
9.8 CRITICAL

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. …

Oct 14, 2025
CVE-2025-11718
6.5 MEDIUM

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in …

Oct 14, 2025
CVE-2025-11717
9.1 CRITICAL

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last …

Oct 14, 2025
CVE-2025-11716
6.5 MEDIUM

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and …

Oct 14, 2025
CVE-2025-11715
8.8 HIGH

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption …

Oct 14, 2025
CVE-2025-11714
8.8 HIGH

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence …

Oct 14, 2025
CVE-2025-11713
8.1 HIGH

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not …

Oct 14, 2025
CVE-2025-11712
6.1 MEDIUM

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served …

Oct 14, 2025
CVE-2025-11711
6.5 MEDIUM

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, …

Oct 14, 2025
CVE-2025-11710
9.8 CRITICAL

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. …

Oct 14, 2025
CVE-2025-11709
9.8 CRITICAL

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability …

Oct 14, 2025
CVE-2025-11708
9.8 CRITICAL

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

Oct 14, 2025
CVE-2025-11498
6.1 MEDIUM

An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling …

Oct 14, 2025
CVE-2025-10610
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure allows …

Oct 14, 2025
CVE-2025-9437

A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability …

Oct 14, 2025
CVE-2025-40812
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The …

Oct 14, 2025
CVE-2025-40811
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The …

Oct 14, 2025
CVE-2025-40810
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The …

Oct 14, 2025
CVE-2025-40809
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The …

Oct 14, 2025
CVE-2025-40774
4.4 MEDIUM

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are …

Oct 14, 2025
CVE-2025-40773
3.5 LOW

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks …

Oct 14, 2025
CVE-2025-40772
7.4 HIGH

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker …

Oct 14, 2025
CVE-2025-40771
9.8 CRITICAL

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP …

Oct 14, 2025
CVE-2025-40765
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This …

Oct 14, 2025
CVE-2025-40755
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated …

Oct 14, 2025
CVE-2025-20724
5.5 MEDIUM

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Oct 14, 2025
CVE-2025-20723
7.8 HIGH

In gnss driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Oct 14, 2025
CVE-2025-20722
5.5 MEDIUM

In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a …

Oct 14, 2025
CVE-2025-20721
7.8 HIGH

In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Oct 14, 2025
CVE-2025-20720
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-20719
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-20718
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20717
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20716
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20715
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20714
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20713
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20712
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-20711
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-20710
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) escalation of …

Oct 14, 2025
CVE-2025-20709
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-10228
8.8 HIGH

Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking.This issue affects Agentis: before 4.44.

Oct 14, 2025
CVE-2011-20002
7.4 HIGH

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS …

Oct 14, 2025
CVE-2011-20001
7.5 HIGH

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS …

Oct 14, 2025
CVE-2025-46581
9.8 CRITICAL

ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

Oct 14, 2025
CVE-2025-41718
7.5 HIGH

A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI.

Oct 14, 2025
CVE-2025-41699
8.8 HIGH

An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting …

Oct 14, 2025
CVE-2025-55078
5.5 MEDIUM

In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory …

Oct 14, 2025
CVE-2025-41707
5.3 MEDIUM

The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a crafted websocket message to trigger the issue …

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.