CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11188
7.3 HIGH

The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding …

Oct 10, 2025
CVE-2025-52650
8.2 HIGH

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

Oct 10, 2025
CVE-2025-52634
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

Oct 10, 2025
CVE-2025-52632
6.5 MEDIUM

A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-52630
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-41089

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, …

Oct 10, 2025
CVE-2025-41088

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the …

Oct 10, 2025
CVE-2025-37727
5.7 MEDIUM

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API …

Oct 10, 2025
CVE-2025-30001
7.3 HIGH

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which …

Oct 10, 2025
CVE-2025-25018
8.7 HIGH

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

Oct 10, 2025
CVE-2025-25017
8.2 HIGH

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

Oct 10, 2025
CVE-2025-52655
3.1 LOW

Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code …

Oct 10, 2025
CVE-2025-40640
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of …

Oct 10, 2025
CVE-2025-62292
4.3 MEDIUM

In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, …

Oct 10, 2025
CVE-2025-21070
4.0 MEDIUM

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-21069
4.0 MEDIUM

Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21068
4.0 MEDIUM

Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21067
4.0 MEDIUM

Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21066
4.0 MEDIUM

Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21065
6.6 MEDIUM

Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

Oct 10, 2025
CVE-2025-21064
8.8 HIGH

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

Oct 10, 2025
CVE-2025-21063
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording …

Oct 10, 2025
CVE-2025-21062
7.8 HIGH

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction …

Oct 10, 2025
CVE-2025-21061
7.1 HIGH

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering …

Oct 10, 2025
CVE-2025-21060
5.5 MEDIUM

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required …

Oct 10, 2025
CVE-2025-21059
6.2 MEDIUM

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

Oct 10, 2025
CVE-2025-21058
7.3 HIGH

Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attackers to potentially execute arbitrary code …

Oct 10, 2025
CVE-2025-21057
4.0 MEDIUM

Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

Oct 10, 2025
CVE-2025-21055
4.3 MEDIUM

Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21054
4.0 MEDIUM

Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21053
4.0 MEDIUM

Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

Oct 10, 2025
CVE-2025-21052
4.0 MEDIUM

Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory …

Oct 10, 2025
CVE-2025-21051
4.0 MEDIUM

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-21050
7.1 HIGH

Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

Oct 10, 2025
CVE-2025-21049
5.5 MEDIUM

Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this …

Oct 10, 2025
CVE-2025-21048
6.7 MEDIUM

Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.

Oct 10, 2025
CVE-2025-21047
5.2 MEDIUM

Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

Oct 10, 2025
CVE-2025-21046
2.4 LOW

Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.

Oct 10, 2025
CVE-2025-21045
4.0 MEDIUM

Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.

Oct 10, 2025
CVE-2025-21044
5.7 MEDIUM

Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-10124
4.5 MEDIUM

The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. …

Oct 10, 2025
CVE-2025-61871
6.7 MEDIUM

NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root …

Oct 10, 2025
CVE-2025-11570
4.6 MEDIUM

Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if …

Oct 10, 2025
CVE-2025-11569

Rejected reason: This record was withdrawn by its CNA; further investigation revealed it was not a security issue.

Oct 10, 2025
CVE-2025-11450

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed …

Oct 10, 2025
CVE-2025-11449

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed …

Oct 10, 2025
CVE-2025-61928

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any …

Oct 9, 2025
CVE-2025-61926

Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook …

Oct 9, 2025
CVE-2025-62240
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update …

Oct 9, 2025
CVE-2025-61783

Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the …

Oct 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.