CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-45095
7.3 HIGH

Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unquoted service path vulnerability. An attacker with …

Oct 9, 2025
CVE-2025-39664
6.5 MEDIUM

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file …

Oct 9, 2025
CVE-2025-32919
7.8 HIGH

Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 …

Oct 9, 2025
CVE-2025-32916
4.3 MEDIUM

Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to …

Oct 9, 2025
CVE-2025-62228
8.8 HIGH

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through …

Oct 9, 2025
CVE-2025-36225
4.3 MEDIUM

IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.

Oct 9, 2025
CVE-2025-36171
4.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive …

Oct 9, 2025
CVE-2025-11561
8.8 HIGH

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos …

Oct 9, 2025
CVE-2023-37401
5.3 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.

Oct 9, 2025
CVE-2025-39963
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix incorrect io_kiocb reference in io_link_skb In io_link_skb function, there is a bug where …

Oct 9, 2025
CVE-2025-39962
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix untrusted unsigned subtract Fix the following Smatch static checker warning: net/rxrpc/rxgk_app.c:65 rxgk_yfs_decode_ticket() warn: …

Oct 9, 2025
CVE-2025-39961
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase page table level The AMD IOMMU host page table …

Oct 9, 2025
CVE-2025-39960
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: gpiolib: acpi: initialize acpi_gpio_info struct Since commit 7c010d463372 ("gpiolib: acpi: Make sure we fill struct …

Oct 9, 2025
CVE-2025-10240
8.8 HIGH

A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a malicious link provided by an attacker …

Oct 9, 2025
CVE-2025-10239
7.2 HIGH

In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privileges and access to the management interface to …

Oct 9, 2025
CVE-2025-9371
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versions up to, and including, 28.1.6 due to …

Oct 9, 2025
CVE-2025-2934
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 …

Oct 9, 2025
CVE-2025-11340
7.7 HIGH

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed …

Oct 9, 2025
CVE-2025-10249
6.5 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in …

Oct 9, 2025
CVE-2025-10004
7.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make …

Oct 9, 2025
CVE-2025-39959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix incorrect retrival of acp_chip_info Use dev_get_drvdata(dev->parent) instead of dev_get_platdata(dev) to correctly …

Oct 9, 2025
CVE-2025-39958
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Make attach succeed when the device was surprise removed When a PCI device is …

Oct 9, 2025
CVE-2025-39957
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Currently the S1G capability element is not taken into …

Oct 9, 2025
CVE-2025-39956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error When igc_led_setup() fails, igc_probe() fails and triggers …

Oct 9, 2025
CVE-2025-39955
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). syzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk …

Oct 9, 2025
CVE-2025-39954
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate readback When dual-divider clock support was introduced, the …

Oct 9, 2025
CVE-2025-10862
7.5 HIGH

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to SQL Injection in all versions up to, …

Oct 9, 2025
CVE-2025-11539
9.9 CRITICAL

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv …

Oct 9, 2025
CVE-2025-11522
9.8 CRITICAL

The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and …

Oct 9, 2025
CVE-2025-7634
9.8 CRITICAL

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up …

Oct 9, 2025
CVE-2025-7526
9.8 CRITICAL

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to …

Oct 9, 2025
CVE-2025-6038
8.8 HIGH

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password update in …

Oct 9, 2025
CVE-2025-47355
7.8 HIGH

Memory corruption while invoking remote procedure IOCTL calls.

Oct 9, 2025
CVE-2025-47354
7.8 HIGH

Memory corruption while allocating buffers in DSP service.

Oct 9, 2025
CVE-2025-47351
7.8 HIGH

Memory corruption while processing user buffers.

Oct 9, 2025
CVE-2025-47349
7.8 HIGH

Memory corruption while processing an escape call.

Oct 9, 2025
CVE-2025-47347
7.8 HIGH

Memory corruption while processing control commands in the virtual memory management interface.

Oct 9, 2025
CVE-2025-47342
7.1 HIGH

Transient DOS may occur when multi-profile concurrency arises with QHS enabled.

Oct 9, 2025
CVE-2025-47341
7.8 HIGH

memory corruption while processing an image encoding completion event.

Oct 9, 2025
CVE-2025-47340
7.8 HIGH

Memory corruption while processing IOCTL call to get the mapping.

Oct 9, 2025
CVE-2025-47338
7.8 HIGH

Memory corruption while processing escape commands from userspace.

Oct 9, 2025
CVE-2025-27060
8.8 HIGH

Memory corruption while performing SCM call with malformed inputs.

Oct 9, 2025
CVE-2025-27059
8.8 HIGH

Memory corruption while performing SCM call.

Oct 9, 2025
CVE-2025-27054
7.8 HIGH

Memory corruption while processing a malformed license file during reboot.

Oct 9, 2025
CVE-2025-27053
7.8 HIGH

Memory corruption during PlayReady APP usecase while processing TA commands.

Oct 9, 2025
CVE-2025-27049
5.5 MEDIUM

Transient DOS while processing IOCTL call for image encoding.

Oct 9, 2025
CVE-2025-27048
7.8 HIGH

Memory corruption while processing camera platform driver IOCTL calls.

Oct 9, 2025
CVE-2025-27045
6.1 MEDIUM

Information disclosure while processing batch command execution in Video driver.

Oct 9, 2025
CVE-2025-27041
5.5 MEDIUM

Transient DOS while processing video packets received from video firmware.

Oct 9, 2025
CVE-2025-27040
6.5 MEDIUM

Information disclosure may occur while processing the hypervisor log.

Oct 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.