CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-50511
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: lib/fonts: fix undefined behavior in bit shift for get_default_font Shifting signed 32-bit value by 31 …

Oct 7, 2025
CVE-2022-50510
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/smmuv3: Fix hotplug callback leak in arm_smmu_pmu_init() arm_smmu_pmu_init() won't remove the callback added by cpuhp_setup_state_multi() …

Oct 7, 2025
CVE-2022-50509
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: coda: Add check for kmalloc As the kmalloc may return NULL pointer, it should …

Oct 7, 2025
CVE-2025-61772
7.5 HIGH

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data when a multipart part’s …

Oct 7, 2025
CVE-2025-61771
7.5 HIGH

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) …

Oct 7, 2025
CVE-2025-61770
7.5 HIGH

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart preamble (bytes before the …

Oct 7, 2025
CVE-2025-11398
6.3 MEDIUM

A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unknown function of the file /profile.php of …

Oct 7, 2025
CVE-2023-6215

A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow …

Oct 7, 2025
CVE-2025-59425
7.5 HIGH

vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a …

Oct 7, 2025
CVE-2025-57564
8.2 HIGH

CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/insert/elasticsearch/_bulk endpoint. This endpoint accepts bulk log data without requiring …

Oct 7, 2025
CVE-2025-54406
8.8 HIGH

Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary …

Oct 7, 2025
CVE-2025-54405
8.8 HIGH

Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary …

Oct 7, 2025
CVE-2025-54404
8.8 HIGH

Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead to arbitrary command execution. …

Oct 7, 2025
CVE-2025-54403
8.8 HIGH

Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead to arbitrary command execution. …

Oct 7, 2025
CVE-2025-54402
8.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based …

Oct 7, 2025
CVE-2025-54401
8.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based …

Oct 7, 2025
CVE-2025-54400
8.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based …

Oct 7, 2025
CVE-2025-54399
8.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based …

Oct 7, 2025
CVE-2025-53476
5.3 MEDIUM

A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A specially crafted series of network connections can lead to …

Oct 7, 2025
CVE-2025-50505
7.8 HIGH

Clash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API …

Oct 7, 2025
CVE-2025-48826
8.8 HIGH

A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to memory corruption. …

Oct 7, 2025
CVE-2025-37728
5.4 MEDIUM

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector …

Oct 7, 2025
CVE-2025-25009
8.7 HIGH

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.

Oct 7, 2025
CVE-2025-11397
7.3 HIGH

A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. …

Oct 7, 2025
CVE-2021-22291
8.0 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects …

Oct 7, 2025
CVE-2025-40889
8.1 HIGH

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, …

Oct 7, 2025
CVE-2025-40888
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can …

Oct 7, 2025
CVE-2025-40887
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can …

Oct 7, 2025
CVE-2025-40886
7.5 HIGH

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can …

Oct 7, 2025
CVE-2025-40885
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges …

Oct 7, 2025
CVE-2025-40676

Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Research Infrastructure (BBMRI-ERIC). This vulnerability allows an attacker to access …

Oct 7, 2025
CVE-2025-40649

Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infrastructure (BBMRI-ERIC), consisting of a stored XSS due to a lack …

Oct 7, 2025
CVE-2025-3719
8.1 HIGH

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. …

Oct 7, 2025
CVE-2025-3718
7.9 HIGH

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with …

Oct 7, 2025
CVE-2025-11396
7.3 HIGH

A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument …

Oct 7, 2025
CVE-2025-11390
4.3 MEDIUM

A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of …

Oct 7, 2025
CVE-2025-11389
8.8 HIGH

A security flaw has been discovered in Tenda AC15 15.03.05.18. Affected is an unknown function of the file /goform/saveAutoQos. Performing a manipulation of the argument …

Oct 7, 2025
CVE-2025-0603
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection.This …

Oct 7, 2025
CVE-2025-11388
8.8 HIGH

A vulnerability was identified in Tenda AC15 15.03.05.18. This impacts an unknown function of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to …

Oct 7, 2025
CVE-2025-11387
8.8 HIGH

A vulnerability was determined in Tenda AC15 15.03.05.18. This affects an unknown function of the file /goform/fast_setting_pppoe_set. This manipulation of the argument Password causes stack-based …

Oct 7, 2025
CVE-2025-11386
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.18. The impacted element is an unknown function of the file /goform/SetDDNSCfg of the component POST Parameter Handler. …

Oct 7, 2025
CVE-2025-11385
8.8 HIGH

A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The affected element is the function sscanf of the file /goform/fast_setting_wifi_set. The manipulation of …

Oct 7, 2025
CVE-2025-11360
4.3 MEDIUM

A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the file api/src/app.js of the component API. …

Oct 7, 2025
CVE-2025-11359
6.3 MEDIUM

A security vulnerability has been detected in code-projects Simple Banking System 1.0. The affected element is an unknown function of the file /transfermoney.php. The manipulation …

Oct 7, 2025
CVE-2025-10645
5.3 MEDIUM

The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when …

Oct 7, 2025
CVE-2025-7400
6.4 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featured Image custom fields in all versions …

Oct 7, 2025
CVE-2025-11358
6.3 MEDIUM

A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /removeuser.php. Executing manipulation of the argument …

Oct 7, 2025
CVE-2025-11357
6.3 MEDIUM

A security flaw has been discovered in code-projects Simple Banking System 1.0. This issue affects some unknown processing of the file /createuser.php. Performing manipulation of …

Oct 7, 2025
CVE-2025-11356
8.8 HIGH

A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of …

Oct 7, 2025
CVE-2025-11355
8.8 HIGH

A vulnerability has been found in UTT 1250GW up to v2v3.2.2-200710. Affected by this vulnerability is the function strcpy of the file /goform/aspChangeChannel. The manipulation …

Oct 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.