CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39904
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: kexec: initialize kexec_buf struct in load_other_segments() Patch series "kexec: Fix invalid field access". The …

Oct 1, 2025
CVE-2025-39903
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: of_numa: fix uninitialized memory nodes causing kernel panic When there are memory-only nodes (nodes without …

Oct 1, 2025
CVE-2025-39902
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err() object_err() reports details of an …

Oct 1, 2025
CVE-2025-39901
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'command' and 'netdev_ops' debugfs files are a …

Oct 1, 2025
CVE-2025-39900
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y syzbot reported a WARNING in est_timer() [1] Problem here …

Oct 1, 2025
CVE-2025-39899
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: fix kmap_local LIFO ordering for CONFIG_HIGHPTE With CONFIG_HIGHPTE on 32-bit ARM, move_pages_pte() maps PTE …

Oct 1, 2025
CVE-2025-39898

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Oct 1, 2025
CVE-2025-39897
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX metadata pointer retrieval Add proper error checking …

Oct 1, 2025
CVE-2025-39896
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued during device removal Use disable_work_sync() instead of cancel_work_sync() …

Oct 1, 2025
CVE-2025-39895
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched: Fix sched_numa_find_nth_cpu() if mask offline sched_numa_find_nth_cpu() uses a bsearch to look for the 'closest' …

Oct 1, 2025
CVE-2025-39894
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast …

Oct 1, 2025
CVE-2025-39893
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: unregister ECC engine on probe error and device remove The on-host hardware ECC …

Oct 1, 2025
CVE-2025-39892
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: care NULL dirver name on snd_soc_lookup_component_nolocked() soc-generic-dmaengine-pcm.c uses same dev for both CPU …

Oct 1, 2025
CVE-2025-39891
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Initialize the chan_stats array to zero The adapter->chan_stats[] array is initialized in mwifiex_init_channel_scan_gap() …

Oct 1, 2025
CVE-2025-11226

ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary …

Oct 1, 2025
CVE-2020-36852
9.1 CRITICAL

The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a …

Oct 1, 2025
CVE-2025-9512
6.1 MEDIUM

The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modifications, making it possible for …

Oct 1, 2025
CVE-2025-9075
6.4 MEDIUM

The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due …

Oct 1, 2025
CVE-2025-10744
5.9 MEDIUM

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Oct 1, 2025
CVE-2025-10735
4.0 MEDIUM

The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and …

Oct 1, 2025
CVE-2025-10538

An authentication bypass vulnerability exists in LG Innotek camera models LND7210 and LNV7210R. The vulnerability allows a malicious actor to gain access to camera information …

Oct 1, 2025
CVE-2025-61722

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61721

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61720

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61719

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61718

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61717

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61716

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61715

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61714

Rejected reason: Not used

Oct 1, 2025
CVE-2025-61792
6.4 MEDIUM

Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Question Mark button, the Help Button, …

Sep 30, 2025
CVE-2025-55191
6.5 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain …

Sep 30, 2025
CVE-2025-43826
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, …

Sep 30, 2025
CVE-2025-24525
7.5 HIGH

Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via …

Sep 30, 2025
CVE-2022-40285

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-13967. Reason: This record is a reservation duplicate of CVE-2024-13967. Notes: All CVE users should reference …

Sep 30, 2025
CVE-2025-56392
8.1 HIGH

An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via …

Sep 30, 2025
CVE-2025-36262
4.9 MEDIUM

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access …

Sep 30, 2025
CVE-2025-36132
5.4 MEDIUM

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Sep 30, 2025
CVE-2025-10659
9.8 CRITICAL

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs …

Sep 30, 2025
CVE-2024-55017
7.5 HIGH

Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept authorization codes and gain …

Sep 30, 2025
CVE-2025-56132
7.3 HIGH

LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email …

Sep 30, 2025
CVE-2025-43827
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, …

Sep 30, 2025
CVE-2025-57254
6.5 MEDIUM

An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allows remote attackers to execute arbitrary SQL queries via the …

Sep 30, 2025
CVE-2025-56675
3.5 LOW

The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.

Sep 30, 2025
CVE-2025-56513
9.8 CRITICAL

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the …

Sep 30, 2025
CVE-2025-56200
6.1 MEDIUM

A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use …

Sep 30, 2025
CVE-2025-23293
8.7 HIGH

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability …

Sep 30, 2025
CVE-2025-23292
4.6 MEDIUM

NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Attacker may cause an authorized action. A successful exploit of …

Sep 30, 2025
CVE-2025-23291
2.4 LOW

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability …

Sep 30, 2025
CVE-2025-11195
3.3 LOW

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration …

Sep 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.