CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-56241
7.5 HIGH

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows …

Sep 24, 2025
CVE-2025-52907
8.8 HIGH

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Sep 24, 2025
CVE-2025-52906
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through …

Sep 24, 2025
CVE-2025-48869
7.5 HIGH

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing …

Sep 24, 2025
CVE-2025-48867
4.8 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin …

Sep 24, 2025
CVE-2025-20352
7.7 HIGH KEV

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, …

Sep 24, 2025
CVE-2025-20338
6.0 MEDIUM

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root …

Sep 24, 2025
CVE-2025-20327
7.7 HIGH

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service …

Sep 24, 2025
CVE-2025-20316
5.3 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an …

Sep 24, 2025
CVE-2025-20315
8.6 HIGH

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device …

Sep 24, 2025
CVE-2025-20314
6.7 MEDIUM

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an …

Sep 24, 2025
CVE-2025-20313
6.7 MEDIUM

Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to …

Sep 24, 2025
CVE-2025-20312
7.7 HIGH

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial …

Sep 24, 2025
CVE-2025-20311
7.4 HIGH

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker …

Sep 24, 2025
CVE-2025-20293
5.3 MEDIUM

A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an …

Sep 24, 2025
CVE-2025-20240
6.1 MEDIUM

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack …

Sep 24, 2025
CVE-2025-20160
8.1 HIGH

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to …

Sep 24, 2025
CVE-2025-20149
6.5 MEDIUM

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device …

Sep 24, 2025
CVE-2025-56816
8.8 HIGH

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to the config/jdbc-driver-ext.yml path. …

Sep 24, 2025
CVE-2025-56815
7.1 HIGH

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to save the uploaded file to a …

Sep 24, 2025
CVE-2025-20365
4.3 MEDIUM

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 …

Sep 24, 2025
CVE-2025-20364
4.3 MEDIUM

A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless …

Sep 24, 2025
CVE-2025-20339
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass …

Sep 24, 2025
CVE-2025-20334
8.8 HIGH

A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root …

Sep 24, 2025
CVE-2025-10909
2.4 LOW

A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the …

Sep 24, 2025
CVE-2025-10892
8.8 HIGH

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10891
8.8 HIGH

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10890
9.1 CRITICAL

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10585
9.8 CRITICAL KEV

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10502
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium …

Sep 24, 2025
CVE-2025-10501
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 24, 2025
CVE-2025-10500
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 24, 2025
CVE-2025-56819
9.8 CRITICAL

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

Sep 24, 2025
CVE-2025-47329
7.8 HIGH

Memory corruption while handling invalid inputs in application info setup.

Sep 24, 2025
CVE-2025-47328
7.5 HIGH

Transient DOS while processing power control requests with invalid antenna or stream values.

Sep 24, 2025
CVE-2025-47327
7.8 HIGH

Memory corruption while encoding the image data.

Sep 24, 2025
CVE-2025-47326
7.5 HIGH

Transient DOS while handling command data during power control processing.

Sep 24, 2025
CVE-2025-47318
7.5 HIGH

Transient DOS while parsing the EPTM test control message to get the test pattern.

Sep 24, 2025
CVE-2025-47317
7.8 HIGH

Memory corruption due to global buffer overflow when a test command uses an invalid payload type.

Sep 24, 2025
CVE-2025-47316
7.8 HIGH

Memory corruption due to double free when multiple threads race to set the timestamp store.

Sep 24, 2025
CVE-2025-47315
7.8 HIGH

Memory corruption while handling repeated memory unmap requests from guest VM.

Sep 24, 2025
CVE-2025-47314
7.8 HIGH

Memory corruption while processing data sent by FE driver.

Sep 24, 2025
CVE-2025-27077
7.8 HIGH

Memory corruption while processing message in guest VM.

Sep 24, 2025
CVE-2025-27037
7.8 HIGH

Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.

Sep 24, 2025
CVE-2025-27036
6.1 MEDIUM

Information disclosure when Video engine escape input data is less than expected minimum size.

Sep 24, 2025
CVE-2025-27034
9.8 CRITICAL

Memory corruption while selecting the PLMN from SOR failed list.

Sep 24, 2025
CVE-2025-27033
6.1 MEDIUM

Information disclosure while running video usecase having rogue firmware.

Sep 24, 2025
CVE-2025-27032
7.8 HIGH

memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.

Sep 24, 2025
CVE-2025-27030
6.1 MEDIUM

information disclosure while invoking calibration data from user space to update firmware size.

Sep 24, 2025
CVE-2025-21488
8.2 HIGH

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.

Sep 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.