CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21487
8.2 HIGH

Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.

Sep 24, 2025
CVE-2025-21484
8.2 HIGH

Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.

Sep 24, 2025
CVE-2025-21483
9.8 CRITICAL

Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.

Sep 24, 2025
CVE-2025-21482
7.1 HIGH

Cryptographic issue while performing RSA PKCS padding decoding.

Sep 24, 2025
CVE-2025-21481
7.8 HIGH

Memory corruption while performing private key encryption in trusted application.

Sep 24, 2025
CVE-2025-21476
7.8 HIGH

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

Sep 24, 2025
CVE-2025-10360

In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files …

Sep 24, 2025
CVE-2025-8869

When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note …

Sep 24, 2025
CVE-2025-48868
7.2 HIGH

Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to …

Sep 24, 2025
CVE-2025-23354
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful …

Sep 24, 2025
CVE-2025-23353
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A …

Sep 24, 2025
CVE-2025-23349
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this …

Sep 24, 2025
CVE-2025-23348
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. …

Sep 24, 2025
CVE-2025-23346
3.3 LOW

NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exploit of this vulnerability may …

Sep 24, 2025
CVE-2025-23340
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed …

Sep 24, 2025
CVE-2025-23339
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to …

Sep 24, 2025
CVE-2025-23338
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write by running nvdisasm on a malicious …

Sep 24, 2025
CVE-2025-23308
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to …

Sep 24, 2025
CVE-2025-23275
4.2 MEDIUM

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain …

Sep 24, 2025
CVE-2025-23274
4.5 MEDIUM

NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted input image with dimensions …

Sep 24, 2025
CVE-2025-23273
2.5 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a divide by zero error by submitting …

Sep 24, 2025
CVE-2025-23272
5.7 MEDIUM

NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially crafted JPEG file. A successful exploit …

Sep 24, 2025
CVE-2025-23271
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed …

Sep 24, 2025
CVE-2025-23255
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-bounds read by passing a malformed …

Sep 24, 2025
CVE-2025-23248
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed …

Sep 24, 2025
CVE-2025-9353
6.4 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to …

Sep 24, 2025
CVE-2025-60020
6.4 MEDIUM

nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.

Sep 24, 2025
CVE-2025-10906
8.4 HIGH

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the …

Sep 24, 2025
CVE-2025-9054
9.8 CRITICAL

The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Sep 24, 2025
CVE-2025-39890
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_ready_ext_event Currently, in ath12k_service_ready_ext_event(), svc_rdy_ext.mac_phy_caps is not freed in …

Sep 24, 2025
CVE-2025-39889
8.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C …

Sep 24, 2025
CVE-2024-58241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregister_dev This make use of disable_work_* on hci_unregister_dev since the …

Sep 24, 2025
CVE-2025-58457
4.3 MEDIUM

Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 …

Sep 24, 2025
CVE-2025-9031
4.3 MEDIUM

Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing.This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.

Sep 24, 2025
CVE-2025-41716
5.3 MEDIUM

The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical …

Sep 24, 2025
CVE-2025-41715
9.8 CRITICAL

The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to gain unauthorized access and potentially compromise it.

Sep 24, 2025
CVE-2025-48459
5.3 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, …

Sep 24, 2025
CVE-2025-48392
7.5 HIGH

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version …

Sep 24, 2025
CVE-2025-58319
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute …

Sep 24, 2025
CVE-2025-58317
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute …

Sep 24, 2025
CVE-2025-59930

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59929

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59928

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59927

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59926

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59925

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59924

Rejected reason: Not used

Sep 24, 2025
CVE-2023-47538

Rejected reason: Not used

Sep 24, 2025
CVE-2025-43819
6.5 MEDIUM

A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and …

Sep 24, 2025
CVE-2025-43779
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 …

Sep 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.