CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59424
7.3 HIGH

LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. …

Sep 18, 2025
CVE-2025-10688
7.3 HIGH

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/operation/paid.php. This manipulation of the argument …

Sep 18, 2025
CVE-2025-47906
6.5 MEDIUM

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result …

Sep 18, 2025
CVE-2025-26503
6.7 MEDIUM

A crafted system call argument can cause memory corruption.

Sep 18, 2025
CVE-2025-10650

SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin …

Sep 18, 2025
CVE-2025-10687
7.3 HIGH

A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /admin/add_teacher.php. The manipulation of the argument Username …

Sep 18, 2025
CVE-2025-55912
7.3 HIGH

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any …

Sep 18, 2025
CVE-2025-50255
7.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request.

Sep 18, 2025
CVE-2025-36146
4.3 MEDIUM

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in further attacks against the system.

Sep 18, 2025
CVE-2025-36143
4.7 MEDIUM

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input.

Sep 18, 2025
CVE-2025-36139
5.5 MEDIUM

IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI …

Sep 18, 2025
CVE-2025-10676
4.3 MEDIUM

A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /brand/queryAll. Executing manipulation can lead to improper authorization. …

Sep 18, 2025
CVE-2025-10675
4.3 MEDIUM

A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of the file /attribute/queryAll. Performing manipulation results in improper authorization. …

Sep 18, 2025
CVE-2025-10674
4.3 MEDIUM

A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController of the file /attributecategory/queryAll. Such manipulation leads to improper authorization. The attack …

Sep 18, 2025
CVE-2023-53447
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: don't reset unchangable mount option in f2fs_remount() syzbot reports a bug as below: general …

Sep 18, 2025
CVE-2023-53446
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Disable ASPM on MFD function removal to avoid use-after-free Struct pcie_link_state->downstream is a pointer …

Sep 18, 2025
CVE-2023-53445
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Fix a refcount bug in qrtr_recvmsg() Syzbot reported a bug as following: refcount_t: …

Sep 18, 2025
CVE-2023-53444
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fix bulk_move corruption when adding a entry When the resource is the first in …

Sep 18, 2025
CVE-2023-53443
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mfd: arizona: Use pm_runtime_resume_and_get() to prevent refcnt leak In arizona_clk32k_enable(), we should use pm_runtime_resume_and_get() as …

Sep 18, 2025
CVE-2023-53442
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: Block switchdev mode when ADQ is active and vice versa ADQ and switchdev are …

Sep 18, 2025
CVE-2023-53441
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: cpumap: Fix memory leak in cpu_map_update_elem Syzkaller reported a memory leak as follows: BUG: …

Sep 18, 2025
CVE-2023-53440
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix sysfs interface lifetime The current nilfs2 sysfs support has issues with the timing …

Sep 18, 2025
CVE-2023-53439
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: skb_partial_csum_set() fix against transport header magic value skb->transport_header uses the special 0xFFFF value to …

Sep 18, 2025
CVE-2023-53438
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/MCE: Always save CS register on AMD Zen IF Poison errors The Instruction Fetch (IF) …

Sep 18, 2025
CVE-2023-53437
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Handle cameras with invalid descriptors If the source entity does not contain any …

Sep 18, 2025
CVE-2023-53436
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible memory leak if device_add() fails If device_add() returns error, the name …

Sep 18, 2025
CVE-2023-53435
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cassini: Fix a memory leak in the error handling path of cas_init_one() cas_saturn_firmware_init() allocates some …

Sep 18, 2025
CVE-2023-53434
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: remoteproc: imx_dsp_rproc: Add custom memory copy implementation for i.MX DSP Cores The IRAM is part …

Sep 18, 2025
CVE-2023-53433
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: add vlan_get_protocol_and_depth() helper Before blamed commit, pskb_may_pull() was used instead of skb_header_pointer() in __vlan_get_protocol() …

Sep 18, 2025
CVE-2023-53432
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: firewire: net: fix use after free in fwnet_finish_incoming_packet() The netif_rx() function frees the skb so …

Sep 18, 2025
CVE-2023-53431
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Handle enclosure with just a primary component gracefully This reverts commit 3fe97ff3d949 ("scsi: …

Sep 18, 2025
CVE-2023-53430
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: dma: fix memory leak running mt76_dma_tx_cleanup Fix device unregister memory leak and alway …

Sep 18, 2025
CVE-2023-53429
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't check PageError in __extent_writepage __extent_writepage currenly sets PageError whenever any error happens, and …

Sep 18, 2025
CVE-2023-53428
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powercap: arm_scmi: Remove recursion while parsing zones Powercap zones can be defined as arranged in …

Sep 18, 2025
CVE-2023-53427
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix warning and UAF when destroy the MR list If the MR allocate failed, …

Sep 18, 2025
CVE-2023-53426
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xsk: Fix xsk_diag use-after-free error during socket cleanup Fix a use-after-free error that is possible …

Sep 18, 2025
CVE-2023-53425
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: platform: mediatek: vpu: fix NULL ptr dereference If pdev is NULL, then it is …

Sep 18, 2025
CVE-2023-53424
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: fix of_iomap memory leak Smatch reports: drivers/clk/mediatek/clk-mtk.c:583 mtk_clk_simple_probe() warn: 'base' from of_iomap() not …

Sep 18, 2025
CVE-2023-53423
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: objtool: Fix memory leak in create_static_call_sections() strdup() allocates memory for key_name. We need to release …

Sep 18, 2025
CVE-2023-53422
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fw: fix memory leak in debugfs Fix a memory leak that occurs when …

Sep 18, 2025
CVE-2023-53421
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats() When blkg_alloc() is called to allocate a blkcg_gq …

Sep 18, 2025
CVE-2023-53420
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr() Here is a BUG report from syzbot: …

Sep 18, 2025
CVE-2023-53419
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rcu: Protect rcu_print_task_exp_stall() ->exp_tasks access For kernels built with CONFIG_PREEMPT_RCU=y, the following scenario can result …

Sep 18, 2025
CVE-2023-49367
8.8 HIGH

An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by user.

Sep 18, 2025
CVE-2022-50419
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times device_add shall not be called multiple …

Sep 18, 2025
CVE-2022-50418
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: mhi: fix potential memory leak in ath11k_mhi_register() mhi_alloc_controller() allocates a memory space for …

Sep 18, 2025
CVE-2022-50417
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix GEM handle creation ref-counting panfrost_gem_create_with_handle() previously returned a BO but with the only …

Sep 18, 2025
CVE-2022-50416
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/wpcm450: Fix memory leak in wpcm450_aic_of_init() If of_iomap() failed, 'aic' should be freed before return. …

Sep 18, 2025
CVE-2022-50415
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: led: Fix potential null-ptr-deref in start_task() start_task() calls create_singlethread_workqueue() and not checked the ret …

Sep 18, 2025
CVE-2022-50414
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Fix transport not deattached when fcoe_if_init() fails fcoe_init() calls fcoe_transport_attach(&fcoe_sw_transport), but when fcoe_if_init() …

Sep 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.