CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39750
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Correct tid cleanup when tid setup fails Currently, if any error occurs during …

Sep 11, 2025
CVE-2025-39749
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: rcu: Protect ->defer_qs_iw_pending from data race On kernels built with CONFIG_IRQ_WORK=y, when rcu_read_unlock() is invoked …

Sep 11, 2025
CVE-2025-39748
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Forget ranges when refining tnum after JSET Syzbot reported a kernel warning due to …

Sep 11, 2025
CVE-2025-39747
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Add error handling for krealloc in metadata setup Function msm_ioctl_gem_info_set_metadata() now checks for krealloc …

Sep 11, 2025
CVE-2025-39746
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: shutdown driver when hardware is unreliable In rare cases, ath10k may lose connection …

Sep 11, 2025
CVE-2025-39745
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rcutorture: Fix rcutorture_one_extend_check() splat in RT kernels For built with CONFIG_PREEMPT_RT=y kernels, running rcutorture tests …

Sep 11, 2025
CVE-2025-39744
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: rcu: Fix rcu_read_unlock() deadloop due to IRQ work During rcu_read_unlock_special(), if this happens during irq_exit(), …

Sep 11, 2025
CVE-2025-39743
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 The fileset value of the …

Sep 11, 2025
CVE-2025-39742
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() The function divides number of online CPUs by …

Sep 11, 2025
CVE-2025-39741
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: don't overflow max copy size With non-page aligned copy, we need to use 4 …

Sep 11, 2025
CVE-2025-39740
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: prevent potential UAF If we hit the error path, the previous fence (if there …

Sep 11, 2025
CVE-2025-39739
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-qcom: Add SM6115 MDSS compatible Add the SM6115 MDSS compatible to clients compatible list, as …

Sep 11, 2025
CVE-2025-39738
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped subvolumes [BUG] There is an internal report …

Sep 11, 2025
CVE-2025-39737
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() A soft lockup warning was observed on a relative …

Sep 11, 2025
CVE-2025-39736
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock When netpoll is enabled, calling pr_warn_once() while …

Sep 11, 2025
CVE-2025-26499
6.0 MEDIUM

Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This flaw allows one user to be granted a …

Sep 11, 2025
CVE-2025-10255
3.5 LOW

A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the file /Products/Projects/Messages.aspx of the component Comment …

Sep 11, 2025
CVE-2025-10254
3.5 LOW

A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of the file /Products/Projects/Messages.aspx of the component …

Sep 11, 2025
CVE-2025-8716

In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames …

Sep 11, 2025
CVE-2025-58145
7.5 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping …

Sep 11, 2025
CVE-2025-58144
7.5 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping …

Sep 11, 2025
CVE-2025-58143
9.8 CRITICAL

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling …

Sep 11, 2025
CVE-2025-58142
9.8 CRITICAL

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling …

Sep 11, 2025
CVE-2025-27466
9.8 CRITICAL

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling …

Sep 11, 2025
CVE-2025-10253
3.5 LOW

A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifive.php of the component SVG File Handler. Such manipulation …

Sep 11, 2025
CVE-2025-10252
3.1 LOW

A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. …

Sep 11, 2025
CVE-2025-10193

DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j …

Sep 11, 2025
CVE-2025-10251
6.3 MEDIUM

A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/admin/controller/Images.php. The manipulation of the …

Sep 11, 2025
CVE-2025-9018
8.8 HIGH

The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update_table_function' and …

Sep 11, 2025
CVE-2025-40696
5.4 MEDIUM

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper …

Sep 11, 2025
CVE-2025-40695
5.4 MEDIUM

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper …

Sep 11, 2025
CVE-2025-40694
5.4 MEDIUM

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper …

Sep 11, 2025
CVE-2025-40693
5.4 MEDIUM

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack …

Sep 11, 2025
CVE-2025-40692
9.8 CRITICAL

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter …

Sep 11, 2025
CVE-2025-40691
9.8 CRITICAL

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter …

Sep 11, 2025
CVE-2025-40690
9.8 CRITICAL

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter …

Sep 11, 2025
CVE-2025-40689
9.8 CRITICAL

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' …

Sep 11, 2025
CVE-2025-40687
9.8 CRITICAL

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' …

Sep 11, 2025
CVE-2025-10250
5.0 MEDIUM

A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry Channel. …

Sep 11, 2025
CVE-2025-58321
10.0 CRITICAL

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Sep 11, 2025
CVE-2025-58320
7.3 HIGH

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Sep 11, 2025
CVE-2025-48041

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files …

Sep 11, 2025
CVE-2025-48040

Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects …

Sep 11, 2025
CVE-2025-48039

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with …

Sep 11, 2025
CVE-2025-48038

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with …

Sep 11, 2025
CVE-2025-9918

A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions) allows an authenticated attacker …

Sep 11, 2025
CVE-2025-9874
7.5 HIGH

The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6 via the 'uclwp_dashboard' shortcode. …

Sep 11, 2025
CVE-2025-9861
6.4 MEDIUM

The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'los_showposts' shortcode in all versions up to, and including, 1.8.5 …

Sep 11, 2025
CVE-2025-9860
6.4 MEDIUM

The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in all versions up to, and including, 1.1 due …

Sep 11, 2025
CVE-2025-9855
6.4 MEDIUM

The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_authors' shortcode in all versions up to, and including, 1.3.8 …

Sep 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.