CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10068
7.3 HIGH

A flaw has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/admin_forum/add_views.php. Executing manipulation of the argument …

Sep 7, 2025
CVE-2025-10067
4.3 MEDIUM

A vulnerability was detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/empty_table.php. Performing manipulation …

Sep 7, 2025
CVE-2025-36100
5.1 MEDIUM

IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 …

Sep 7, 2025
CVE-2025-10066
4.3 MEDIUM

A security vulnerability has been detected in itsourcecode POS Point of Sale System 1.0. The affected element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dymanic_table.php. …

Sep 7, 2025
CVE-2025-10065
4.3 MEDIUM

A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_th.php. This manipulation of …

Sep 7, 2025
CVE-2025-10064
4.3 MEDIUM

A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown processing of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_two_headers.php. The …

Sep 7, 2025
CVE-2025-10063
4.3 MEDIUM

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.php. The manipulation of the …

Sep 6, 2025
CVE-2025-10062
7.3 HIGH

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument …

Sep 6, 2025
CVE-2025-58445
7.5 HIGH

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through …

Sep 6, 2025
CVE-2025-58443
9.1 CRITICAL

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to …

Sep 6, 2025
CVE-2025-58446
7.5 HIGH

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very …

Sep 6, 2025
CVE-2025-58438

internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vulnerability in the File.download() …

Sep 6, 2025
CVE-2025-0034
4.7 MEDIUM

Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_SPATIAL_PART and cause read or write past the end of …

Sep 6, 2025
CVE-2025-0032
7.2 HIGH

Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss …

Sep 6, 2025
CVE-2025-0011
3.3 LOW

Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in …

Sep 6, 2025
CVE-2025-0010
6.1 MEDIUM

An out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting in loss of confidentiality, integrity, …

Sep 6, 2025
CVE-2025-0009
5.5 MEDIUM

A NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentially resulting in a …

Sep 6, 2025
CVE-2024-36354
7.5 HIGH

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant …

Sep 6, 2025
CVE-2024-36352
8.4 HIGH

Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial …

Sep 6, 2025
CVE-2024-36346
6.0 MEDIUM

Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a …

Sep 6, 2025
CVE-2024-36342
8.8 HIGH

Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execution.

Sep 6, 2025
CVE-2024-36331
3.2 LOW

Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity.

Sep 6, 2025
CVE-2024-36326
8.4 HIGH

Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a standby state, potentially resulting in a loss …

Sep 6, 2025
CVE-2024-21970
4.4 MEDIUM

Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a …

Sep 6, 2025
CVE-2024-21947
7.5 HIGH

Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in arbitrary code execution at …

Sep 6, 2025
CVE-2023-31365
3.9 LOW

An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reserved dRAM area resulting in …

Sep 6, 2025
CVE-2023-31351
5.3 MEDIUM

Improper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integrity.

Sep 6, 2025
CVE-2023-31330
2.5 LOW

An out-of-bounds read in the ASP could allow a privileged attacker with access to a malicious bootloader to potentially read sensitive memory resulting in loss …

Sep 6, 2025
CVE-2023-31326
2.8 LOW

Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution environment (TEE) driver, potentially leading …

Sep 6, 2025
CVE-2023-31325
7.2 HIGH

Improper isolation of shared resources on System-on-a-chip (SOC) could a privileged attacker to tamper with the contents of the PSP reserved DRAM region potentially resulting …

Sep 6, 2025
CVE-2023-31322
8.7 HIGH

Type confusion in the ASP could allow an attacker to pass a malformed argument to the Reliability, Availability, and Serviceability trusted application (RAS TA) potentially …

Sep 6, 2025
CVE-2023-31306
3.3 LOW

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management …

Sep 6, 2025
CVE-2023-20516
3.3 LOW

Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentially resulting in loss of confidentiality …

Sep 6, 2025
CVE-2021-46750
3.0 LOW

Failure to validate the address and size in TEE (Trusted Execution Environment) may allow a malicious x86 attacker to send malformed messages to the graphics …

Sep 6, 2025
CVE-2021-26377
4.1 MEDIUM

Insufficient parameter validation while allocating process space in the Trusted OS (TOS) may allow for a malicious userspace process to trigger an integer overflow, leading …

Sep 6, 2025
CVE-2025-10034
8.8 HIGH

A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_response.cg of the component httpd. Performing manipulation of the …

Sep 6, 2025
CVE-2025-10033
7.3 HIGH

A vulnerability has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin. Such manipulation of the argument …

Sep 6, 2025
CVE-2025-10032
4.3 MEDIUM

A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown function of the file /index.php. The manipulation …

Sep 6, 2025
CVE-2025-10031
7.3 HIGH

A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. The manipulation …

Sep 6, 2025
CVE-2025-10030
7.3 HIGH

A weakness has been identified in Campcodes Grocery Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=save_receiving. Executing manipulation …

Sep 6, 2025
CVE-2025-10029
3.5 LOW

A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation …

Sep 6, 2025
CVE-2025-9961

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500. The exploit can only be conducted via …

Sep 6, 2025
CVE-2025-10046
4.9 MEDIUM

The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, …

Sep 6, 2025
CVE-2025-10028
3.5 LOW

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the …

Sep 6, 2025
CVE-2025-6757
6.4 MEDIUM

The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpwe' shortcode in all versions up to, and …

Sep 6, 2025
CVE-2025-9493
6.4 MEDIUM

The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.14 …

Sep 6, 2025
CVE-2025-9442
6.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChannel’ parameter in all versions up to, and including, 1.1.5 …

Sep 6, 2025
CVE-2025-9126
6.4 MEDIUM

The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.1 …

Sep 6, 2025
CVE-2025-8722
6.4 MEDIUM

The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widgets in all versions up to, and …

Sep 6, 2025
CVE-2025-8564
6.4 MEDIUM

The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.7 …

Sep 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.