CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38737
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before …

Sep 5, 2025
CVE-2025-38736
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization Syzbot reported shift-out-of-bounds exception …

Sep 5, 2025
CVE-2025-38735
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gve: prevent ethtool ops after shutdown A crash can occur if an ethtool operation is …

Sep 5, 2025
CVE-2025-38734
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() BPF CI testing report a UAF issue: [ …

Sep 5, 2025
CVE-2025-38733
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Do not map lowcore with identity mapping Since the identity mapping is pinned to …

Sep 5, 2025
CVE-2025-38732
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject: don't leak dst refcount for loopback packets recent patches to add a WARN() …

Sep 5, 2025
CVE-2025-38731
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix vm_bind_ioctl double free bug If the argument check during an array bind fails, …

Sep 5, 2025
CVE-2025-35452
9.8 CRITICAL

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.

Sep 5, 2025
CVE-2025-35451
9.8 CRITICAL

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening …

Sep 5, 2025
CVE-2025-30200
6.3 MEDIUM

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.

Sep 5, 2025
CVE-2025-30199
7.2 HIGH

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot …

Sep 5, 2025
CVE-2025-30198
6.3 MEDIUM

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

Sep 5, 2025
CVE-2025-10014
3.1 LOW

A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address …

Sep 5, 2025
CVE-2025-9999

Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker …

Sep 5, 2025
CVE-2025-9998

The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulnerability to send specially crafted messages to …

Sep 5, 2025
CVE-2025-58628
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous miraculous allows Blind SQL Injection.This issue affects Miraculous: from …

Sep 5, 2025
CVE-2025-58440

Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager.

Sep 5, 2025
CVE-2025-58214
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri indutri allows PHP Local File Inclusion.This issue …

Sep 5, 2025
CVE-2025-58206
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach maxcoach allows PHP Local File Inclusion.This issue …

Sep 5, 2025
CVE-2025-57889
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery inpost-gallery allows PHP Local File Inclusion.This …

Sep 5, 2025
CVE-2025-54744
6.5 MEDIUM

Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.6.15.

Sep 5, 2025
CVE-2025-53571
6.5 MEDIUM

Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.6.

Sep 5, 2025
CVE-2025-53307
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from …

Sep 5, 2025
CVE-2025-49401
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue affects smart SEO: from n/a through <= 4.0.

Sep 5, 2025
CVE-2025-48317
7.5 HIGH

Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay allows Path Traversal.This issue affects WooCommerce Payment Gateway for Saferpay: from n/a …

Sep 5, 2025
CVE-2025-48105
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Boiardt Easy Flash Embed easy-flash-embed allows Stored XSS.This issue affects Easy Flash …

Sep 5, 2025
CVE-2025-48104
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player allows Stored XSS.This issue affects Floating Window Music Player: from n/a through <= …

Sep 5, 2025
CVE-2025-48103
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mulscully Today's Date Inserter todays-date-inserter allows Stored XSS.This issue affects Today's Date Inserter: …

Sep 5, 2025
CVE-2025-48102
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gourl GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership gourl-bitcoin-payment-gateway-paid-downloads-membership allows Stored …

Sep 5, 2025
CVE-2025-32320
7.8 HIGH

In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of …

Sep 5, 2025
CVE-2025-32318
8.8 HIGH

In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with …

Sep 5, 2025
CVE-2025-32317
5.5 MEDIUM

In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution …

Sep 5, 2025
CVE-2025-32316
5.5 MEDIUM

In gralloc4, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no …

Sep 5, 2025
CVE-2025-27003
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments quick-paypal-payments allows Cross Site Request Forgery.This issue affects Quick Paypal Payments: from n/a through <= …

Sep 5, 2025
CVE-2025-26461
3.3 LOW

In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the user attempts to close the app …

Sep 5, 2025
CVE-2025-26434
5.5 MEDIUM

In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional …

Sep 5, 2025
CVE-2024-0028
5.5 MEDIUM

In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permission check. This could lead …

Sep 5, 2025
CVE-2025-10013
6.3 MEDIUM

A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao-para-o-seb. Performing manipulation results in improper access …

Sep 5, 2025
CVE-2025-58780
7.2 HIGH

index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately …

Sep 5, 2025
CVE-2025-10012
6.3 MEDIUM

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation …

Sep 5, 2025
CVE-2025-8695
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad NetGIS Server allows Reflected XSS.This issue affects NetGIS Server: from …

Sep 5, 2025
CVE-2025-58887
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | andré martin - it solutions & research UG Course Booking …

Sep 5, 2025
CVE-2025-58886
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tan Nguyen Instant Locations instant-locations allows Stored XSS.This issue affects Instant Locations: from …

Sep 5, 2025
CVE-2025-58884
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivan Drago vipdrv vipdrv-vip-test-drive allows Stored XSS.This issue affects vipdrv: from n/a through …

Sep 5, 2025
CVE-2025-58883
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One search-cloud-one allows Stored XSS.This issue affects Search Cloud …

Sep 5, 2025
CVE-2025-58882
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider simple-text-slider allows Stored XSS.This issue affects Simple Text Slider: …

Sep 5, 2025
CVE-2025-58881
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery new-simple-gallery allows Blind SQL Injection.This issue affects …

Sep 5, 2025
CVE-2025-58880
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reubenthiessen Translate This gTranslate Shortcode translate-this-google-translate-web-element-shortcode allows Stored XSS.This issue affects Translate This …

Sep 5, 2025
CVE-2025-58878
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in usamafarooq Woocommerce Gifts Product woo-gift-product allows Cross Site Request Forgery.This issue affects Woocommerce Gifts Product: from n/a through <= …

Sep 5, 2025
CVE-2025-58876
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Aghdam Aparat Video Shortcode aparat-shortcode allows Stored XSS.This issue affects Aparat Video …

Sep 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.