CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9519
7.2 HIGH

The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 via the plugin's shortcodes. This …

Sep 4, 2025
CVE-2025-9518
7.2 HIGH

The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on the 'debug_path' parameter in all versions …

Sep 4, 2025
CVE-2025-9517
7.2 HIGH

The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This …

Sep 4, 2025
CVE-2025-9516
4.9 MEDIUM

The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This …

Sep 4, 2025
CVE-2025-9467

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of …

Sep 4, 2025
CVE-2025-6984
7.5 HIGH

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. …

Sep 4, 2025
CVE-2025-6085
7.2 HIGH

The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions …

Sep 4, 2025
CVE-2025-58701

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58700

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58699

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58698

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58697

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58696

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58695

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58694

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58358
7.5 HIGH

Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain a command injection vulnerability, caused by the unsanitized …

Sep 4, 2025
CVE-2025-58357
9.6 CRITICAL

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 contains a vulnerability in the chat page's script gadgets that …

Sep 4, 2025
CVE-2025-58355
7.7 HIGH

Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled …

Sep 4, 2025
CVE-2025-58171

Rejected reason: This CVE is a duplicate of another CVE.

Sep 4, 2025
CVE-2025-58064

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a …

Sep 4, 2025
CVE-2025-58057
7.5 HIGH

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, …

Sep 4, 2025
CVE-2025-43772

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not …

Sep 4, 2025
CVE-2025-36909
5.3 MEDIUM

Information disclosure

Sep 4, 2025
CVE-2025-36908
6.7 MEDIUM

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36907
7.3 HIGH

In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36906
7.8 HIGH

In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36905
7.8 HIGH

In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36904
9.8 CRITICAL

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

Sep 4, 2025
CVE-2025-36903
7.8 HIGH

In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution …

Sep 4, 2025
CVE-2025-36902
6.7 MEDIUM

In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36901
8.8 HIGH

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.

Sep 4, 2025
CVE-2025-36900
6.7 MEDIUM

In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalation of privilege with System …

Sep 4, 2025
CVE-2025-36899
8.4 HIGH

There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with …

Sep 4, 2025
CVE-2025-36898
7.8 HIGH

There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no …

Sep 4, 2025
CVE-2025-36897
9.8 CRITICAL

In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Sep 4, 2025
CVE-2025-36896
9.8 CRITICAL

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

Sep 4, 2025
CVE-2025-36895
7.5 HIGH

Information disclosure

Sep 4, 2025
CVE-2025-36894
7.5 HIGH

In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no …

Sep 4, 2025
CVE-2025-36893
5.5 MEDIUM

In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution …

Sep 4, 2025
CVE-2025-36892
7.5 HIGH

Denial of service

Sep 4, 2025
CVE-2025-36891
8.8 HIGH

Elevation of privilege

Sep 4, 2025
CVE-2025-36890
9.8 CRITICAL

Elevation of Privilege

Sep 4, 2025
CVE-2025-36887
7.8 HIGH

In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-2417
8.6 HIGH

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication Bypass.This issue affects e-Mutabakat: from 2.02.06 before v2.02.06.

Sep 4, 2025
CVE-2025-2411
8.6 HIGH

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass.This issue affects TaskPano: from s1.06.04 before v1.06.06.

Sep 4, 2025
CVE-2024-56190
7.8 HIGH

In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Sep 4, 2025
CVE-2024-56189
6.5 MEDIUM

In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Sep 4, 2025
CVE-2024-13073
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft TaskPano allows Cross-Site Scripting (XSS).This issue affects TaskPano: s1.06.04.

Sep 4, 2025
CVE-2024-13071
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-Mutabakat allows Cross-Site Scripting (XSS).This issue affects e-Mutabakat: from 2.02.05 …

Sep 4, 2025
CVE-2025-9928
7.3 HIGH

A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation …

Sep 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.