CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21025
5.1 MEDIUM

Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.

Sep 3, 2025
CVE-2023-3666
3.3 LOW

The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Sep 3, 2025
CVE-2023-21483
6.4 MEDIUM

Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.

Sep 3, 2025
CVE-2023-21482
6.1 MEDIUM

Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to …

Sep 3, 2025
CVE-2023-21481
5.4 MEDIUM

Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.

Sep 3, 2025
CVE-2023-21480
8.5 HIGH

Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.

Sep 3, 2025
CVE-2023-21479
5.3 MEDIUM

Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a …

Sep 3, 2025
CVE-2023-21478
6.0 MEDIUM

Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

Sep 3, 2025
CVE-2023-21477
7.9 HIGH

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

Sep 3, 2025
CVE-2023-21476
8.0 HIGH

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

Sep 3, 2025
CVE-2023-21475
8.0 HIGH

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

Sep 3, 2025
CVE-2023-21474
6.3 MEDIUM

Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.

Sep 3, 2025
CVE-2023-21473
6.8 MEDIUM

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

Sep 3, 2025
CVE-2023-21472
6.8 MEDIUM

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

Sep 3, 2025
CVE-2023-21471
4.0 MEDIUM

Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

Sep 3, 2025
CVE-2023-21470
4.0 MEDIUM

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.

Sep 3, 2025
CVE-2023-21469
4.0 MEDIUM

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.

Sep 3, 2025
CVE-2023-21468
5.9 MEDIUM

Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.

Sep 3, 2025
CVE-2023-21467
4.6 MEDIUM

Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.

Sep 3, 2025
CVE-2023-21466
5.3 MEDIUM

PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.

Sep 3, 2025
CVE-2025-9785

PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an …

Sep 3, 2025
CVE-2025-58351
6.8 MEDIUM

Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature which facilitates local file system storage capabilities …

Sep 3, 2025
CVE-2025-58176
8.8 HIGH

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click Remote Code …

Sep 3, 2025
CVE-2025-58170

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58169

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58168

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58167

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58166

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58165

Rejected reason: This CVE is a duplicate of another CVE, CVE-2025-58163.

Sep 3, 2025
CVE-2025-58164

Rejected reason: This CVE is a duplicate of another CVE, CVE-2025-58163.

Sep 3, 2025
CVE-2025-9848
7.3 HIGH

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such …

Sep 3, 2025
CVE-2025-9847
6.3 MEDIUM

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the …

Sep 3, 2025
CVE-2025-7039
3.7 LOW

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform …

Sep 3, 2025
CVE-2025-58163
8.8 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untrusted data vulnerability …

Sep 3, 2025
CVE-2025-9845
3.5 LOW

A vulnerability has been found in code-projects Fruit Shop Management System 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. Such …

Sep 3, 2025
CVE-2025-9843
5.3 MEDIUM

A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This manipulation causes information …

Sep 3, 2025
CVE-2025-57806

Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local …

Sep 3, 2025
CVE-2025-9842
5.3 MEDIUM

A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. The manipulation results in information …

Sep 3, 2025
CVE-2025-9841
6.3 MEDIUM

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of …

Sep 3, 2025
CVE-2025-9260
6.5 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 …

Sep 3, 2025
CVE-2025-54588
7.5 HIGH

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Versions 1.34.0 through 1.34.4 and 1.35.0 contain a …

Sep 3, 2025
CVE-2025-9840
6.3 MEDIUM

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of …

Sep 2, 2025
CVE-2025-9839
7.3 HIGH

A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing …

Sep 2, 2025
CVE-2025-9838
7.3 HIGH

A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument …

Sep 2, 2025
CVE-2025-26416
9.8 CRITICAL

In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of …

Sep 2, 2025
CVE-2025-22442
7.0 HIGH

In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created work profile due to a race condition. …

Sep 2, 2025
CVE-2025-22439
7.3 HIGH

In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission check. This could lead …

Sep 2, 2025
CVE-2025-22438
7.8 HIGH

In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. …

Sep 2, 2025
CVE-2025-22437
7.8 HIGH

In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code. This …

Sep 2, 2025
CVE-2025-22435
9.8 CRITICAL

In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no …

Sep 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.