CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9277
6.4 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_replace expression in all versions up to, and …

Aug 26, 2025
CVE-2025-57820

Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse …

Aug 26, 2025
CVE-2025-35115
8.1 HIGH

Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of …

Aug 26, 2025
CVE-2025-35114
7.5 HIGH

Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of …

Aug 26, 2025
CVE-2025-35113
5.9 MEDIUM

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by …

Aug 26, 2025
CVE-2025-35112
4.1 MEDIUM

Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and …

Aug 26, 2025
CVE-2025-26417
4.0 MEDIUM

In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could …

Aug 26, 2025
CVE-2025-22413
4.0 MEDIUM

In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local information …

Aug 26, 2025
CVE-2025-22412
8.8 HIGH

In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote …

Aug 26, 2025
CVE-2025-22411
8.8 HIGH

In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) …

Aug 26, 2025
CVE-2025-22410
8.4 HIGH

In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of …

Aug 26, 2025
CVE-2025-22409
8.4 HIGH

In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation …

Aug 26, 2025
CVE-2025-22408
9.8 CRITICAL

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code …

Aug 26, 2025
CVE-2025-22407
5.5 MEDIUM

In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local information …

Aug 26, 2025
CVE-2025-22406
8.4 HIGH

In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation …

Aug 26, 2025
CVE-2025-22405
8.4 HIGH

In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of …

Aug 26, 2025
CVE-2025-22404
8.4 HIGH

In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation …

Aug 26, 2025
CVE-2025-22403
9.8 CRITICAL

In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code …

Aug 26, 2025
CVE-2025-0093
7.5 HIGH

In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with …

Aug 26, 2025
CVE-2025-0092
6.5 MEDIUM

In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with …

Aug 26, 2025
CVE-2025-0086
6.2 MEDIUM

In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to local information …

Aug 26, 2025
CVE-2025-0084
8.8 HIGH

In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over …

Aug 26, 2025
CVE-2025-0083
4.0 MEDIUM

In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information …

Aug 26, 2025
CVE-2025-0082
5.5 MEDIUM

In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confused deputy. This could lead …

Aug 26, 2025
CVE-2025-0081
7.5 HIGH

In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to remote denial of service …

Aug 26, 2025
CVE-2025-0080
7.8 HIGH

In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack. This could lead to local escalation …

Aug 26, 2025
CVE-2025-0079
7.8 HIGH

In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error in the code. This …

Aug 26, 2025
CVE-2025-0078
8.8 HIGH

In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to local …

Aug 26, 2025
CVE-2025-0075
9.8 CRITICAL

In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code …

Aug 26, 2025
CVE-2025-0074
9.8 CRITICAL

In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code …

Aug 26, 2025
CVE-2024-49740
5.5 MEDIUM

In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution …

Aug 26, 2025
CVE-2023-21125
8.0 HIGH

In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of …

Aug 26, 2025
CVE-2025-9492
7.3 HIGH

A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the file /addclient1.php. Executing manipulation of the argument …

Aug 26, 2025
CVE-2024-47192
5.3 MEDIUM

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that …

Aug 26, 2025
CVE-2024-35203
6.1 MEDIUM

Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via …

Aug 26, 2025
CVE-2025-55443
9.1 CRITICAL

Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files …

Aug 26, 2025
CVE-2025-52353
9.8 CRITICAL

An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload …

Aug 26, 2025
CVE-2025-50971
7.5 HIGH

Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.

Aug 26, 2025
CVE-2025-9478
8.8 HIGH

Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 26, 2025
CVE-2025-50975
5.4 MEDIUM

IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr, allowing …

Aug 26, 2025
CVE-2025-23315
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious data created by an attacker could cause a …

Aug 26, 2025
CVE-2025-23314
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection …

Aug 26, 2025
CVE-2025-23313
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection …

Aug 26, 2025
CVE-2025-23312
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker could cause a code …

Aug 26, 2025
CVE-2025-23307
7.8 HIGH

NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. A successful exploit of …

Aug 26, 2025
CVE-2025-57818
6.3 MEDIUM

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to version 2.0.1, a server-side request forgery (SSRF) vulnerability was discovered in Firecrawl's webhook …

Aug 26, 2025
CVE-2025-57803
7.5 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit …

Aug 26, 2025
CVE-2025-55298
7.5 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability …

Aug 26, 2025
CVE-2025-50976
6.1 MEDIUM

IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query parameters, resulting in a reflected cross-site …

Aug 26, 2025
CVE-2025-9491
7.8 HIGH

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. …

Aug 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.