CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8419
5.3 MEDIUM

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is …

Aug 6, 2025
CVE-2025-30127
9.8 CRITICAL

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings …

Aug 6, 2025
CVE-2025-20332
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected …

Aug 6, 2025
CVE-2025-20331
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a stored XSS attack …

Aug 6, 2025
CVE-2025-20215
5.4 MEDIUM

A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of …

Aug 6, 2025
CVE-2025-53786
8.0 HIGH

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general …

Aug 6, 2025
CVE-2025-51532
7.5 HIGH

Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has …

Aug 6, 2025
CVE-2025-51531
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser …

Aug 6, 2025
CVE-2025-48394
4.7 MEDIUM

An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the …

Aug 6, 2025
CVE-2025-48393
5.7 MEDIUM

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This …

Aug 6, 2025
CVE-2024-8244
3.7 LOW

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) …

Aug 6, 2025
CVE-2025-51308
5.3 MEDIUM

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, …

Aug 6, 2025
CVE-2025-51306
6.5 MEDIUM

In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without expiration, due to incorrect …

Aug 6, 2025
CVE-2025-51040
7.5 HIGH

Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html endpoint in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, …

Aug 6, 2025
CVE-2025-50286
8.1 HIGH

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, …

Aug 6, 2025
CVE-2025-50234
6.5 MEDIUM

MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is …

Aug 6, 2025
CVE-2025-50233
6.5 MEDIUM

A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in …

Aug 6, 2025
CVE-2025-36020
5.9 MEDIUM

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.

Aug 6, 2025
CVE-2025-2028
6.5 MEDIUM

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

Aug 6, 2025
CVE-2024-52885
5.0 MEDIUM

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File …

Aug 6, 2025
CVE-2025-8616

A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue …

Aug 6, 2025
CVE-2025-3354
8.1 HIGH

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could …

Aug 6, 2025
CVE-2025-3320
8.1 HIGH

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could …

Aug 6, 2025
CVE-2025-23335
4.4 MEDIUM

NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a …

Aug 6, 2025
CVE-2025-23334
5.9 MEDIUM

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by sending …

Aug 6, 2025
CVE-2025-23333
5.9 MEDIUM

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by manipulating …

Aug 6, 2025
CVE-2025-23331
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value, leading to …

Aug 6, 2025
CVE-2025-23327
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through specially crafted inputs. A successful …

Aug 6, 2025
CVE-2025-23326
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through a specially crafted input. A …

Aug 6, 2025
CVE-2025-23325
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled recursion through a specially crafted input. A successful …

Aug 6, 2025
CVE-2025-23324
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a segmentation …

Aug 6, 2025
CVE-2025-23323
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a segmentation …

Aug 6, 2025
CVE-2025-23322
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a double free when a stream is cancelled before …

Aug 6, 2025
CVE-2025-23321
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero issue by issuing an invalid …

Aug 6, 2025
CVE-2025-23320
7.5 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause the shared memory limit to …

Aug 6, 2025
CVE-2025-23319
8.1 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending …

Aug 6, 2025
CVE-2025-23318
8.1 HIGH

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful …

Aug 6, 2025
CVE-2025-23317
9.1 CRITICAL

NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP …

Aug 6, 2025
CVE-2025-23311
9.8 CRITICAL

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requests. A successful exploit of this …

Aug 6, 2025
CVE-2025-23310
9.8 CRITICAL

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specially crafted inputs. A successful …

Aug 6, 2025
CVE-2025-5197
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting …

Aug 6, 2025
CVE-2025-46391
6.5 MEDIUM

CWE-284: Improper Access Control

Aug 6, 2025
CVE-2025-46390
7.5 HIGH

CWE-204: Observable Response Discrepancy

Aug 6, 2025
CVE-2025-46389
6.5 MEDIUM

CWE-620: Unverified Password Change

Aug 6, 2025
CVE-2025-46388
4.3 MEDIUM

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Aug 6, 2025
CVE-2025-46387
8.8 HIGH

CWE-639 Authorization Bypass Through User-Controlled Key

Aug 6, 2025
CVE-2025-46386
8.8 HIGH

CWE-639 Authorization Bypass Through User-Controlled Key

Aug 6, 2025
CVE-2025-8620
5.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This …

Aug 6, 2025
CVE-2025-7771

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation …

Aug 6, 2025
CVE-2025-6013
6.5 MEDIUM

Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple …

Aug 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.