CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8646
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8645
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8644
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8643
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8642
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8641
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8640
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8639
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected Kenwood DMX958XR devices. Authentication is not …

Aug 6, 2025
CVE-2025-8638
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8637
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8636
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8635
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8634
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8633
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8632
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8631
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8630
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8629
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8628
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-7502
6.4 MEDIUM

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, …

Aug 6, 2025
CVE-2025-7036
7.5 HIGH

The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due …

Aug 6, 2025
CVE-2025-6986
6.5 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions …

Aug 6, 2025
CVE-2025-6690
6.4 MEDIUM

The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 …

Aug 6, 2025
CVE-2025-6259
6.4 MEDIUM

The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view shortcode in all versions up to, and including, 1.2.3 due …

Aug 6, 2025
CVE-2025-6256
6.4 MEDIUM

The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ parameter in all versions up to, and including, 1.2.5 due …

Aug 6, 2025
CVE-2025-54623
6.3 MEDIUM

Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54622
8.3 HIGH

Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54621
5.3 MEDIUM

Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.

Aug 6, 2025
CVE-2025-54620
5.5 MEDIUM

Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54619
5.3 MEDIUM

Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.

Aug 6, 2025
CVE-2025-54618
5.7 MEDIUM

Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54617
6.8 MEDIUM

Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.

Aug 6, 2025
CVE-2025-54616
4.0 MEDIUM

Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54615
6.2 MEDIUM

Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54614
6.2 MEDIUM

Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54613
5.9 MEDIUM

Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

Aug 6, 2025
CVE-2025-54612
5.9 MEDIUM

Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

Aug 6, 2025
CVE-2025-54611
7.3 HIGH

EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54610
5.4 MEDIUM

Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54609
5.4 MEDIUM

Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54608
6.2 MEDIUM

Vulnerability that allows setting screen rotation direction without permission verification in the screen management module. Impact: Successful exploitation of this vulnerability may cause device screen …

Aug 6, 2025
CVE-2025-54607
7.7 HIGH

Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54606
7.3 HIGH

Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Aug 6, 2025
CVE-2025-54655
8.1 HIGH

Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module.

Aug 6, 2025
CVE-2025-54653
8.4 HIGH

Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization file module.

Aug 6, 2025
CVE-2025-54652
8.4 HIGH

Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization module.

Aug 6, 2025
CVE-2025-54884

Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and getSecureRandomInt functions in security-kit …

Aug 6, 2025
CVE-2025-54883

Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the getSecureRandomInt function in security-kit versions prior …

Aug 6, 2025
CVE-2025-54879
5.3 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through …

Aug 6, 2025
CVE-2025-54876

The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local …

Aug 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.