CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6818
3.3 LOW

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_protect of the file /src/H5Ochunk.c. The manipulation leads to …

Jun 28, 2025
CVE-2023-29113
6.3 MEDIUM

The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with …

Jun 28, 2025
CVE-2023-28912
5.7 MEDIUM

The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access …

Jun 28, 2025
CVE-2023-28911
6.5 MEDIUM

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28910
8.0 HIGH

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled abortion flag eventually leading to bypassing …

Jun 28, 2025
CVE-2023-28909
8.0 HIGH

A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28908
5.4 MEDIUM

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28907
6.7 MEDIUM

There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to …

Jun 28, 2025
CVE-2023-28906
7.8 HIGH

A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative …

Jun 28, 2025
CVE-2023-28905
8.0 HIGH

A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability …

Jun 28, 2025
CVE-2023-28904
5.2 MEDIUM

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to …

Jun 28, 2025
CVE-2023-28903
3.3 LOW

An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause a …

Jun 28, 2025
CVE-2023-28902
3.3 LOW

An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service …

Jun 28, 2025
CVE-2025-1991
7.5 HIGH

IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processing packets.

Jun 28, 2025
CVE-2025-6817
3.3 LOW

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation …

Jun 28, 2025
CVE-2025-6816
3.3 LOW

A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based …

Jun 28, 2025
CVE-2025-5937
4.3 MEDIUM

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jun 28, 2025
CVE-2025-38086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nway_restart In mii_nway_restart() the code attempts to call mii->mdio_read …

Jun 28, 2025
CVE-2025-38085
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that …

Jun 28, 2025
CVE-2025-38084
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table …

Jun 28, 2025
CVE-2025-6755
8.8 HIGH

The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDeleteTheme() function in …

Jun 28, 2025
CVE-2025-5304
9.8 CRITICAL

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. …

Jun 28, 2025
CVE-2025-6252
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.9.1 …

Jun 28, 2025
CVE-2025-6381
8.8 HIGH

The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file() function. This makes …

Jun 28, 2025
CVE-2025-6379
8.8 HIGH

The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_live_fn() function. This …

Jun 28, 2025
CVE-2025-6350
6.4 MEDIUM

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ …

Jun 28, 2025
CVE-2025-53388

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53387

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53386

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53385

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53384

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53383

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53382

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53381

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53380

Rejected reason: Not used

Jun 28, 2025
CVE-2025-36027
5.4 MEDIUM

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Jun 28, 2025
CVE-2025-36026
4.3 MEDIUM

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the …

Jun 28, 2025
CVE-2024-52900
6.4 MEDIUM

IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to …

Jun 28, 2025
CVE-2024-39730
5.4 MEDIUM

IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to …

Jun 28, 2025
CVE-2024-36347
6.4 MEDIUM

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in …

Jun 27, 2025
CVE-2025-53098
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within the …

Jun 27, 2025
CVE-2025-53097
5.9 MEDIUM

Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent's `search_files` tool did not …

Jun 27, 2025
CVE-2025-6778
2.4 LOW

A vulnerability, which was classified as problematic, was found in code-projects Food Distributor Site 1.0. Affected is an unknown function of the file /admin/save_settings.php. The …

Jun 27, 2025
CVE-2025-6777
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Food Distributor Site 1.0. This issue affects some unknown processing of the file …

Jun 27, 2025
CVE-2025-6776
7.3 HIGH

A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the …

Jun 27, 2025
CVE-2025-6775
6.3 MEDIUM

A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file /app/api/v1/openvpn.py of the …

Jun 27, 2025
CVE-2025-6774
6.3 MEDIUM

A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is the function AddTemp of …

Jun 27, 2025
CVE-2025-53094

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage …

Jun 27, 2025
CVE-2025-6773
5.3 MEDIUM

A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_input_dir of …

Jun 27, 2025
CVE-2025-6772
7.3 HIGH

A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import. …

Jun 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.