CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-37998
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output_userspace() This patch replaces the manual Netlink attribute iteration …

May 29, 2025
CVE-2025-37997
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4 contained three …

May 29, 2025
CVE-2025-37996
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in user_mem_abort() Commit fce886a60207 ("KVM: arm64: Plumb the pKVM …

May 29, 2025
CVE-2025-37995
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for module type kobjects In 'lookup_or_create_module_kobject()', an internal kobject …

May 29, 2025
CVE-2025-37994
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer access This patch ensures that the UCSI driver …

May 29, 2025
CVE-2025-37993
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize spin lock on device probe The spin lock tx_handling_spinlock in struct …

May 29, 2025
CVE-2025-33043
5.8 MEDIUM

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerability can potentially impact of …

May 29, 2025
CVE-2025-48047

An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

May 29, 2025
CVE-2025-48046

An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.

May 29, 2025
CVE-2025-48045

An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.

May 29, 2025
CVE-2025-48388
6.5 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used …

May 29, 2025
CVE-2025-5286
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 …

May 29, 2025
CVE-2025-5122
6.4 MEDIUM

The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.2.1 …

May 29, 2025
CVE-2025-4687

In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending …

May 29, 2025
CVE-2025-4670
6.4 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode …

May 29, 2025
CVE-2025-27151
4.7 MEDIUM

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in …

May 29, 2025
CVE-2024-52588
4.9 MEDIUM

Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching …

May 29, 2025
CVE-2025-5276
7.4 HIGH

All versions of the package mcp-markdownify-server are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function. An attacker can craft a prompt that, once …

May 29, 2025
CVE-2025-5273
6.5 MEDIUM

All versions of the package mcp-markdownify-server are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a …

May 29, 2025
CVE-2025-4583
5.4 MEDIUM

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-plugin` attribute in …

May 29, 2025
CVE-2025-3755
9.1 CRITICAL

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker …

May 29, 2025
CVE-2023-51756

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2023-51753

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2023-50338

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2023-49904

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2023-49604

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2023-49139

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2023-49137

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2023-48726

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2025-27706
3.4 LOW

CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with system administrator permissions can interfere …

May 28, 2025
CVE-2025-27703
6.0 MEDIUM

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific …

May 28, 2025
CVE-2025-27702
4.9 MEDIUM

CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who …

May 28, 2025
CVE-2022-47914

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-46739

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-46736

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-46735

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-46734

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-46729

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-46655

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-46419

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-46296

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-45878

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-45125

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-45120

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-45117

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-45114

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-44618

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-44614

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-44613

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-44609

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.