CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48845

Rejected reason: Not used

May 28, 2025
CVE-2025-48844

Rejected reason: Not used

May 28, 2025
CVE-2025-48843

Rejected reason: Not used

May 28, 2025
CVE-2025-48842

Rejected reason: Not used

May 28, 2025
CVE-2025-48841

Rejected reason: Not used

May 28, 2025
CVE-2023-41839

Rejected reason: Not used

May 28, 2025
CVE-2025-25029
4.9 MEDIUM

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

May 28, 2025
CVE-2025-25026
4.3 MEDIUM

IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.

May 28, 2025
CVE-2025-25025
4.3 MEDIUM

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This …

May 28, 2025
CVE-2025-2826
2.6 LOW

n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on …

May 27, 2025
CVE-2025-2796
5.3 MEDIUM

On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. …

May 27, 2025
CVE-2024-45094
5.5 MEDIUM

IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code …

May 27, 2025
CVE-2024-11185
6.5 MEDIUM

On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, …

May 27, 2025
CVE-2022-21200

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 27, 2025
CVE-2022-21150

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 27, 2025
CVE-2025-40911
6.5 MEDIUM

Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass …

May 27, 2025
CVE-2025-32440
10.0 CRITICAL

NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update …

May 27, 2025
CVE-2025-5283
5.4 MEDIUM

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 27, 2025
CVE-2025-5281
5.4 MEDIUM

Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium …

May 27, 2025
CVE-2025-5280
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

May 27, 2025
CVE-2025-5279

When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. An …

May 27, 2025
CVE-2025-5278
4.4 MEDIUM

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside …

May 27, 2025
CVE-2025-5222
7.0 HIGH

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag …

May 27, 2025
CVE-2025-5198
5.0 MEDIUM

A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of …

May 27, 2025
CVE-2025-5067
5.4 MEDIUM

Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

May 27, 2025
CVE-2025-5066
6.5 MEDIUM

Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI …

May 27, 2025
CVE-2025-5065
6.5 MEDIUM

Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

May 27, 2025
CVE-2025-5064
5.4 MEDIUM

Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

May 27, 2025
CVE-2025-5063
8.8 HIGH

Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 27, 2025
CVE-2025-46173
6.1 MEDIUM

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.

May 27, 2025
CVE-2025-45529
7.1 HIGH

An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to …

May 27, 2025
CVE-2024-13966
7.3 HIGH

ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should …

May 27, 2025
CVE-2025-5252
7.3 HIGH

A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-subadmin.php. …

May 27, 2025
CVE-2025-45475
5.4 MEDIUM

maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

May 27, 2025
CVE-2024-49197
6.5 MEDIUM

An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. …

May 27, 2025
CVE-2025-5251
7.3 HIGH

A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. …

May 27, 2025
CVE-2025-5250
7.3 HIGH

A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of the file …

May 27, 2025
CVE-2025-5249
7.3 HIGH

A vulnerability has been found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

May 27, 2025
CVE-2025-48057
9.8 CRITICAL

Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to …

May 27, 2025
CVE-2025-23247
4.4 MEDIUM

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow …

May 27, 2025
CVE-2025-22377
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, …

May 27, 2025
CVE-2024-49196
7.5 HIGH

An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of Service.

May 27, 2025
CVE-2025-5248
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affected is an unknown function of the file /bwdates-reports-details.php. …

May 27, 2025
CVE-2025-48370

auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require …

May 27, 2025
CVE-2025-27701
5.5 MEDIUM

In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will …

May 27, 2025
CVE-2025-27700
8.4 HIGH

There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional …

May 27, 2025
CVE-2024-56193
5.1 MEDIUM

There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no additional execution …

May 27, 2025
CVE-2022-21138

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 27, 2025
CVE-2022-0003

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 27, 2025
CVE-2025-5247
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \view\url.go. The …

May 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.