CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5004
7.3 HIGH

A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add_course.php. …

May 20, 2025
CVE-2025-4436

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 20, 2025
CVE-2025-5003
7.3 HIGH

A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /semester_ajax.php. …

May 20, 2025
CVE-2025-5002
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. …

May 20, 2025
CVE-2025-5001
3.3 LOW

A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The …

May 20, 2025
CVE-2025-5000
6.3 MEDIUM

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the …

May 20, 2025
CVE-2025-4999
6.3 MEDIUM

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function sub_4153FC of …

May 20, 2025
CVE-2025-4998
6.5 MEDIUM

A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of …

May 20, 2025
CVE-2025-44898
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.

May 20, 2025
CVE-2025-44897
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.

May 20, 2025
CVE-2025-44896
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.

May 20, 2025
CVE-2025-44894
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.

May 20, 2025
CVE-2025-44891
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.

May 20, 2025
CVE-2025-44883
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.

May 20, 2025
CVE-2025-44882
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

May 20, 2025
CVE-2025-44880
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

May 20, 2025
CVE-2025-4997
6.5 MEDIUM

A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function UpdateWanParams/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList/Edit_BasicSSID/Edit_GuestSSIDFor2P4G/Edit_BasicSSID_5G/SetAPInfoById of the file /goform/aspForm of …

May 20, 2025
CVE-2025-48056
5.3 MEDIUM

Hubble is a fully distributed networking and security observability platform for cloud native workloads. Prior to version 1.17.2, a network attacker could inject malicious control …

May 20, 2025
CVE-2025-44893
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.

May 20, 2025
CVE-2025-44890
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.

May 20, 2025
CVE-2025-44888
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.

May 20, 2025
CVE-2025-44887
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

May 20, 2025
CVE-2025-44886
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.

May 20, 2025
CVE-2025-44885
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.

May 20, 2025
CVE-2025-44884
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.

May 20, 2025
CVE-2025-44881
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

May 20, 2025
CVE-2025-4996
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add …

May 20, 2025
CVE-2025-47290
5.9 MEDIUM

containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially …

May 20, 2025
CVE-2025-4364

The affected products could allow an unauthenticated attacker to access system information that could enable further access to sensitive files and obtain administrative credentials.

May 20, 2025
CVE-2025-48391
7.7 HIGH

In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

May 20, 2025
CVE-2025-47854
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page

May 20, 2025
CVE-2025-47853
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible

May 20, 2025
CVE-2025-47852
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible

May 20, 2025
CVE-2025-47851
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible

May 20, 2025
CVE-2025-47850
4.3 MEDIUM

In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

May 20, 2025
CVE-2025-47277
9.8 CRITICAL

vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the …

May 20, 2025
CVE-2025-46725
9.8 CRITICAL

Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas eval() through `compute_from_docs()`. As a result, …

May 20, 2025
CVE-2025-46724
9.8 CRITICAL

Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval()`. If fed by untrusted user …

May 20, 2025
CVE-2025-37991
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that on parisc a SIGFPE exception will crash …

May 20, 2025
CVE-2025-37990
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The function brcmf_usb_dl_writeimage() calls the function brcmf_usb_dl_cmd() …

May 20, 2025
CVE-2025-37989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: leds: fix memory leak A network restart test on a router led to …

May 20, 2025
CVE-2025-37988
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount() Normally do_lock_mount(path, _) is locking …

May 20, 2025
CVE-2025-37987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent possible adminq overflow/stuck condition The pds_core's adminq is protected by the adminq_lock, which …

May 20, 2025
CVE-2025-37986
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Invalidate USB device pointers on partner unregistration To avoid using invalid USB …

May 20, 2025
CVE-2025-37985
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wdm_open and wdm_wwan_port_stop Clearing WDM_WWAN_IN_USE must be the last action …

May 20, 2025
CVE-2025-37984
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow …

May 20, 2025
CVE-2025-37983
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: qibfs: fix _another_ leak failure to allocate inode => leaked dentry... this one had been …

May 20, 2025
CVE-2025-22157
8.8 HIGH

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, …

May 20, 2025
CVE-2025-44084
9.8 CRITICAL

D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and …

May 20, 2025
CVE-2025-37982
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: fix memory leak in wl1251_tx_work The skb dequeued from tx_queue is lost when …

May 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.