CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-37981
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Use is_kdump_kernel() to check for kdump The smartpqi driver checks the reset_devices variable …

May 20, 2025
CVE-2025-37980
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix resource leak in blk_register_queue() error path When registering a queue fails after blk_mq_sysfs_register() …

May 20, 2025
CVE-2025-37979
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix sc7280 lpass potential buffer overflow Case values introduced in commit 5f78e1fb7a3e ("ASoC: …

May 20, 2025
CVE-2025-37978
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: integrity: Do not call set_page_dirty_lock() Placing multiple protection information buffers inside the same page …

May 20, 2025
CVE-2025-37977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set If dma-coherent property isn't set …

May 20, 2025
CVE-2025-37976

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 20, 2025
CVE-2025-37975
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv: module: Fix out-of-bounds relocation access The current code allows rel[j] to access one element …

May 20, 2025
CVE-2025-37974
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix missing check for zpci_create_device() error return The zpci_create_device() function returns an error pointer …

May 20, 2025
CVE-2025-37973
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation Currently during the multi-link element defragmentation …

May 20, 2025
CVE-2025-37972
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: mtk-pmic-keys - fix possible null pointer dereference In mtk_pmic_keys_probe, the regs parameter is only …

May 20, 2025
CVE-2025-37971
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: bcm2835-camera: Initialise dev in v4l2_dev Commit 42a2f6664e18 ("staging: vc04_services: Move global g_state to vchiq_state") …

May 20, 2025
CVE-2025-37970
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo Prevent st_lsm6dsx_read_fifo from falling in an infinite …

May 20, 2025
CVE-2025-37969
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo Prevent st_lsm6dsx_read_tagged_fifo from falling in an infinite …

May 20, 2025
CVE-2025-37968
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: light: opt3001: fix deadlock due to concurrent flag access The threaded IRQ function in …

May 20, 2025
CVE-2025-37967
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix deadlock This patch introduces the ucsi_con_mutex_lock / ucsi_con_mutex_unlock functions to …

May 20, 2025
CVE-2025-37966
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix kernel crash due to PR_SET_TAGGED_ADDR_CTRL When userspace does PR_SET_TAGGED_ADDR_CTRL, but Supm extension is …

May 20, 2025
CVE-2025-37965
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix invalid context error in dml helper [Why] "BUG: sleeping function called from invalid …

May 20, 2025
CVE-2025-48018
7.5 HIGH

An authenticated user can modify application state data.

May 20, 2025
CVE-2025-48017
9.0 CRITICAL

Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files

May 20, 2025
CVE-2025-48016
4.3 MEDIUM

OpenFlow discovery protocol can exhaust resources because it is not rate limited

May 20, 2025
CVE-2025-48015
3.7 LOW

Failed login response could be different depending on whether the username was local or central.

May 20, 2025
CVE-2025-48014
7.5 HIGH

Password guessing limits could be bypassed when using LDAP authentication.

May 20, 2025
CVE-2025-37964
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr: There is a window …

May 20, 2025
CVE-2025-37963
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users Support for eBPF programs loaded …

May 20, 2025
CVE-2025-37962
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leak in parse_lease_state() The previous patch that added bounds check for create …

May 20, 2025
CVE-2025-37961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix uninit-value for saddr in do_output_route4 syzbot reports for uninit-value for the saddr argument …

May 20, 2025
CVE-2025-37960
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memblock: Accept allocated memory before use in memblock_double_array() When increasing the array size in memblock_double_array() …

May 20, 2025
CVE-2025-37959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redirect packets to a device …

May 20, 2025
CVE-2025-37958
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix dereferencing invalid pmd migration entry When migrating a THP, concurrent access to the …

May 20, 2025
CVE-2025-37957
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception Previously, commit ed129ec9057f ("KVM: x86: forcibly …

May 20, 2025
CVE-2025-37956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to ksmbd server. …

May 20, 2025
CVE-2025-37955
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable() The selftests added to our CI by Bui …

May 20, 2025
CVE-2025-37954
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: Avoid race in open_cached_dir with lease breaks A pre-existing valid cfid returned from …

May 20, 2025
CVE-2025-37953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sch_htb: make htb_deactivate() idempotent Alan reported a NULL pointer dereference in htb_next_rb_node() after we made …

May 20, 2025
CVE-2025-37952
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file …

May 20, 2025
CVE-2025-37951
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Add job to pending list if the reset was skipped When a CL/CSD job …

May 20, 2025
CVE-2025-37950
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix panic in failed foilio allocation commit 7e119cff9d0a ("ocfs2: convert w_pages to w_folios") and …

May 20, 2025
CVE-2025-37949
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xenbus: Use kref to track req lifetime Marek reported seeing a NULL pointer fault in …

May 20, 2025
CVE-2025-37948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Add BHB mitigation to the epilogue for cBPF programs A malicious BPF program …

May 20, 2025
CVE-2025-37947
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write …

May 20, 2025
CVE-2025-37946
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs With commit bcb5d6c76903 ("s390/pci: …

May 20, 2025
CVE-2025-37945
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY DSA …

May 20, 2025
CVE-2025-37944
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process Currently, ath12k_dp_mon_srng_process uses ath12k_hal_srng_src_get_next_entry to fetch the …

May 20, 2025
CVE-2025-37943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets …

May 20, 2025
CVE-2025-37942

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 20, 2025
CVE-2025-37941
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd937x: fix a potential memory leak in wcd937x_soc_codec_probe() When snd_soc_dapm_new_controls() or snd_soc_dapm_add_routes() fails, …

May 20, 2025
CVE-2025-37940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ftrace: Add cond_resched() to ftrace_graph_set_hash() When the kernel contains a large number of functions that …

May 20, 2025
CVE-2025-37939
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: libbpf: Fix accessing BTF.ext core_relo header Update btf_ext_parse_info() to ensure the core_relo header is present …

May 20, 2025
CVE-2025-37938
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Verify event formats that have "%*p.." The trace event verifier checks the formats of …

May 20, 2025
CVE-2025-37937
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds() If dib8000_set_dds()'s call to dib8000_read32() returns zero, the …

May 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.