CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31206
4.3 MEDIUM

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS …

May 12, 2025
CVE-2025-31205
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS …

May 12, 2025
CVE-2025-31204
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, …

May 12, 2025
CVE-2025-31196
5.5 MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS …

May 12, 2025
CVE-2025-31195
6.3 MEDIUM

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of …

May 12, 2025
CVE-2025-30453
7.8 HIGH

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app …

May 12, 2025
CVE-2025-30448
9.1 CRITICAL

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma …

May 12, 2025
CVE-2025-30442
7.8 HIGH

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may …

May 12, 2025
CVE-2025-30440
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be …

May 12, 2025
CVE-2025-30436
9.1 CRITICAL

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may …

May 12, 2025
CVE-2025-24274
7.8 HIGH

An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. …

May 12, 2025
CVE-2025-24258
7.8 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may …

May 12, 2025
CVE-2025-24225
6.5 MEDIUM

An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing an email may …

May 12, 2025
CVE-2025-24223
8.0 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, …

May 12, 2025
CVE-2025-24222
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web content may lead to an …

May 12, 2025
CVE-2025-24220
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may be able …

May 12, 2025
CVE-2025-24155
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may …

May 12, 2025
CVE-2025-24144
5.5 MEDIUM

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia …

May 12, 2025
CVE-2025-24142
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS …

May 12, 2025
CVE-2025-24111
5.5 MEDIUM

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, …

May 12, 2025
CVE-2025-3659

Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and …

May 12, 2025
CVE-2025-1079
7.8 HIGH

Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature

May 12, 2025
CVE-2025-47682
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue …

May 12, 2025
CVE-2024-55466
6.5 MEDIUM

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via …

May 12, 2025
CVE-2024-4982
7.6 HIGH

A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the …

May 12, 2025
CVE-2024-4981
7.6 HIGH

A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show …

May 12, 2025
CVE-2025-44176
6.5 MEDIUM

Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.

May 12, 2025
CVE-2025-44175
5.4 MEDIUM

Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.

May 12, 2025
CVE-2023-34732
5.4 MEDIUM

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user …

May 12, 2025
CVE-2025-46750
4.4 MEDIUM

SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and change password-protected BIOS settings by importing a BIOS …

May 12, 2025
CVE-2025-46749
4.3 MEDIUM

An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequent client-side script execution.

May 12, 2025
CVE-2025-46748
2.7 LOW

An authenticated user attempting to change their password could do so without using the current password.

May 12, 2025
CVE-2025-46747
5.7 MEDIUM

An authenticated user without user-management permissions could identify other user accounts.

May 12, 2025
CVE-2025-46746
5.8 MEDIUM

An administrator could discover another account's credentials.

May 12, 2025
CVE-2025-46745
6.5 MEDIUM

An authenticated user without user-management permissions could view other users account information.

May 12, 2025
CVE-2025-46744
2.7 LOW

An authenticated administrator could modify the Created By username for a user account

May 12, 2025
CVE-2025-46743
6.3 MEDIUM

An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.

May 12, 2025
CVE-2025-46742
4.3 MEDIUM

Users who were required to change their password could still access system information before changing their password

May 12, 2025
CVE-2025-46741
5.7 MEDIUM

A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.

May 12, 2025
CVE-2025-46740
7.5 HIGH

An authenticated user without user administrative permissions could change the administrator Account Name.

May 12, 2025
CVE-2025-46739
8.1 HIGH

An unauthenticated user could discover account credentials via a brute-force attack without rate limiting

May 12, 2025
CVE-2025-45779
9.8 CRITICAL

Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.

May 12, 2025
CVE-2025-3632
7.5 HIGH

IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due …

May 12, 2025
CVE-2025-47578
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button bns-twitter-follow-button allows DOM-Based XSS.This issue affects BNS …

May 12, 2025
CVE-2025-46738
6.6 MEDIUM

An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code.

May 12, 2025
CVE-2025-46737
7.4 HIGH

SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes …

May 12, 2025
CVE-2025-44830
9.8 CRITICAL

EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.

May 12, 2025
CVE-2025-44022
9.8 CRITICAL

An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.

May 12, 2025
CVE-2025-47274

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to the ordering of code used to …

May 12, 2025
CVE-2025-46718
3.3 LOW

sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of …

May 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.