CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-37849
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the …

May 9, 2025
CVE-2025-37848
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix PM related deadlocks in MS IOCTLs Prevent runtime resume/suspend while MS IOCTLs are …

May 9, 2025
CVE-2025-37847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix deadlock in ivpu_ms_cleanup() Fix deadlock in ivpu_ms_cleanup() by preventing runtime resume after file_priv->ms_lock …

May 9, 2025
CVE-2025-37846
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: arm64: mops: Do not dereference src reg for a set operation The source register is …

May 9, 2025
CVE-2025-37845
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tracing: fprobe events: Fix possible UAF on modules Commit ac91052f0ae5 ("tracing: tprobe-events: Fix leakage of …

May 9, 2025
CVE-2025-37844
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: avoid NULL pointer dereference in dbg call cifs_server_dbg() implies server to be non-NULL so …

May 9, 2025
CVE-2025-37843
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: pciehp: Avoid unnecessary device replacement check Hot-removal of nested PCI hotplug ports suffers from …

May 9, 2025
CVE-2025-37842
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: fsl-qspi: use devm function instead of driver remove Driver use devm APIs to manage …

May 9, 2025
CVE-2025-37841
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pm: cpupower: bench: Prevent NULL dereference on malloc failure If malloc returns NULL due to …

May 9, 2025
CVE-2025-37840
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: brcmnand: fix PM resume warning Fixed warning on PM resume as shown below …

May 9, 2025
CVE-2025-37839
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jbd2: remove wrong sb->s_sequence check Journal emptiness is not determined by sb->s_sequence == 0 but …

May 9, 2025
CVE-2025-37837
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix warnings due to dmam_free_coherent() Two WARNINGs are observed when SMMU driver rolls back …

May 9, 2025
CVE-2025-37836
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: Fix reference leak in pci_register_host_bridge() If device_register() fails, call put_device() to give up the …

May 9, 2025
CVE-2025-37835

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 9, 2025
CVE-2025-2253
9.8 CRITICAL

The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the …

May 9, 2025
CVE-2024-11617
9.8 CRITICAL

The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'zetra_languageUpload' and 'zetra_fontsUpload' functions in …

May 9, 2025
CVE-2025-4466
7.3 HIGH

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?action=save_payment. …

May 9, 2025
CVE-2025-4465
7.3 HIGH

A vulnerability was found in itsourcecode Gym Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

May 9, 2025
CVE-2025-4464
7.3 HIGH

A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

May 9, 2025
CVE-2025-4377

Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows …

May 9, 2025
CVE-2025-4376

Improper Input Validation vulnerability in Sparx Systems Pro Cloud Server's WebEA model search field allows Cross-Site Scripting (XSS). This issue affects Pro Cloud Server: earlier …

May 9, 2025
CVE-2025-4375

Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at …

May 9, 2025
CVE-2025-3463

"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS DriverHub may allow …

May 9, 2025
CVE-2025-3462

"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation in ASUS DriverHub may allow unauthorized …

May 9, 2025
CVE-2025-4463
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Gym Management System 1.0. Affected is an unknown function of the file /ajax.php?action=save_package. The …

May 9, 2025
CVE-2025-4462
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. This issue affects some unknown processing of the file /boafrm/formWsc. The …

May 9, 2025
CVE-2025-4461
2.4 LOW

A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unknown code of the component Virtual Server Page. The manipulation leads …

May 9, 2025
CVE-2025-47737
2.9 LOW

lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero.

May 9, 2025
CVE-2025-47736
2.9 LOW

dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.

May 9, 2025
CVE-2025-47735
2.9 LOW

inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization.

May 9, 2025
CVE-2025-4460
2.4 LOW

A vulnerability classified as problematic has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the component URL Filtering Page. The manipulation …

May 9, 2025
CVE-2025-4459
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

May 9, 2025
CVE-2025-4458
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 9, 2025
CVE-2025-4457
7.3 HIGH

A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file …

May 9, 2025
CVE-2025-4456
7.3 HIGH

A vulnerability classified as critical has been found in Project Worlds Car Rental Project 1.0. Affected is an unknown function of the file /signup.php. The …

May 9, 2025
CVE-2025-3714
9.8 CRITICAL

The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit …

May 9, 2025
CVE-2025-3713
7.5 HIGH

The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit …

May 9, 2025
CVE-2025-3712
7.5 HIGH

The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit …

May 9, 2025
CVE-2025-3711
9.8 CRITICAL

The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit …

May 9, 2025
CVE-2025-3710
9.8 CRITICAL

The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit …

May 9, 2025
CVE-2025-4455
7.0 HIGH

A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects some unknown processing …

May 9, 2025
CVE-2025-4454
6.3 MEDIUM

A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the function wake_on_lan. The manipulation of the argument …

May 9, 2025
CVE-2025-4453
6.3 MEDIUM

A vulnerability was found in D-Link DIR-619L 2.04B04. It has been classified as critical. This affects the function formSysCmd. The manipulation of the argument sysCmd …

May 9, 2025
CVE-2025-3811
9.8 CRITICAL

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to …

May 9, 2025
CVE-2025-3810
9.8 CRITICAL

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to …

May 9, 2025
CVE-2025-4452
8.8 HIGH

A vulnerability was found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this issue is the function formSetWizard2. The manipulation of the argument …

May 9, 2025
CVE-2025-4451
8.8 HIGH

A vulnerability has been found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this vulnerability is the function formSetWAN_Wizard52. The manipulation of the …

May 9, 2025
CVE-2025-4450
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.04B04. Affected is the function formSetEasy_Wizard. The manipulation of the argument curTime leads …

May 9, 2025
CVE-2025-4449
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.04B04. This issue affects the function formEasySetupWizard3. The manipulation of the argument …

May 9, 2025
CVE-2025-4448
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-619L 2.04B04. This vulnerability affects the function formEasySetupWizard. The manipulation of the argument curTime leads to …

May 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.