CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-37815
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration Resolve kernel panic while accessing …

May 8, 2025
CVE-2025-37814
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT This requirement was overeagerly loosened in commit …

May 8, 2025
CVE-2025-37813
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix invalid pointer dereference in Etron workaround This check is performed before prepare_transfer() …

May 8, 2025
CVE-2025-37812
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Fix deadlock when using NCM gadget The cdns3 driver has the same NCM …

May 8, 2025
CVE-2025-37811
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: ci_hdrc_imx: fix usbmisc handling usbmisc is an optional device property so it is …

May 8, 2025
CVE-2025-37810
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: check that event count does not exceed event buffer length The event …

May 8, 2025
CVE-2025-37809
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Fix NULL pointer access Concurrent calls to typec_partner_unlink_device can lead to a …

May 8, 2025
CVE-2025-37808
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: null - Use spin lock instead of mutex As the null algorithm may be …

May 8, 2025
CVE-2025-37807
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kmemleak warning for percpu hashmap Vlad Poenaru reported the following kmemleak issue: unreferenced …

May 8, 2025
CVE-2025-37806
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Keep write operations atomic syzbot reported a NULL pointer dereference in __generic_file_write_iter. [1] Before …

May 8, 2025
CVE-2025-37805
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitialized work_structs Betty reported hitting the following warning: [ 8.709131][ …

May 8, 2025
CVE-2025-37804

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 8, 2025
CVE-2025-37803
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix a buf size overflow issue during udmabuf creation by casting size_limit_mb to u64 …

May 8, 2025
CVE-2025-37802
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING" wait_event_timeout() will set the state …

May 8, 2025
CVE-2025-37801
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Add check for the return value of spi_imx_setupxfer(). spi_imx->rx …

May 8, 2025
CVE-2025-37800
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference in dev_uevent() If userspace reads "uevent" device attribute …

May 8, 2025
CVE-2025-3419
7.5 HIGH

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, …

May 8, 2025
CVE-2024-13793
7.3 HIGH

The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.8.11. This …

May 8, 2025
CVE-2025-32873
5.3 MEDIUM

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service …

May 8, 2025
CVE-2024-55651
5.4 MEDIUM

i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a …

May 8, 2025
CVE-2025-46727
7.5 HIGH

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data …

May 7, 2025
CVE-2025-35939
5.3 MEDIUM KEV

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft …

May 7, 2025
CVE-2025-32441
4.2 MEDIUM

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack …

May 7, 2025
CVE-2025-0936
6.5 MEDIUM

On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause …

May 7, 2025
CVE-2025-46826

insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student …

May 7, 2025
CVE-2025-46821
5.3 MEDIUM

Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI template matcher incorrectly excludes the `*` character from a …

May 7, 2025
CVE-2025-46265
8.8 HIGH

On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions …

May 7, 2025
CVE-2025-43878
6.0 MEDIUM

When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system …

May 7, 2025
CVE-2025-41433
7.5 HIGH

When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests …

May 7, 2025
CVE-2025-41431
7.5 HIGH

When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems …

May 7, 2025
CVE-2025-41414
7.5 HIGH

When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached …

May 7, 2025
CVE-2025-41399
7.5 HIGH

When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: …

May 7, 2025
CVE-2025-36557
7.5 HIGH

When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) …

May 7, 2025
CVE-2025-36546
8.1 HIGH

On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; …

May 7, 2025
CVE-2025-36525
7.5 HIGH

When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versions which have …

May 7, 2025
CVE-2025-36504
7.5 HIGH

When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions …

May 7, 2025
CVE-2025-35995
7.5 HIGH

When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on …

May 7, 2025
CVE-2025-31644
8.7 HIGH

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an …

May 7, 2025
CVE-2023-7303
3.5 LOW

A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This affects the function process_request of the file q2apro-onsitenotifications-page.php. The …

May 7, 2025
CVE-2025-4043
6.8 MEDIUM

An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot.

May 7, 2025
CVE-2025-3925
7.8 HIGH

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for …

May 7, 2025
CVE-2025-31177
5.5 MEDIUM

gnuplot is affected by a heap buffer overflow at function utf8_copy_one.

May 7, 2025
CVE-2025-45514
6.5 MEDIUM

Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.

May 7, 2025
CVE-2025-45388
6.1 MEDIUM

Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. …

May 7, 2025
CVE-2025-3476

Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, …

May 7, 2025
CVE-2025-3272

Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allow authenticated users to change their password without providing their old password. This issue …

May 7, 2025
CVE-2025-30147

Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum client Hyperledger Besu. Besu 24.7.1 …

May 7, 2025
CVE-2025-29746
6.1 MEDIUM

Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the collection, Wishlist and album components

May 7, 2025
CVE-2025-26169
8.1 HIGH

IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be …

May 7, 2025
CVE-2025-26168
8.1 HIGH

IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that …

May 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.