CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2777
9.3 CRITICAL

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover …

May 7, 2025
CVE-2025-2776
9.3 CRITICAL KEV

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account …

May 7, 2025
CVE-2025-2775
9.3 CRITICAL KEV

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover …

May 7, 2025
CVE-2025-29448
7.5 HIGH

Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future …

May 7, 2025
CVE-2025-29602
6.1 MEDIUM

flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.

May 7, 2025
CVE-2025-29154
6.5 MEDIUM

HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/ted/solicitacao_treinamento/, .galera.app/rh/metas/perspectiva_estrategica/edicao/, .galera.app/rh/cadastros/perspectivas/listagem/adc/, .galera.app/escolaridade/listagem/, .galera.app/estados_civis/cadastro/, .galera.app/nivel_hierarquico/listagem/, .galera.app/nivel_decisorio/cadastro/, .galera.app/escolaridade/cadastro/, …

May 7, 2025
CVE-2025-29153
5.4 MEDIUM

SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export, filters functions.

May 7, 2025
CVE-2025-29152
7.6 HIGH

Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple components, including Strategic Planning Perspective Registration, Training Request, …

May 7, 2025
CVE-2020-36791
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access …

May 7, 2025
CVE-2025-33093
7.5 HIGH

IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

May 7, 2025
CVE-2025-4104
9.8 CRITICAL

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to …

May 7, 2025
CVE-2025-39361
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor …

May 7, 2025
CVE-2025-27533
7.5 HIGH

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which …

May 7, 2025
CVE-2025-20980
4.0 MEDIUM

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

May 7, 2025
CVE-2025-20979
8.4 HIGH

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.

May 7, 2025
CVE-2025-20978
6.2 MEDIUM

Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.

May 7, 2025
CVE-2025-20977
3.3 LOW

Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction …

May 7, 2025
CVE-2025-20976
5.5 MEDIUM

Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.

May 7, 2025
CVE-2025-20975
5.5 MEDIUM

Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activity with systemui privilege.

May 7, 2025
CVE-2025-20974
6.1 MEDIUM

Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.

May 7, 2025
CVE-2025-20973
5.4 MEDIUM

Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type …

May 7, 2025
CVE-2025-20972
6.2 MEDIUM

Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.

May 7, 2025
CVE-2025-20971
5.5 MEDIUM

Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.

May 7, 2025
CVE-2025-20970
6.2 MEDIUM

Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to …

May 7, 2025
CVE-2025-20969
5.5 MEDIUM

Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows …

May 7, 2025
CVE-2025-20968
7.2 HIGH

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows …

May 7, 2025
CVE-2025-20967
5.1 MEDIUM

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows …

May 7, 2025
CVE-2025-20966
4.6 MEDIUM

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows …

May 7, 2025
CVE-2025-20965
6.2 MEDIUM

Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.

May 7, 2025
CVE-2025-20964
6.6 MEDIUM

Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

May 7, 2025
CVE-2025-20963
6.6 MEDIUM

Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

May 7, 2025
CVE-2025-20962
4.0 MEDIUM

Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

May 7, 2025
CVE-2025-20961
5.5 MEDIUM

Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system …

May 7, 2025
CVE-2025-20960
4.0 MEDIUM

Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

May 7, 2025
CVE-2025-20959
5.1 MEDIUM

Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.

May 7, 2025
CVE-2025-20958
4.4 MEDIUM

Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.

May 7, 2025
CVE-2025-20957
7.3 HIGH

Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.

May 7, 2025
CVE-2025-20956
4.3 MEDIUM

Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.

May 7, 2025
CVE-2025-20955
5.5 MEDIUM

Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.

May 7, 2025
CVE-2025-20954
5.5 MEDIUM

Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is …

May 7, 2025
CVE-2025-20953
5.1 MEDIUM

Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.

May 7, 2025
CVE-2025-20949
5.1 MEDIUM

Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.

May 7, 2025
CVE-2025-20937
6.7 MEDIUM

Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

May 7, 2025
CVE-2025-4171
6.4 MEDIUM

The WZ Followed Posts – Display what visitors are reading plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wfp' shortcode in …

May 7, 2025
CVE-2025-0669
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOINC Server: before 1.4.3.

May 7, 2025
CVE-2025-0668
9.8 CRITICAL

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: before 1.4.5.

May 7, 2025
CVE-2025-0667
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.

May 7, 2025
CVE-2025-0666
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.

May 7, 2025
CVE-2024-12120
5.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up …

May 7, 2025
CVE-2025-32405
7.5 HIGH

An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by …

May 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.