CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1495
4.3 MEDIUM

IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to missing authorization validation.

May 3, 2025
CVE-2024-58134
8.1 HIGH

Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These …

May 3, 2025
CVE-2024-41753
6.1 MEDIUM

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated …

May 3, 2025
CVE-2025-4237
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component MDELETE …

May 3, 2025
CVE-2025-4236
7.3 HIGH

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component …

May 3, 2025
CVE-2025-37799
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp vmxnet3 driver's XDP handling is buggy for packet …

May 3, 2025
CVE-2025-4226
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The …

May 3, 2025
CVE-2024-58135
5.3 MEDIUM

Mojolicious versions from 7.28 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default When creating a default app skeleton …

May 3, 2025
CVE-2025-3815
6.4 MEDIUM

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.12.32 due to …

May 3, 2025
CVE-2025-4222
5.9 MEDIUM

The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup files stored in …

May 3, 2025
CVE-2025-4199
6.1 MEDIUM

The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.02. This is due to missing …

May 3, 2025
CVE-2025-4198
6.1 MEDIUM

The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.1. This is due to missing …

May 3, 2025
CVE-2025-4188
6.1 MEDIUM

The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is …

May 3, 2025
CVE-2025-4172
6.4 MEDIUM

The VerticalResponse Newsletter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'verticalresponse' shortcode in all versions up to, and including, …

May 3, 2025
CVE-2025-4170
6.4 MEDIUM

The Xavin's Review Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xrr' shortcode in all versions up to, and including, …

May 3, 2025
CVE-2025-4168
6.4 MEDIUM

The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode in all versions up to, and including, 1.3.3 …

May 3, 2025
CVE-2025-47229
2.9 LOW

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such …

May 3, 2025
CVE-2025-3918
9.8 CRITICAL

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The …

May 3, 2025
CVE-2025-3779
6.4 MEDIUM

The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all versions up to, and including, 0.10 due to …

May 3, 2025
CVE-2024-13738
7.3 HIGH

The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

May 3, 2025
CVE-2025-46723

OpenVM is a performant and modular zkVM framework built for customization and extensibility. In version 1.0.0, OpenVM is vulnerable to overflow through byte decomposition of …

May 2, 2025
CVE-2025-21572
6.1 MEDIUM

OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens through improper handling of path segments. The application …

May 2, 2025
CVE-2024-55069
5.3 MEDIUM

ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.

May 2, 2025
CVE-2022-21546
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix WRITE_SAME No Data Buffer crash In newer version of the SBC specs, …

May 2, 2025
CVE-2025-4218
5.3 MEDIUM

A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulnerability is the function GPTSeleniumAgent of …

May 2, 2025
CVE-2025-4215
3.1 LOW

A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file …

May 2, 2025
CVE-2025-47226
5.0 MEDIUM

Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

May 2, 2025
CVE-2025-0782

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 2, 2025
CVE-2025-4214
7.3 HIGH

A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue affects some unknown processing of the file …

May 2, 2025
CVE-2024-58253
2.9 LOW

In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces …

May 2, 2025
CVE-2025-4213
7.3 HIGH

A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search.php. …

May 2, 2025
CVE-2025-46332
6.5 MEDIUM

Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 and prior and @vercel/flags from 3.1.1 and …

May 2, 2025
CVE-2025-45800
9.8 CRITICAL

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the processing of the deviceMac parameter.

May 2, 2025
CVE-2025-3879
6.6 MEDIUM

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the …

May 2, 2025
CVE-2025-4210
7.3 HIGH

A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers/scim.go of the component …

May 2, 2025
CVE-2023-53144
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: erofs: fix wrong kunmap when using LZMA on HIGHMEM platforms As the call trace shown, …

May 2, 2025
CVE-2023-53143
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix another off-by-one fsmap error on 1k block filesystems Apparently syzbot figured out that …

May 2, 2025
CVE-2023-53142
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ice: copy last block omitted in ice_get_module_eeprom() ice_get_module_eeprom() is broken since commit e9c9692c8a81 ("ice: Reimplement …

May 2, 2025
CVE-2023-53141
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ila: do not generate empty messages in ila_xlat_nl_cmd_get_mapping() ila_xlat_nl_cmd_get_mapping() generates an empty skb, triggerring a …

May 2, 2025
CVE-2023-53140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier Remove the /proc/scsi/${proc_name} directory earlier to fix a …

May 2, 2025
CVE-2023-53139
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: add null check of devm_kmalloc_array in fdp_nci_i2c_read_device_properties devm_kmalloc_array may fails, *fw_vsc_cfg might be …

May 2, 2025
CVE-2023-53138
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: caif: Fix use-after-free in cfusbl_device_notify() syzbot reported use-after-free in cfusbl_device_notify() [1]. This causes a …

May 2, 2025
CVE-2023-53137

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 2, 2025
CVE-2023-53136
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: af_unix: fix struct pid leaks in OOB support syzbot reported struct pid leak [1]. Issue …

May 2, 2025
CVE-2023-53135
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv: Use READ_ONCE_NOCHECK in imprecise unwinding stack mode When CONFIG_FRAME_POINTER is unset, the stack unwinding …

May 2, 2025
CVE-2023-53134
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Avoid order-5 memory allocation for TPA data The driver needs to keep track of …

May 2, 2025
CVE-2023-53133
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix an infinite loop error when len is 0 in tcp_bpf_recvmsg_parser() When the …

May 2, 2025
CVE-2023-53132
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix mpi3mr_hba_port memory leak in mpi3mr_remove() Free mpi3mr_hba_port at .remove.

May 2, 2025
CVE-2023-53131
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a server shutdown leak Fix a race where kthread_stop() may prevent the threadfn …

May 2, 2025
CVE-2023-53130

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.