CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29643
9.1 CRITICAL

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

Apr 18, 2025
CVE-2025-40364
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state …

Apr 18, 2025
CVE-2025-3790
5.3 MEDIUM

A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the component Apache …

Apr 18, 2025
CVE-2025-3789
3.5 LOW

A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Apr 18, 2025
CVE-2025-32790
6.3 MEDIUM

Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are …

Apr 18, 2025
CVE-2024-46089
6.3 MEDIUM

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

Apr 18, 2025
CVE-2024-49808
6.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization …

Apr 18, 2025
CVE-2024-45651
6.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate …

Apr 18, 2025
CVE-2025-3788
3.5 LOW

A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Apr 18, 2025
CVE-2025-3787
2.7 LOW

A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation …

Apr 18, 2025
CVE-2025-3106
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions …

Apr 18, 2025
CVE-2025-3786
8.8 HIGH

A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The …

Apr 18, 2025
CVE-2025-3785
8.8 HIGH

A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component …

Apr 18, 2025
CVE-2025-3056
5.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due …

Apr 18, 2025
CVE-2025-2492

An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer …

Apr 18, 2025
CVE-2024-26014

Rejected reason: Not used

Apr 18, 2025
CVE-2025-40325
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard request with REQ_NOWAIT raid10_handle_discard should wait barrier before returning …

Apr 18, 2025
CVE-2025-40114
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: light: Add check for array bounds in veml6075_read_int_time_ms The array contains only 5 elements, …

Apr 18, 2025
CVE-2025-40014
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: objtool, spi: amd: Fix out-of-bounds stack access in amd_set_spi_freq() If speed_hz < AMD_SPI_MIN_HZ, amd_set_spi_freq() iterates …

Apr 18, 2025
CVE-2025-39989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-from-user context Patch series "mm/hwpoison: Fix regressions in memory failure …

Apr 18, 2025
CVE-2025-39930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai() commit 419d1918105e ("ASoC: simple-card-utils: use __free(device_node) for device …

Apr 18, 2025
CVE-2025-39778
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show() The csts_state_names[] array only has six sparse …

Apr 18, 2025
CVE-2025-39755
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_driver struct was still only using the old …

Apr 18, 2025
CVE-2025-39735
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in ea_get(), the code checks …

Apr 18, 2025
CVE-2025-39728
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due …

Apr 18, 2025
CVE-2025-39688
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against …

Apr 18, 2025
CVE-2025-38637
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue assertions In the current implementation, skbprio enqueue/dequeue contains an …

Apr 18, 2025
CVE-2025-38575
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free() instead of kfree() to properly free memory …

Apr 18, 2025
CVE-2025-38479
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: free irq correctly in remove path Add fsl_edma->txirq/errirq check to avoid below warning …

Apr 18, 2025
CVE-2025-38240
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr The function mtk_dp_wait_hpd_asserted() …

Apr 18, 2025
CVE-2025-38152
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdown There is case as below could trigger kernel dump: …

Apr 18, 2025
CVE-2025-38104
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRIOV …

Apr 18, 2025
CVE-2025-38049
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors Commit 6eac36bb9eb0 ("x86/resctrl: Allocate …

Apr 18, 2025
CVE-2025-37925
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type Syzbot has reported the following BUG: kernel …

Apr 18, 2025
CVE-2025-37893
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prologue() Vincent reported that running BPF progs with tailcalls …

Apr 18, 2025
CVE-2025-37860
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_param() Since cited commit, ef100_probe_main() and hence also ef100_check_design_params() run …

Apr 18, 2025
CVE-2025-37785
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which …

Apr 18, 2025
CVE-2025-3783
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Apr 18, 2025
CVE-2025-3598
6.1 MEDIUM

The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up …

Apr 18, 2025
CVE-2025-2162
4.8 MEDIUM

The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 18, 2025
CVE-2025-1863
9.8 CRITICAL

Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the …

Apr 18, 2025
CVE-2025-39471
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal Survey modal-survey.This issue affects Modal Survey: from n/a through …

Apr 18, 2025
CVE-2025-39470
8.1 HIGH

Path Traversal: '.../...//' vulnerability in ThimPress Ivy School ivy-school allows PHP Local File Inclusion.This issue affects Ivy School: from n/a through <= 1.6.0.

Apr 18, 2025
CVE-2025-39469
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pantherius Modal Survey modal-survey.This issue affects Modal Survey: from n/a through <= 2.0.2.0.1.

Apr 18, 2025
CVE-2025-42599
9.8 CRITICAL KEV

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated …

Apr 18, 2025
CVE-2025-3520
8.1 HIGH

The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, …

Apr 18, 2025
CVE-2025-2613
4.4 MEDIUM

The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom logo …

Apr 18, 2025
CVE-2024-13650
6.4 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all …

Apr 18, 2025
CVE-2025-25427
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote …

Apr 18, 2025
CVE-2025-0467
8.2 HIGH

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU …

Apr 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.