CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20940
4.0 MEDIUM

Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.

Apr 8, 2025
CVE-2025-20939
5.4 MEDIUM

Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch …

Apr 8, 2025
CVE-2025-20938
5.5 MEDIUM

Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.

Apr 8, 2025
CVE-2025-20936
8.8 HIGH

Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root.

Apr 8, 2025
CVE-2025-20935
5.5 MEDIUM

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User …

Apr 8, 2025
CVE-2025-20934
5.5 MEDIUM

Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.

Apr 8, 2025
CVE-2024-13820
5.3 MEDIUM

The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.15.11 via the 'run' function, which …

Apr 8, 2025
CVE-2025-3408
6.3 MEDIUM

A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The …

Apr 8, 2025
CVE-2025-3407
6.3 MEDIUM

A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerability is the function stbhw_build_tileset_from_image. The …

Apr 8, 2025
CVE-2025-3406
4.3 MEDIUM

A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function stbhw_build_tileset_from_image of the component Header …

Apr 8, 2025
CVE-2025-3405
4.3 MEDIUM

A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Apr 8, 2025
CVE-2025-3403
2.7 LOW

A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101. It has been classified as problematic. Affected is an unknown function …

Apr 8, 2025
CVE-2025-3402
6.3 MEDIUM

A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform 5.5.2 and classified as critical. This issue affects some unknown processing of the …

Apr 8, 2025
CVE-2025-3401
7.3 HIGH

A vulnerability has been found in ESAFENET CDG 5.6.3.154.205_20250114 and classified as critical. This vulnerability affects unknown code of the file /parameter/getLimitIPList.jsp. The manipulation of …

Apr 8, 2025
CVE-2025-3364
6.7 MEDIUM

The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire …

Apr 8, 2025
CVE-2025-32414
5.6 MEDIUM

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. …

Apr 8, 2025
CVE-2025-32413
6.4 MEDIUM

Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.

Apr 8, 2025
CVE-2025-3400
7.3 HIGH

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. This affects an unknown part of the file /client/UnChkMailApplication.jsp. The manipulation of …

Apr 8, 2025
CVE-2025-3399
7.3 HIGH

A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5.6.3.154.205_20250114. Affected by this issue is some unknown functionality of the file …

Apr 8, 2025
CVE-2025-3398
6.3 MEDIUM

A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang/config/WebSecurityConfig.java. …

Apr 8, 2025
CVE-2025-3397
4.3 MEDIUM

A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument …

Apr 8, 2025
CVE-2025-3393
3.5 LOW

A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been classified as problematic. This affects an unknown part of the file /ucan-admin/index …

Apr 8, 2025
CVE-2025-3392
3.5 LOW

A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue is the function Save of the file …

Apr 8, 2025
CVE-2025-3363
9.8 CRITICAL

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them …

Apr 8, 2025
CVE-2025-3362
9.8 CRITICAL

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them …

Apr 8, 2025
CVE-2025-3361
9.8 CRITICAL

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them …

Apr 8, 2025
CVE-2025-2526
8.8 HIGH

The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.2. This is due to …

Apr 8, 2025
CVE-2025-2525
8.8 HIGH

The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_Authentication_Controller::edit_profile' function in all versions up …

Apr 8, 2025
CVE-2025-2519
6.5 MEDIUM

The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file …

Apr 8, 2025
CVE-2025-3391
3.5 LOW

A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function outAddress of the …

Apr 8, 2025
CVE-2025-3390
3.5 LOW

A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controller/daymanager/DaymanageController.java of …

Apr 8, 2025
CVE-2025-3389
3.5 LOW

A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file …

Apr 8, 2025
CVE-2025-3388
4.3 MEDIUM

A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the …

Apr 7, 2025
CVE-2025-3387
3.5 LOW

A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknown part of the component JSON Handler. The …

Apr 7, 2025
CVE-2025-3386
2.4 LOW

A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Apr 7, 2025
CVE-2025-3385
2.4 LOW

A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component …

Apr 7, 2025
CVE-2025-32409
8.1 HIGH

Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to …

Apr 7, 2025
CVE-2025-0942
8.6 HIGH

The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for unauthenticated users to …

Apr 7, 2025
CVE-2025-3384
7.3 HIGH

A vulnerability was found in 1000 Projects Human Resource Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Apr 7, 2025
CVE-2025-3383
7.3 HIGH

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0 and classified as critical. This issue affects some unknown processing of the file …

Apr 7, 2025
CVE-2025-32034
7.5 HIGH

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to …

Apr 7, 2025
CVE-2025-32033
7.5 HIGH

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to …

Apr 7, 2025
CVE-2025-32032
7.5 HIGH

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability …

Apr 7, 2025
CVE-2025-32031
7.5 HIGH

Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with …

Apr 7, 2025
CVE-2025-32030
7.5 HIGH

Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with …

Apr 7, 2025
CVE-2025-32029

ts-asn1-der is a collection of utility classes to encode ASN.1 data following DER rule. Incorrect number DER encoding can lead to denial on service for …

Apr 7, 2025
CVE-2025-31496
7.5 HIGH

apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Compiler allowed queries with deeply nested and reused …

Apr 7, 2025
CVE-2025-3382
6.3 MEDIUM

A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and classified as critical. This vulnerability affects the function update of the file /api/user/update. …

Apr 7, 2025
CVE-2025-3381
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component …

Apr 7, 2025
CVE-2025-29769
5.5 MEDIUM

libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when …

Apr 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.