CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25729
7.5 HIGH

An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via …

Feb 28, 2025
CVE-2025-25728
6.5 MEDIUM

Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers …

Feb 28, 2025
CVE-2025-25727
6.2 MEDIUM

Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.

Feb 28, 2025
CVE-2025-25477
8.1 HIGH

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in …

Feb 28, 2025
CVE-2025-1687
8.8 HIGH

The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation …

Feb 28, 2025
CVE-2025-1682
8.8 HIGH

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' …

Feb 28, 2025
CVE-2025-1681
5.4 MEDIUM

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename …

Feb 28, 2025
CVE-2024-12811
8.8 HIGH

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it possible …

Feb 28, 2025
CVE-2025-24832
5.5 MEDIUM

Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM …

Feb 27, 2025
CVE-2024-37567
9.1 CRITICAL

Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.

Feb 27, 2025
CVE-2024-37566
9.8 CRITICAL

Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.

Feb 27, 2025
CVE-2024-36047
9.8 CRITICAL

Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.

Feb 27, 2025
CVE-2024-36046
9.8 CRITICAL

Infoblox NIOS through 8.6.4 executes with more privileges than required.

Feb 27, 2025
CVE-2025-26325
9.8 CRITICAL

ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.

Feb 27, 2025
CVE-2025-26264
8.8 HIGH

GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated …

Feb 27, 2025
CVE-2025-25730
4.6 MEDIUM

An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control …

Feb 27, 2025
CVE-2025-25570
9.8 CRITICAL

Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.

Feb 27, 2025
CVE-2024-38292
9.8 CRITICAL

In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.

Feb 27, 2025
CVE-2024-38291
8.8 HIGH

In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.

Feb 27, 2025
CVE-2024-38290
5.3 MEDIUM

In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.

Feb 27, 2025
CVE-2024-55160
9.8 CRITICAL

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.

Feb 27, 2025
CVE-2024-51139
9.8 CRITICAL

Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 …

Feb 27, 2025
CVE-2024-51138
9.8 CRITICAL

Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133/2762/2832 3.9.9 and earlier; Vigor2135/2765/2766 4.4.5. and earlier; Vigor2865/2866/2927 …

Feb 27, 2025
CVE-2024-41340
8.4 HIGH

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to …

Feb 27, 2025
CVE-2024-41339
8.8 HIGH

An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor …

Feb 27, 2025
CVE-2024-41338
7.5 HIGH

A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 …

Feb 27, 2025
CVE-2024-41336
7.5 HIGH

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 …

Feb 27, 2025
CVE-2024-41335
7.5 HIGH

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 …

Feb 27, 2025
CVE-2024-41334
8.8 HIGH

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 …

Feb 27, 2025
CVE-2025-22952
9.8 CRITICAL

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.

Feb 27, 2025
CVE-2025-21824
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix a use of uninitialized mutex commit c8347f915e67 ("gpu: host1x: Fix boot regression …

Feb 27, 2025
CVE-2025-21823
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: batman-adv: Drop unmanaged ELP metric worker The ELP worker needs to calculate new metric values …

Feb 27, 2025
CVE-2025-21822
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: Set driver data before its usage If vmclock_ptp_register() fails during probing, vmclock_remove() is …

Feb 27, 2025
CVE-2025-21821
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbdev: omap: use threaded IRQ for LCD DMA When using touchscreen and framebuffer, Nokia 770 …

Feb 27, 2025
CVE-2025-21820
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tty: xilinx_uartps: split sysrq handling lockdep detects the following circular locking dependency: CPU 0 CPU …

Feb 27, 2025
CVE-2025-21819
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd/display: Use HW lock mgr for PSR1" This reverts commit a2b5a9956269 ("drm/amd/display: Use HW …

Feb 27, 2025
CVE-2025-21818

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 27, 2025
CVE-2025-21817
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: mark GFP_NOIO around sysfs ->store() sysfs ->store is called with queue freezed, meantime we …

Feb 27, 2025
CVE-2025-21816
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hrtimers: Force migrate away hrtimers queued after CPUHP_AP_HRTIMERS_DYING hrtimers are migrated away from the dying …

Feb 27, 2025
CVE-2025-21815
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm/compaction: fix UBSAN shift-out-of-bounds warning syzkaller reported a UBSAN shift-out-of-bounds warning of (1UL << order) …

Feb 27, 2025
CVE-2025-21814
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ptp: Ensure info->enable callback is always set The ioctl and sysfs handlers unconditionally call the …

Feb 27, 2025
CVE-2025-21813
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: timers/migration: Fix off-by-one root mis-connection Before attaching a new root to the old root, the …

Feb 27, 2025
CVE-2025-21812
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ax25: rcu protect dev->ax25_ptr syzbot found a lockdep issue [1]. We should remove ax25 RTNL …

Feb 27, 2025
CVE-2025-21811
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: protect access to buffers with no active references nilfs_lookup_dirty_data_buffers(), which iterates through the buffers …

Feb 27, 2025
CVE-2025-21810
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: driver core: class: Fix wild pointer dereferences in API class_dev_iter_next() There are a potential wild …

Feb 27, 2025
CVE-2025-21809
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc, afs: Fix peer hash locking vs RCU callback In its address list, afs now …

Feb 27, 2025
CVE-2025-21808
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: xdp: Disallow attaching device-bound programs in generic mode Device-bound programs are used to support …

Feb 27, 2025
CVE-2025-21807
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix queue freeze vs limits lock order in sysfs store methods queue_attr_store() always freezes …

Feb 27, 2025
CVE-2025-21806
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: let net.core.dev_weight always be non-zero The following problem was encountered during stability test: (NULL …

Feb 27, 2025
CVE-2025-21805
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the …

Feb 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.