CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21804
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: rcar-ep: Fix incorrect variable used when calling devm_request_mem_region() The rcar_pcie_parse_outbound_ranges() uses the devm_request_mem_region() macro …

Feb 27, 2025
CVE-2025-21803
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix warnings during S3 suspend The enable_gpe_wakeup() function calls acpi_enable_all_wakeup_gpes(), and the later one …

Feb 27, 2025
CVE-2025-21802
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix oops when unload drivers paralleling When unload hclge driver, it tries to …

Feb 27, 2025
CVE-2025-21801
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ravb: Fix missing rtnl lock in suspend/resume path Fix the suspend/resume path by ensuring …

Feb 27, 2025
CVE-2025-21800
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix definer's HWS_SET32 macro for negative offset When bit offset for HWS_SET32 macro …

Feb 27, 2025
CVE-2025-21799
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: fix freeing IRQ in am65_cpsw_nuss_remove_tx_chns() When getting the IRQ we use …

Feb 27, 2025
CVE-2025-21798
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firewire: test: Fix potential null dereference in firewire kunit test kunit_kzalloc() may return a NULL …

Feb 27, 2025
CVE-2024-58042
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rhashtable: Fix potential deadlock by moving schedule_work outside lock Move the hash table growth check …

Feb 27, 2025
CVE-2024-58034
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: memory: tegra20-emc: fix an OF node reference bug in tegra_emc_find_node_by_ram_code() As of_find_node_by_name() release the reference …

Feb 27, 2025
CVE-2024-58022
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mailbox: th1520: Fix a NULL vs IS_ERR() bug The devm_ioremap() function doesn't return error pointers, …

Feb 27, 2025
CVE-2024-54957
6.1 MEDIUM

Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker …

Feb 27, 2025
CVE-2024-53944
9.8 CRITICAL

An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can …

Feb 27, 2025
CVE-2024-53408
5.4 MEDIUM

AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.

Feb 27, 2025
CVE-2025-22624

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 was found to be vulnerable. The web application dynamically generates web content without …

Feb 27, 2025
CVE-2025-0767
9.8 CRITICAL

WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.

Feb 27, 2025
CVE-2025-27399
5.3 MEDIUM

Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" …

Feb 27, 2025
CVE-2025-1745
4.3 MEDIUM

A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. This vulnerability affects unknown code of the component Logout. The manipulation leads …

Feb 27, 2025
CVE-2025-1743
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of …

Feb 27, 2025
CVE-2025-27157
5.3 MEDIUM

Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. …

Feb 27, 2025
CVE-2025-25329
5.5 MEDIUM

An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link.

Feb 27, 2025
CVE-2025-23687
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simonhunter Woo Store Mode woo-store-mode allows Reflected XSS.This issue affects Woo Store Mode: …

Feb 27, 2025
CVE-2025-1742
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in pihome-shc PiHome 2.0. Affected by this issue is some unknown functionality of the file …

Feb 27, 2025
CVE-2024-9285
4.3 MEDIUM

A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue affects some unknown …

Feb 27, 2025
CVE-2025-25334
5.5 MEDIUM

An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted link.

Feb 27, 2025
CVE-2025-25333
7.5 HIGH

An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.

Feb 27, 2025
CVE-2025-25331
5.5 MEDIUM

An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.

Feb 27, 2025
CVE-2025-25330
5.5 MEDIUM

An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.

Feb 27, 2025
CVE-2025-25326
5.5 MEDIUM

An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted …

Feb 27, 2025
CVE-2025-25325
5.5 MEDIUM

An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.

Feb 27, 2025
CVE-2025-25324
5.5 MEDIUM

An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a crafted link.

Feb 27, 2025
CVE-2025-25323
5.5 MEDIUM

An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user information via supplying a crafted link.

Feb 27, 2025
CVE-2025-1756
7.5 HIGH

mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted …

Feb 27, 2025
CVE-2025-1755
7.5 HIGH

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a …

Feb 27, 2025
CVE-2025-1741
4.7 MEDIUM

A vulnerability classified as problematic was found in b1gMail up to 7.4.1-pl1. Affected by this vulnerability is an unknown functionality of the file src/admin/users.php of …

Feb 27, 2025
CVE-2025-0914
3.8 LOW

An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments …

Feb 27, 2025
CVE-2025-25761
7.2 HIGH

HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.

Feb 27, 2025
CVE-2025-25760
7.5 HIGH

A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a crafted GET request.

Feb 27, 2025
CVE-2025-25759
7.5 HIGH

An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request.

Feb 27, 2025
CVE-2025-0759
3.3 LOW

IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization.

Feb 27, 2025
CVE-2024-56812
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56811
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56810
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56496
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56495
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56494
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-56493
3.3 LOW

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used …

Feb 27, 2025
CVE-2024-54170
5.5 MEDIUM

IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an inefficient complexity …

Feb 27, 2025
CVE-2024-54169
6.5 MEDIUM

IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot …

Feb 27, 2025
CVE-2024-13148
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection.This issue affects B2B …

Feb 27, 2025
CVE-2025-27154
9.8 CRITICAL

Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to …

Feb 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.