CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-51531
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser …

Aug 6, 2025
CVE-2025-48394
4.7 MEDIUM

An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the …

Aug 6, 2025
CVE-2025-48393
5.7 MEDIUM

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This …

Aug 6, 2025
CVE-2025-51308
5.3 MEDIUM

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, …

Aug 6, 2025
CVE-2025-51306
6.5 MEDIUM

In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without expiration, due to incorrect …

Aug 6, 2025
CVE-2025-50234
6.5 MEDIUM

MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is …

Aug 6, 2025
CVE-2025-50233
6.5 MEDIUM

A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in …

Aug 6, 2025
CVE-2025-36020
5.9 MEDIUM

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.

Aug 6, 2025
CVE-2025-2028
6.5 MEDIUM

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

Aug 6, 2025
CVE-2024-52885
5.0 MEDIUM

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File …

Aug 6, 2025
CVE-2025-23335
4.4 MEDIUM

NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a …

Aug 6, 2025
CVE-2025-23334
5.9 MEDIUM

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by sending …

Aug 6, 2025
CVE-2025-23333
5.9 MEDIUM

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by manipulating …

Aug 6, 2025
CVE-2025-5197
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting …

Aug 6, 2025
CVE-2025-46391
6.5 MEDIUM

CWE-284: Improper Access Control

Aug 6, 2025
CVE-2025-46389
6.5 MEDIUM

CWE-620: Unverified Password Change

Aug 6, 2025
CVE-2025-46388
4.3 MEDIUM

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Aug 6, 2025
CVE-2025-8620
5.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This …

Aug 6, 2025
CVE-2025-6013
6.5 MEDIUM

Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple …

Aug 6, 2025
CVE-2025-27072
5.5 MEDIUM

Information disclosure while processing a packet at EAVB BE side with invalid header length.

Aug 6, 2025
CVE-2025-21472
5.5 MEDIUM

Information disclosure while capturing logs as eSE debug messages are logged.

Aug 6, 2025
CVE-2025-21465
6.5 MEDIUM

Information disclosure while processing the hash segment in an MBN file.

Aug 6, 2025
CVE-2025-21464
6.5 MEDIUM

Information disclosure while reading data from an image using specified offset and size parameters.

Aug 6, 2025
CVE-2025-21457
6.1 MEDIUM

Information disclosure while opening a fastrpc session when domain is not sanitized.

Aug 6, 2025
CVE-2025-7727
6.4 MEDIUM

The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, …

Aug 6, 2025
CVE-2025-7376
5.9 MEDIUM

Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi …

Aug 6, 2025
CVE-2025-21021
5.7 MEDIUM

Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

Aug 6, 2025
CVE-2025-21020
5.7 MEDIUM

Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

Aug 6, 2025
CVE-2025-21019
5.5 MEDIUM

Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this …

Aug 6, 2025
CVE-2025-21018
4.4 MEDIUM

Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.

Aug 6, 2025
CVE-2025-21017
6.3 MEDIUM

Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

Aug 6, 2025
CVE-2025-21016
4.3 MEDIUM

Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allows local attackers to use the …

Aug 6, 2025
CVE-2025-21015
4.0 MEDIUM

Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

Aug 6, 2025
CVE-2025-21014
4.3 MEDIUM

Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.

Aug 6, 2025
CVE-2025-21013
6.2 MEDIUM

Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise …

Aug 6, 2025
CVE-2025-21012
5.5 MEDIUM

Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.

Aug 6, 2025
CVE-2025-21011
5.5 MEDIUM

Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and …

Aug 6, 2025
CVE-2025-21010
6.0 MEDIUM

Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.

Aug 6, 2025
CVE-2025-20990
4.0 MEDIUM

Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.

Aug 6, 2025
CVE-2025-8100
5.4 MEDIUM

The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and …

Aug 6, 2025
CVE-2025-7498
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, …

Aug 6, 2025
CVE-2025-7399
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all versions up to, and including, 28.1.3 due …

Aug 6, 2025
CVE-2025-54651
4.8 MEDIUM

Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54650
4.2 MEDIUM

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

Aug 6, 2025
CVE-2025-54649
4.5 MEDIUM

Vulnerability of using incompatible types to access resources in the location service. Impact: Successful exploitation of this vulnerability may cause some location information attributes to …

Aug 6, 2025
CVE-2025-54648
5.4 MEDIUM

Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54647
5.4 MEDIUM

Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54646
5.1 MEDIUM

Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance.

Aug 6, 2025
CVE-2025-54645
5.0 MEDIUM

Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54644
6.6 MEDIUM

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.