CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53649
5.1 MEDIUM

"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive …

Jul 29, 2025
CVE-2025-53079
4.9 MEDIUM

Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

Jul 29, 2025
CVE-2025-53077
6.5 MEDIUM

An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the …

Jul 29, 2025
CVE-2025-4566
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element …

Jul 29, 2025
CVE-2025-4370
5.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing …

Jul 29, 2025
CVE-2025-3075
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode …

Jul 29, 2025
CVE-2025-7811
6.4 MEDIUM

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-7810
5.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-7809
6.4 MEDIUM

The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-54768
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54767
6.5 MEDIUM

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

Jul 29, 2025
CVE-2025-54766
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54765
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54423
5.4 MEDIUM

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in …

Jul 28, 2025
CVE-2025-54538
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

Jul 28, 2025
CVE-2025-54537
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

Jul 28, 2025
CVE-2025-54536
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint

Jul 28, 2025
CVE-2025-54535
5.8 MEDIUM

In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

Jul 28, 2025
CVE-2025-54534
4.8 MEDIUM

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

Jul 28, 2025
CVE-2025-54533
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

Jul 28, 2025
CVE-2025-54532
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

Jul 28, 2025
CVE-2025-54528
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

Jul 28, 2025
CVE-2025-54527
6.1 MEDIUM

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

Jul 28, 2025
CVE-2025-6250
6.7 MEDIUM

Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service …

Jul 28, 2025
CVE-2024-49343
5.4 MEDIUM

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Jul 28, 2025
CVE-2025-32731
6.1 MEDIUM

A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream MedDream PACS Premium 7.3.5.860. A specially crafted malicious url can lead to …

Jul 28, 2025
CVE-2025-30126
5.3 MEDIUM

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a …

Jul 28, 2025
CVE-2025-24485
5.8 MEDIUM

A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP request can lead to SSRF. An …

Jul 28, 2025
CVE-2025-8275
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown …

Jul 28, 2025
CVE-2025-54569
4.5 MEDIUM

In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation.

Jul 28, 2025
CVE-2025-38496
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm-bufio: fix sched in atomic context If "try_verify_in_tasklet" is set for dm-verity, DM_BUFIO_CLIENT_NO_SLEEP is enabled …

Jul 28, 2025
CVE-2025-38495
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the …

Jul 28, 2025
CVE-2025-38493
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix crash in timerlat_dump_stack() We have observed kernel panics when using timerlat with stack …

Jul 28, 2025
CVE-2025-38492
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix race between cache write completion and ALL_QUEUED being set When netfslib is issuing …

Jul 28, 2025
CVE-2025-38491
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: …

Jul 28, 2025
CVE-2025-38489
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") …

Jul 28, 2025
CVE-2025-38487
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled Mitigate e.g. the following: # echo …

Jul 28, 2025
CVE-2025-38486
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soundwire: Revert "soundwire: qcom: Add set_channel_map api support" This reverts commit 7796c97df6b1b2206681a07f3c80f6023a6593d5. This patch broke …

Jul 28, 2025
CVE-2025-38481
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large The handling of the `COMEDI_INSNLIST` ioctl …

Jul 28, 2025
CVE-2025-38480
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: comedi: Fix use of uninitialized data in insn_rw_emulate_bits() For Comedi `INSN_READ` and `INSN_WRITE` instructions on …

Jul 28, 2025
CVE-2025-38478
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of data for instructions that write to subdevice Some Comedi subdevice instruction …

Jul 28, 2025
CVE-2025-38477
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can occur when 'agg' is …

Jul 28, 2025
CVE-2025-38475
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smc: Fix various oops due to inet_sock type confusion. syzbot reported weird splats [0][1] in …

Jul 28, 2025
CVE-2025-38474
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: net: sierra: check for no status endpoint The driver checks for having three endpoints …

Jul 28, 2025
CVE-2025-38473
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() syzbot reported null-ptr-deref in l2cap_sock_resume_cb(). [0] l2cap_sock_resume_cb() has a similar …

Jul 28, 2025
CVE-2025-38472
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry A crash in conntrack was …

Jul 28, 2025
CVE-2025-38470
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime Assuming the "rx-vlan-filter" …

Jul 28, 2025
CVE-2025-38469
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a …

Jul 28, 2025
CVE-2025-38468
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can …

Jul 28, 2025
CVE-2025-8266
6.3 MEDIUM

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the …

Jul 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.