CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20999
4.1 MEDIUM

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

Jul 8, 2025
CVE-2025-20998
5.5 MEDIUM

Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.

Jul 8, 2025
CVE-2025-20997
6.2 MEDIUM

Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.

Jul 8, 2025
CVE-2025-20983
6.4 MEDIUM

Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Jul 8, 2025
CVE-2025-20982
6.4 MEDIUM

Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Jul 8, 2025
CVE-2025-38237
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() In fimc_is_hw_change_mode(), the function changes camera …

Jul 8, 2025
CVE-2025-7167
6.3 MEDIUM

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. …

Jul 8, 2025
CVE-2025-7166
6.3 MEDIUM

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an unknown part of the file /single.php. …

Jul 8, 2025
CVE-2025-6743
6.4 MEDIUM

The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attribute in all versions up to, and including, 8.2.3 due …

Jul 8, 2025
CVE-2025-42956
6.1 MEDIUM

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an …

Jul 8, 2025
CVE-2025-41665
6.5 MEDIUM

An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config …

Jul 8, 2025
CVE-2025-24004
5.2 MEDIUM

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a …

Jul 8, 2025
CVE-2025-24002
5.3 MEDIUM

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service …

Jul 8, 2025
CVE-2025-7163
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/add-animals.php. The …

Jul 8, 2025
CVE-2025-7162
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue affects some unknown processing of the file …

Jul 8, 2025
CVE-2025-5957
5.3 MEDIUM

The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing …

Jul 8, 2025
CVE-2025-5537
6.4 MEDIUM

The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alternative texts in all versions …

Jul 8, 2025
CVE-2025-7161
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-normal-ticket.php. The manipulation of …

Jul 8, 2025
CVE-2025-7159
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 8, 2025
CVE-2025-7158
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 8, 2025
CVE-2025-6244
6.4 MEDIUM

The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And …

Jul 8, 2025
CVE-2025-5570
5.4 MEDIUM

The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, …

Jul 8, 2025
CVE-2025-20695
6.5 MEDIUM

In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional …

Jul 8, 2025
CVE-2025-20694
6.5 MEDIUM

In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional …

Jul 8, 2025
CVE-2025-20693
6.5 MEDIUM

In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information …

Jul 8, 2025
CVE-2025-20692
5.5 MEDIUM

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Jul 8, 2025
CVE-2025-20691
5.5 MEDIUM

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Jul 8, 2025
CVE-2025-20690
5.5 MEDIUM

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Jul 8, 2025
CVE-2025-20689
5.5 MEDIUM

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Jul 8, 2025
CVE-2025-20688
5.5 MEDIUM

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Jul 8, 2025
CVE-2025-20687
5.5 MEDIUM

In Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local denial of service …

Jul 8, 2025
CVE-2025-7156
6.3 MEDIUM

A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the function execute of the file /v1/chat/completions. The manipulation …

Jul 8, 2025
CVE-2025-7154
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file …

Jul 8, 2025
CVE-2025-43001
6.9 MEDIUM

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting …

Jul 8, 2025
CVE-2025-42992
6.9 MEDIUM

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical …

Jul 8, 2025
CVE-2025-42986
4.3 MEDIUM

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function …

Jul 8, 2025
CVE-2025-42985
6.1 MEDIUM

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could …

Jul 8, 2025
CVE-2025-42981
6.1 MEDIUM

Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at …

Jul 8, 2025
CVE-2025-42979
5.6 MEDIUM

The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an …

Jul 8, 2025
CVE-2025-42974
4.3 MEDIUM

Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally …

Jul 8, 2025
CVE-2025-42973
5.4 MEDIUM

Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status …

Jul 8, 2025
CVE-2025-42971
4.0 MEDIUM

A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it …

Jul 8, 2025
CVE-2025-42970
5.8 MEDIUM

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. …

Jul 8, 2025
CVE-2025-42969
6.1 MEDIUM

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when …

Jul 8, 2025
CVE-2025-42968
5.0 MEDIUM

SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and …

Jul 8, 2025
CVE-2025-42965
4.1 MEDIUM

SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times …

Jul 8, 2025
CVE-2025-42962
6.1 MEDIUM

SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script …

Jul 8, 2025
CVE-2025-42961
4.9 MEDIUM

Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of …

Jul 8, 2025
CVE-2025-42960
4.3 MEDIUM

SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This …

Jul 8, 2025
CVE-2025-31326
4.1 MEDIUM

SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. …

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.