CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3264
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability …

Jul 7, 2025
CVE-2025-3263
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. …

Jul 7, 2025
CVE-2025-3044
5.3 MEDIUM

A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. …

Jul 7, 2025
CVE-2025-7121
6.3 MEDIUM

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects an unknown part of the file /users/complaint-details.php. …

Jul 7, 2025
CVE-2025-24508
6.4 MEDIUM

Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage

Jul 7, 2025
CVE-2025-7108
5.4 MEDIUM

A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vulnerability is the function deleteFile of the file /Digital-Infrastructure-9.6.7/y9-digitalbase-webapp/y9-module-filemanager/risenet-y9boot-webapp-filemanager/src/main/java/net/risesoft/y9public/controller/Y9FileController.java. …

Jul 7, 2025
CVE-2025-7107
5.3 MEDIUM

A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation …

Jul 7, 2025
CVE-2025-53186
5.9 MEDIUM

Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.

Jul 7, 2025
CVE-2025-53185
6.6 MEDIUM

Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Successful exploitation of this …

Jul 7, 2025
CVE-2025-53184
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53183
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53182
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53181
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53180
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53179
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53178
4.8 MEDIUM

Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.

Jul 7, 2025
CVE-2025-53175
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53174
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53173
5.3 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53172
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53171
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53170
4.0 MEDIUM

Null pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53168
5.7 MEDIUM

Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer …

Jul 7, 2025
CVE-2025-53167
6.9 MEDIUM

Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 7, 2025
CVE-2024-58117
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-7103
6.3 MEDIUM

A vulnerability was found in BoyunCMS up to 1.4.20. It has been rated as critical. This issue affects some unknown processing of the file /application/pay/controller/Index.php …

Jul 7, 2025
CVE-2025-7102
6.3 MEDIUM

A vulnerability was found in BoyunCMS up to 1.4.20. It has been declared as critical. This vulnerability affects unknown code of the file application/update/controller/Server.php. The …

Jul 7, 2025
CVE-2025-7101
6.3 MEDIUM

A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of the file /install/install_ok.php of …

Jul 7, 2025
CVE-2025-7100
6.3 MEDIUM

A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /application/user/controller/Index.php. …

Jul 7, 2025
CVE-2025-7099
5.6 MEDIUM

A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 7, 2025
CVE-2025-7098
5.6 MEDIUM

A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the component File Name …

Jul 6, 2025
CVE-2025-7083
6.3 MEDIUM

A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the …

Jul 6, 2025
CVE-2025-7082
6.3 MEDIUM

A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this issue is the function formBSSetSitesurvey of the file /goform/formBSSetSitesurvey of …

Jul 6, 2025
CVE-2025-7081
6.3 MEDIUM

A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this vulnerability is the function formSetWanStatic of the file /goform/formSetWanStatic …

Jul 6, 2025
CVE-2025-38235
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix "appletb_backlight" backlight device reference counting During appletb_kbd_probe, probe attempts to get the …

Jul 6, 2025
CVE-2025-7078
4.3 MEDIUM

A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site …

Jul 6, 2025
CVE-2025-7076
5.4 MEDIUM

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 6, 2025
CVE-2025-7075
6.3 MEDIUM

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 6, 2025
CVE-2025-7074
4.3 MEDIUM

A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation …

Jul 5, 2025
CVE-2023-50786
4.1 MEDIUM

Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an …

Jul 5, 2025
CVE-2025-47228
6.7 MEDIUM

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands …

Jul 5, 2025
CVE-2025-53605
5.9 MEDIUM

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

Jul 5, 2025
CVE-2025-53604
4.0 MEDIUM

The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length …

Jul 5, 2025
CVE-2025-7070
4.3 MEDIUM

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 4, 2025
CVE-2025-53602
5.3 MEDIUM

Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.

Jul 4, 2025
CVE-2025-53482
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Cross-Site Scripting (XSS).This issue …

Jul 4, 2025
CVE-2025-52497
4.8 MEDIUM

Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.

Jul 4, 2025
CVE-2025-49601
4.8 MEDIUM

In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a …

Jul 4, 2025
CVE-2025-49600
4.9 MEDIUM

In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in …

Jul 4, 2025
CVE-2025-38234
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======== When a CPU chooses to call push_rt_task and …

Jul 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.