CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38041
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: h616: Reparent GPU clock during frequency changes The H616 manual does not state …

Jun 18, 2025
CVE-2025-38040
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: mctrl_gpio: split disable_ms into sync and no_sync APIs The following splat has been observed …

Jun 18, 2025
CVE-2025-38039
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid WARN_ON when configuring MQPRIO with HTB offload enabled When attempting to enable MQPRIO …

Jun 18, 2025
CVE-2025-38038
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: Remove unnecessary driver_lock in set_boost set_boost is a per-policy function call, hence a …

Jun 18, 2025
CVE-2025-38037
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vxlan: Annotate FDB data races The 'used' and 'updated' fields in the FDB entry structure …

Jun 18, 2025
CVE-2025-38036
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Perform early GT MMIO initialization to read GMDID VFs need to communicate with the …

Jun 18, 2025
CVE-2025-38035
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: don't restore null sk_state_change queue->state_change is set as part of nvmet_tcp_set_queue_sock(), but if the …

Jun 18, 2025
CVE-2025-38034
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref btrfs_prelim_ref() calls the old and new …

Jun 18, 2025
CVE-2025-38033
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/Kconfig: make CFI_AUTO_DEFAULT depend on !RUST or Rust >= 1.88 Calling core::fmt::write() from rust code …

Jun 18, 2025
CVE-2025-38032
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mr: consolidate the ipmr_can_free_table() checks. Guoyu Yin reported a splat in the ipmr netns cleanup …

Jun 18, 2025
CVE-2025-38031
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: padata: do not leak refcount in reorder_work A recent patch that addressed a UAF introduced …

Jun 18, 2025
CVE-2025-38029
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: kasan: avoid sleepable page allocation from atomic context apply_to_pte_range() enters the lazy MMU mode and …

Jun 18, 2025
CVE-2025-38028
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: Fix a race in nfs_local_open_fh() Once the clp->cl_uuid.lock has been dropped, another CPU could …

Jun 18, 2025
CVE-2025-38025
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7606: check for NULL before calling sw_mode_config() Check that the sw_mode_config function pointer …

Jun 18, 2025
CVE-2025-38023
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfs: handle failure of nfs_get_lock_context in unlock path When memory is insufficient, the allocation of …

Jun 18, 2025
CVE-2025-38021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null check of pipe_ctx->plane_state for update_dchubp_dpp Similar to commit 6a057072ddd1 ("drm/amd/display: Fix null …

Jun 18, 2025
CVE-2025-38020
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Disable MACsec offload for uplink representor profile MACsec offload is not supported in switchdev …

Jun 18, 2025
CVE-2025-38018
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix kernel panic when alloc_page failed We cannot set frag_list to NULL pointer when …

Jun 18, 2025
CVE-2025-38017
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/eventpoll: fix endless busy loop after timeout has expired After commit 0a65bc27bd64 ("eventpoll: Set epoll …

Jun 18, 2025
CVE-2025-38016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: bpf: abort dispatch if device destroyed The current HID bpf implementation assumes no output …

Jun 18, 2025
CVE-2025-38015
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc Memory allocated for idxd …

Jun 18, 2025
CVE-2025-38014
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Refactor remove call with idxd_cleanup() helper The idxd_cleanup() helper cleans up perfmon, interrupts, …

Jun 18, 2025
CVE-2025-38012
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched_ext: bpf_iter_scx_dsq_new() should always initialize iterator BPF programs may call next() and destroy() on BPF …

Jun 18, 2025
CVE-2025-38011
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: csa unmap use uninterruptible lock After process exit to unmap csa and free GPU …

Jun 18, 2025
CVE-2025-38010
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking The current implementation …

Jun 18, 2025
CVE-2025-38009
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: disable napi on driver removal A warning on driver removal started occurring after …

Jun 18, 2025
CVE-2025-38008
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted memory handling The page allocator tracks the number of …

Jun 18, 2025
CVE-2025-38007
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Add NULL check in uclogic_input_configured() devm_kasprintf() returns NULL when memory allocation fails. Currently, …

Jun 18, 2025
CVE-2025-38006
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: mctp: Don't access ifa_index when missing In mctp_dump_addrinfo, ifa_index can be used to filter …

Jun 18, 2025
CVE-2025-38005
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma: Add missing locking Recent kernels complain about a missing lock in k3-udma.c …

Jun 18, 2025
CVE-2025-23999
4.3 MEDIUM

Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.13.

Jun 18, 2025
CVE-2025-5981
6.5 MEDIUM

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, …

Jun 18, 2025
CVE-2025-4955
4.7 MEDIUM

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor …

Jun 18, 2025
CVE-2025-23252
4.5 MEDIUM

The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of this vulnerability may …

Jun 18, 2025
CVE-2025-49149
6.1 MEDIUM

Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website …

Jun 17, 2025
CVE-2025-49593
6.8 MEDIUM

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior …

Jun 17, 2025
CVE-2025-48443
6.7 MEDIUM

Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker …

Jun 17, 2025
CVE-2025-30642
5.5 MEDIUM

A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on …

Jun 17, 2025
CVE-2025-5141
5.5 MEDIUM

A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), …

Jun 17, 2025
CVE-2025-30679
6.5 MEDIUM

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information …

Jun 17, 2025
CVE-2025-30678
6.5 MEDIUM

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to information …

Jun 17, 2025
CVE-2024-40570
6.5 MEDIUM

SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.

Jun 17, 2025
CVE-2025-49487
6.8 MEDIUM

An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a …

Jun 17, 2025
CVE-2025-49158
6.7 MEDIUM

An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations. Please …

Jun 17, 2025
CVE-2025-47866
4.3 MEDIUM

An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected …

Jun 17, 2025
CVE-2025-45880
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of …

Jun 17, 2025
CVE-2025-45878
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a …

Jun 17, 2025
CVE-2025-45879
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the e-mail manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a …

Jun 17, 2025
CVE-2025-6196
5.5 MEDIUM

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, …

Jun 17, 2025
CVE-2025-49882
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP cubewp-framework allows DOM-Based XSS.This issue affects CubeWP: from n/a through …

Jun 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.