CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0590
7.5 HIGH

Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.

Jan 20, 2025
CVE-2025-0586
7.2 HIGH

The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code …

Jan 20, 2025
CVE-2025-0579
7.3 HIGH

A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jan 20, 2025
CVE-2024-41743
7.5 HIGH

IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.

Jan 19, 2025
CVE-2024-41742
7.5 HIGH

IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting …

Jan 19, 2025
CVE-2024-57929
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm array: fix releasing a faulty array block twice in dm_array_cursor_end When dm_bm_read_lock() fails due …

Jan 19, 2025
CVE-2024-57928
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix enomem handling in buffered reads If netfs_read_to_pagecache() gets an error from either ->prepare_read() …

Jan 19, 2025
CVE-2024-57926
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Set private->all_drm_private[i]->drm to NULL if mtk_drm_bind returns err The pointer need to be set …

Jan 19, 2025
CVE-2024-57925
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix a missing return value check bug In the smb2_send_interim_resp(), if ksmbd_alloc_work_struct() fails to …

Jan 19, 2025
CVE-2024-57917
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: topology: Keep the cpumask unchanged when printing cpumap During fuzz testing, the following warning was …

Jan 19, 2025
CVE-2024-57912
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: pressure: zpa2326: fix information leak in triggered buffer The 'sample' local struct is used …

Jan 19, 2025
CVE-2024-57911
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer The 'data' array is allocated via …

Jan 19, 2025
CVE-2024-57910
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: light: vcnl4035: fix information leak in triggered buffer The 'buffer' local array is used …

Jan 19, 2025
CVE-2024-57909
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: light: bh1745: fix information leak in triggered buffer The 'scan' local struct is used …

Jan 19, 2025
CVE-2024-57908
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: imu: kmx61: fix information leak in triggered buffer The 'buffer' local array is used …

Jan 19, 2025
CVE-2024-57907
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: rockchip_saradc: fix information leak in triggered buffer The 'data' local struct is used …

Jan 19, 2025
CVE-2024-57906
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads8688: fix information leak in triggered buffer The 'buffer' local array is used …

Jan 19, 2025
CVE-2024-57905
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1119: fix information leak in triggered buffer The 'scan' local struct is used …

Jan 19, 2025
CVE-2024-57904
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91: call input_free_device() on allocated iio_dev Current implementation of at91_ts_register() calls input_free_deivce() on …

Jan 19, 2025
CVE-2025-21652
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipvlan: Fix use-after-free in ipvlan_get_iflink(). syzbot presented an use-after-free report [0] regarding ipvlan and linkwatch. …

Jan 19, 2025
CVE-2025-21650
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issue The TQP BAR space …

Jan 19, 2025
CVE-2025-21647
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed …

Jan 19, 2025
CVE-2025-21631
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix waker_bfqq UAF after bfq_split_bfqq() Our syzkaller report a following UAF for v6.6: …

Jan 19, 2025
CVE-2025-0566
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNetName of the file /goform/SetDevNetName. The manipulation of the …

Jan 19, 2025
CVE-2025-0565
7.3 HIGH

A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. …

Jan 19, 2025
CVE-2025-0564
7.3 HIGH

A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 19, 2025
CVE-2024-45662
7.5 HIGH

IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denial of service due …

Jan 18, 2025
CVE-2024-47113
8.1 HIGH

IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted XML statements, …

Jan 18, 2025
CVE-2024-13184
7.5 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions …

Jan 18, 2025
CVE-2025-0308
7.5 HIGH

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via …

Jan 18, 2025
CVE-2025-23209
8.0 HIGH KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that …

Jan 18, 2025
CVE-2023-50739
8.8 HIGH

A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leveraged by an attacker …

Jan 18, 2025
CVE-2018-9464
7.8 HIGH

In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalation of …

Jan 18, 2025
CVE-2018-9461
7.0 HIGH

In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app due to a race condition. This …

Jan 18, 2025
CVE-2018-9401
7.8 HIGH

In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to …

Jan 18, 2025
CVE-2018-9389
7.8 HIGH

In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to local escalation …

Jan 18, 2025
CVE-2018-9387
7.8 HIGH

In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local …

Jan 18, 2025
CVE-2025-23208
7.3 HIGH

zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (meta.db) is an append-list so group revocations/removals …

Jan 17, 2025
CVE-2018-9434
7.8 HIGH

In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with …

Jan 17, 2025
CVE-2018-9382
7.8 HIGH

In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This …

Jan 17, 2025
CVE-2018-9375
7.8 HIGH

In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This …

Jan 17, 2025
CVE-2025-23206
8.1 HIGH

The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. …

Jan 17, 2025
CVE-2025-21399
7.4 HIGH

Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability

Jan 17, 2025
CVE-2024-57030
8.1 HIGH

Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.

Jan 17, 2025
CVE-2024-52870
7.1 HIGH

Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result …

Jan 17, 2025
CVE-2025-0534
7.3 HIGH

A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is …

Jan 17, 2025
CVE-2025-0533
7.3 HIGH

A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is …

Jan 17, 2025
CVE-2025-0430
7.5 HIGH

Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition.

Jan 17, 2025
CVE-2024-12757
8.6 HIGH

Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker to potentially execute malicious code.

Jan 17, 2025
CVE-2024-26153
7.4 HIGH

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access …

Jan 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.