CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-47256
5.6 MEDIUM

Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.

May 6, 2025
CVE-2025-4388
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, …

May 6, 2025
CVE-2025-44900
6.5 MEDIUM

In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter mac leads to stack overflow.

May 6, 2025
CVE-2025-37730
6.5 MEDIUM

Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not …

May 6, 2025
CVE-2025-46736
5.3 MEDIUM

Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of …

May 6, 2025
CVE-2025-45250
5.5 MEDIUM

MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.

May 6, 2025
CVE-2025-32022
4.6 MEDIUM

Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot which leads to it overwriting other parts …

May 6, 2025
CVE-2025-26262
6.5 MEDIUM

An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a …

May 6, 2025
CVE-2025-22476
5.5 MEDIUM

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

May 6, 2025
CVE-2023-33770
5.1 MEDIUM

Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php.

May 6, 2025
CVE-2025-4374
6.5 MEDIUM

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been …

May 6, 2025
CVE-2025-4373
4.8 MEDIUM

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the …

May 6, 2025
CVE-2025-4357
4.7 MEDIUM

A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /goform/telnet. The …

May 6, 2025
CVE-2025-4353
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424. Affected is an unknown function of the …

May 6, 2025
CVE-2025-4352
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250424. This issue affects some unknown processing …

May 6, 2025
CVE-2025-3782
6.4 MEDIUM

The Cision Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.3.0 due …

May 6, 2025
CVE-2025-4341
6.3 MEDIUM

A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the file /htdocs/ssdpcgi …

May 6, 2025
CVE-2024-49830
6.6 MEDIUM

Memory corruption while processing an IOCTL call to set mixer controls.

May 6, 2025
CVE-2024-49829
6.7 MEDIUM

Memory corruption can occur during context user dumps due to inadequate checks on buffer length.

May 6, 2025
CVE-2024-45583
6.6 MEDIUM

Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.

May 6, 2025
CVE-2024-45581
6.6 MEDIUM

Memory corruption while sound model registration for voice activation with audio kernel driver.

May 6, 2025
CVE-2024-45570
6.6 MEDIUM

Memory corruption may occur during IO configuration processing when the IO port count is invalid.

May 6, 2025
CVE-2024-45568
6.7 MEDIUM

Memory corruption due to improper bounds check while command handling in camera-kernel driver.

May 6, 2025
CVE-2024-45563
6.6 MEDIUM

Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.

May 6, 2025
CVE-2024-45562
6.6 MEDIUM

Memory corruption during concurrent access to server info object due to unprotected critical field.

May 6, 2025
CVE-2025-4340
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. …

May 6, 2025
CVE-2025-4333
6.3 MEDIUM

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function uploadFile of the …

May 6, 2025
CVE-2025-46593
5.1 MEDIUM

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

May 6, 2025
CVE-2025-46592
4.4 MEDIUM

Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.

May 6, 2025
CVE-2025-46591
6.2 MEDIUM

Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 6, 2025
CVE-2025-46590
6.3 MEDIUM

Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search …

May 6, 2025
CVE-2025-46589
4.4 MEDIUM

Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

May 6, 2025
CVE-2025-46588
4.4 MEDIUM

Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

May 6, 2025
CVE-2025-46587
6.2 MEDIUM

Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 6, 2025
CVE-2025-3281
5.3 MEDIUM

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in …

May 6, 2025
CVE-2025-3020
5.4 MEDIUM

An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several fields of the configuration webpage with …

May 6, 2025
CVE-2024-58252
6.2 MEDIUM

Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 6, 2025
CVE-2025-4329
4.3 MEDIUM

A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the …

May 6, 2025
CVE-2025-4327
4.3 MEDIUM

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. …

May 6, 2025
CVE-2025-46586
5.1 MEDIUM

Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.

May 6, 2025
CVE-2025-4337
4.3 MEDIUM

The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing …

May 6, 2025
CVE-2025-4310
4.7 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/add_topic.php?category=BBS. The manipulation …

May 6, 2025
CVE-2025-3609
5.3 MEDIUM

The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to …

May 6, 2025
CVE-2025-4305
6.3 MEDIUM

A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file app/tools/controller/File.php. …

May 6, 2025
CVE-2024-39442
6.2 MEDIUM

In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

May 6, 2025
CVE-2025-4291
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. …

May 5, 2025
CVE-2025-1493
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service …

May 5, 2025
CVE-2025-1000
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user to cause …

May 5, 2025
CVE-2025-0915
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations could allow an authenticated …

May 5, 2025
CVE-2025-46813
5.8 MEDIUM

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that …

May 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.