CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29982
6.8 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit …

Apr 2, 2025
CVE-2025-27694
5.3 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this …

Apr 2, 2025
CVE-2025-27693
4.9 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged …

Apr 2, 2025
CVE-2025-27692
4.7 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote …

Apr 2, 2025
CVE-2025-31135
5.3 MEDIUM

Go-Guerrilla SMTP Daemon is a lightweight SMTP server written in Go. Prior to 1.6.7, when ProxyOn is enabled, the PROXY command will be accepted multiple …

Apr 1, 2025
CVE-2023-46988
6.7 MEDIUM

Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor …

Apr 1, 2025
CVE-2025-31889
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor. This issue affects Extensions for Elementor: from n/a through …

Apr 1, 2025
CVE-2025-31819
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks.This issue affects Nova Blocks: from n/a through <= 2.1.8.

Apr 1, 2025
CVE-2025-31753
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser advanced-speed-increaser.This issue affects Advanced Speed Increaser: from n/a through <= 2.2.1.

Apr 1, 2025
CVE-2025-31628
5.3 MEDIUM

Missing Authorization vulnerability in SlicedInvoices Sliced Invoices sliced-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliced Invoices: from n/a through <= 3.10.0.

Apr 1, 2025
CVE-2025-31550
5.8 MEDIUM

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in thom4 WP-LESS wp-less allows Retrieve Embedded Sensitive Data.This issue affects WP-LESS: from n/a through …

Apr 1, 2025
CVE-2025-31525
4.3 MEDIUM

Missing Authorization vulnerability in WP Messiah WP Mobile Bottom Menu mobile-bottom-menu-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mobile Bottom Menu: …

Apr 1, 2025
CVE-2025-30853
5.4 MEDIUM

Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Adaptive Images: from n/a through …

Apr 1, 2025
CVE-2025-29049
6.3 MEDIUM

Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.

Apr 1, 2025
CVE-2025-29036
5.9 MEDIUM

An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.

Apr 1, 2025
CVE-2024-13941
5.3 MEDIUM

A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ouch::archive::zip::convert_zip_date_time of the file zip.rs. …

Apr 1, 2025
CVE-2003-20001
5.6 MEDIUM

An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time …

Apr 1, 2025
CVE-2025-26056
5.4 MEDIUM

A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of …

Apr 1, 2025
CVE-2025-26055
6.5 MEDIUM

An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.

Apr 1, 2025
CVE-2025-26054
5.4 MEDIUM

Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.

Apr 1, 2025
CVE-2025-29208
6.5 MEDIUM

CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.

Apr 1, 2025
CVE-2025-28132
4.6 MEDIUM

A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized …

Apr 1, 2025
CVE-2025-28131
4.6 MEDIUM

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and …

Apr 1, 2025
CVE-2025-25041
5.5 MEDIUM

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A …

Apr 1, 2025
CVE-2025-21986
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: switchdev: Convert blocking notification chain to a raw one A blocking notification chain uses …

Apr 1, 2025
CVE-2025-21984
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: fix kernel BUG when userfaultfd_move encounters swapcache userfaultfd_move() checks whether the PTE entry is …

Apr 1, 2025
CVE-2025-21982
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: npcm8xx: Add NULL check in npcm8xx_gpio_fw devm_kasprintf() calls can return null pointers on …

Apr 1, 2025
CVE-2025-21981
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: fix memory leak in aRFS after reset Fix aRFS (accelerated Receive Flow Steering) structures …

Apr 1, 2025
CVE-2025-21980
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched: address a potential NULL pointer dereference in the GRED scheduler. If kzalloc in gred_init …

Apr 1, 2025
CVE-2025-21978
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: Fix address space leak when Hyper-V DRM device is removed When a Hyper-V DRM …

Apr 1, 2025
CVE-2025-21977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Fix hang in kdump kernel when on Hyper-V Gen 2 VMs Gen 2 …

Apr 1, 2025
CVE-2025-21976
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Allow graceful removal of framebuffer When a Hyper-V framebuffer device is unbind, hyperv_fb …

Apr 1, 2025
CVE-2025-21975
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: handle errors in mlx5_chains_create_table() In mlx5_chains_create_table(), the return value of mlx5_get_fdb_sub_ns() and mlx5_get_flow_namespace() must …

Apr 1, 2025
CVE-2025-21974
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: return fail if interface is down in bnxt_queue_mem_alloc() The bnxt_queue_mem_alloc() is called to …

Apr 1, 2025
CVE-2025-21972
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: mctp: unshare packets when reassembling Ensure that the frag_list used for reassembly isn't shared …

Apr 1, 2025
CVE-2025-21971
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: Prevent creation of classes with TC_H_ROOT The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination …

Apr 1, 2025
CVE-2025-21970
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Bridge, fix the crash caused by LAG state check When removing LAG device from …

Apr 1, 2025
CVE-2025-21965
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Validate prev_cpu in scx_bpf_select_cpu_dfl() If a BPF scheduler provides an invalid CPU (outside the …

Apr 1, 2025
CVE-2025-21964
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix integer overflow while processing acregmax mount option User-provided mount parameter acregmax of type …

Apr 1, 2025
CVE-2025-21963
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix integer overflow while processing acdirmax mount option User-provided mount parameter acdirmax of type …

Apr 1, 2025
CVE-2025-21962
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix integer overflow while processing closetimeo mount option User-provided mount parameter closetimeo of type …

Apr 1, 2025
CVE-2025-21961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix truesize for mb-xdp-pass case When mb-xdp is set and return is XDP_PASS, …

Apr 1, 2025
CVE-2025-21960
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: do not update checksum in bnxt_xdp_build_skb() The bnxt_rx_pkt() updates ip_summed value at the …

Apr 1, 2025
CVE-2025-21959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage …

Apr 1, 2025
CVE-2025-21958
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "openvswitch: switch to per-action label counting in conntrack" Currently, ovs_ct_set_labels() is only called for …

Apr 1, 2025
CVE-2025-21957
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qla1280: Fix kernel oops when debug level > 2 A null dereference or oops …

Apr 1, 2025
CVE-2025-21956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Assign normalized_pix_clk when color depth = 14 [WHY & HOW] A warning message "WARNING: …

Apr 1, 2025
CVE-2025-21955
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent connection release during oplock break notification ksmbd_work could be freed when after connection …

Apr 1, 2025
CVE-2025-21954
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently on stable trees we have support for netmem/devmem …

Apr 1, 2025
CVE-2025-21953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: mana: cleanup mana struct after debugfs_remove() When on a MANA VM hibernation is triggered, …

Apr 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.