CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21721
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle errors that nilfs_prepare_chunk() may return Patch series "nilfs2: fix issues with rename operations". …

Feb 27, 2025
CVE-2025-21720
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfrm: delete intermediate secpath entry in packet offload mode Packets handled by hardware have added …

Feb 27, 2025
CVE-2025-21716
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix uninit-value in vxlan_vnifilter_dump() KMSAN reported an uninit-value access in vxlan_vnifilter_dump() [1]. If the …

Feb 27, 2025
CVE-2025-21713
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: Don't unset window if it was never set On pSeries, when user attempts to …

Feb 27, 2025
CVE-2025-21712
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime After commit ec6bb299c7c3 ("md/md-bitmap: add 'sync_size' into struct md_bitmap_stats"), …

Feb 27, 2025
CVE-2025-21711
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/rose: prevent integer overflows in rose_setsockopt() In case of possible unpredictably large arguments passed to …

Feb 27, 2025
CVE-2025-21710
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: correct handling of extreme memory squeeze Testing with iperf3 using the "pasta" protocol splicer …

Feb 27, 2025
CVE-2025-21709
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: kernel: be more careful about dup_mmap() failures and uprobe registering If a memory allocation fails …

Feb 27, 2025
CVE-2025-21708
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: enable basic endpoint checking Syzkaller reports [1] encountering a common issue of …

Feb 27, 2025
CVE-2025-21707
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: consolidate suboption status MPTCP maintains the received sub-options status is the bitmask carrying the …

Feb 27, 2025
CVE-2025-21706
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only set fullmesh for subflow endp With the in-kernel path-manager, it is possible …

Feb 27, 2025
CVE-2025-21705
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: handle fastopen disconnect correctly Syzbot was able to trigger a data stream corruption: WARNING: …

Feb 27, 2025
CVE-2024-58000
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: prevent reg-wait speculations With *ENTER_EXT_ARG_REG instead of passing a user pointer with arguments for …

Feb 27, 2025
CVE-2024-57999
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW Power Hypervisor can possibily allocate MMIO window …

Feb 27, 2025
CVE-2024-57997
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix channel survey memory allocation size KASAN reported a memory allocation issue in …

Feb 27, 2025
CVE-2024-57996
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: don't allow 1 packet limit The current implementation does not work correctly with …

Feb 27, 2025
CVE-2024-57994
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ptr_ring: do not block hard interrupts in ptr_ring_resize_multiple() Jakub added a lockdep_assert_no_hardirq() check in __page_pool_put_page() …

Feb 27, 2025
CVE-2024-57993
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: Fix warning in thrustmaster_probe by adding endpoint check syzbot has found a type …

Feb 27, 2025
CVE-2024-57992
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: unregister wiphy only if it has been registered There is a specific error …

Feb 27, 2025
CVE-2024-57991
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: chan: fix soft lockup in rtw89_entity_recalc_mgnt_roles() During rtw89_entity_recalc_mgnt_roles(), there is a normalizing process …

Feb 27, 2025
CVE-2024-57989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix NULL deref check in mt7925_change_vif_links In mt7925_change_vif_links() devm_kzalloc() may return NULL …

Feb 27, 2025
CVE-2024-57988
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btbcm: Fix NULL deref in btbcm_get_board_name() devm_kstrdup() can return a NULL pointer on failure,but …

Feb 27, 2025
CVE-2024-57987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: check for NULL in btrtl_setup_realtek() If insert an USB dongle which chip is …

Feb 27, 2025
CVE-2024-57986
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections A report in …

Feb 27, 2025
CVE-2024-57985
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Cleanup global '__scm' on probe failures If SCM driver fails the probe, …

Feb 27, 2025
CVE-2024-57981
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix NULL pointer dereference on certain command aborts If a command is queued …

Feb 27, 2025
CVE-2024-57978
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Fix potential error pointer dereference in detach_pm() The proble is on the first …

Feb 27, 2025
CVE-2024-57977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memcg: fix soft lockup in the OOM process A soft lockup issue was found in …

Feb 27, 2025
CVE-2024-57976
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: do proper folio cleanup when cow_file_range() failed [BUG] When testing with COW fixup marked …

Feb 27, 2025
CVE-2024-57975
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: do proper folio cleanup when run_delalloc_nocow() failed [BUG] With CONFIG_DEBUG_VM set, test case generic/476 …

Feb 27, 2025
CVE-2024-57974
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: udp: Deal with race between UDP socket address change and rehash If a UDP socket …

Feb 27, 2025
CVE-2024-57973
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. …

Feb 27, 2025
CVE-2024-57953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rtc: tps6594: Fix integer overflow on 32bit systems The problem is this multiply in tps6594_rtc_set_offset() …

Feb 27, 2025
CVE-2024-57423
6.1 MEDIUM

A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.

Feb 26, 2025
CVE-2024-50684
6.5 MEDIUM

SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted …

Feb 26, 2025
CVE-2025-1726
4.3 MEDIUM

There is a SQL injection issue in Esri ArcGIS Monitor versions 2023.0 through 2024.x on Windows and Linux that allows a remote, authenticated attacker with …

Feb 26, 2025
CVE-2025-20161
5.1 MEDIUM

A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow …

Feb 26, 2025
CVE-2025-20119
6.0 MEDIUM

A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause …

Feb 26, 2025
CVE-2025-20118
4.4 MEDIUM

A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an …

Feb 26, 2025
CVE-2025-20117
5.1 MEDIUM

A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of …

Feb 26, 2025
CVE-2025-20116
4.8 MEDIUM

A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. …

Feb 26, 2025
CVE-2025-0941
5.8 MEDIUM

MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain text within the system. This data is not available …

Feb 26, 2025
CVE-2025-25462
5.5 MEDIUM

A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via …

Feb 26, 2025
CVE-2024-46226
4.8 MEDIUM

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a …

Feb 26, 2025
CVE-2025-25827
6.8 MEDIUM

A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted …

Feb 26, 2025
CVE-2025-25818
5.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Feb 26, 2025
CVE-2025-25813
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.

Feb 26, 2025
CVE-2025-25802
5.1 MEDIUM

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

Feb 26, 2025
CVE-2025-25800
5.3 MEDIUM

SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.

Feb 26, 2025
CVE-2025-25799
6.0 MEDIUM

SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.

Feb 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.