CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21062
7.8 HIGH

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction …

Oct 10, 2025
CVE-2025-21061
7.1 HIGH

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering …

Oct 10, 2025
CVE-2025-21060
5.5 MEDIUM

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required …

Oct 10, 2025
CVE-2025-21059
6.2 MEDIUM

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

Oct 10, 2025
CVE-2025-21058
7.3 HIGH

Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attackers to potentially execute arbitrary code …

Oct 10, 2025
CVE-2025-21057
4.0 MEDIUM

Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

Oct 10, 2025
CVE-2025-21055
4.3 MEDIUM

Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21054
4.0 MEDIUM

Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21053
4.0 MEDIUM

Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

Oct 10, 2025
CVE-2025-21052
4.0 MEDIUM

Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory …

Oct 10, 2025
CVE-2025-21051
4.0 MEDIUM

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-21050
7.1 HIGH

Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

Oct 10, 2025
CVE-2025-21049
5.5 MEDIUM

Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this …

Oct 10, 2025
CVE-2025-21048
6.7 MEDIUM

Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.

Oct 10, 2025
CVE-2025-21047
5.2 MEDIUM

Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

Oct 10, 2025
CVE-2025-21046
2.4 LOW

Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.

Oct 10, 2025
CVE-2025-21045
4.0 MEDIUM

Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.

Oct 10, 2025
CVE-2025-21044
5.7 MEDIUM

Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-10124
4.5 MEDIUM

The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. …

Oct 10, 2025
CVE-2025-61871
6.7 MEDIUM

NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root …

Oct 10, 2025
CVE-2025-11570
4.6 MEDIUM

Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if …

Oct 10, 2025
CVE-2025-11569

Rejected reason: This record was withdrawn by its CNA; further investigation revealed it was not a security issue.

Oct 10, 2025
CVE-2025-11450

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed …

Oct 10, 2025
CVE-2025-11449

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed …

Oct 10, 2025
CVE-2025-61928

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any …

Oct 9, 2025
CVE-2025-61926

Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook …

Oct 9, 2025
CVE-2025-62240
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update …

Oct 9, 2025
CVE-2025-61783

Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the …

Oct 9, 2025
CVE-2025-61779

Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint …

Oct 9, 2025
CVE-2025-61773
8.1 HIGH

pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both …

Oct 9, 2025
CVE-2025-61602
7.5 HIGH

BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for …

Oct 9, 2025
CVE-2025-61601
7.5 HIGH

BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash …

Oct 9, 2025
CVE-2025-60375
7.3 HIGH

The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password …

Oct 9, 2025
CVE-2025-59286
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

Oct 9, 2025
CVE-2025-59272
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

Oct 9, 2025
CVE-2025-59271
8.7 HIGH

Redis Enterprise Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-59252
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

Oct 9, 2025
CVE-2025-59247
8.8 HIGH

Azure PlayFab Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-59246
9.8 CRITICAL

Azure Entra ID Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-59218
9.6 CRITICAL

Azure Entra ID Elevation of Privilege Vulnerability

Oct 9, 2025
CVE-2025-55321
9.3 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.

Oct 9, 2025
CVE-2025-43296
5.5 MEDIUM

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

Oct 9, 2025
CVE-2025-35062
5.3 MEDIUM

Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.

Oct 9, 2025
CVE-2025-35061
5.9 MEDIUM

Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can …

Oct 9, 2025
CVE-2025-35060
5.5 MEDIUM

Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or …

Oct 9, 2025
CVE-2025-35059
4.3 MEDIUM

Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

Oct 9, 2025
CVE-2025-35058
5.9 MEDIUM

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can …

Oct 9, 2025
CVE-2025-35057
5.3 MEDIUM

Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can …

Oct 9, 2025
CVE-2025-35056
5.0 MEDIUM

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary …

Oct 9, 2025
CVE-2025-35055
8.8 HIGH

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can …

Oct 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.