CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39957
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Currently the S1G capability element is not taken into …

Oct 9, 2025
CVE-2025-39956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error When igc_led_setup() fails, igc_probe() fails and triggers …

Oct 9, 2025
CVE-2025-39955
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). syzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk …

Oct 9, 2025
CVE-2025-39954
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate readback When dual-divider clock support was introduced, the …

Oct 9, 2025
CVE-2025-10862
7.5 HIGH

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to SQL Injection in all versions up to, …

Oct 9, 2025
CVE-2025-11539
9.9 CRITICAL

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv …

Oct 9, 2025
CVE-2025-11522
9.8 CRITICAL

The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and …

Oct 9, 2025
CVE-2025-7634
9.8 CRITICAL

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up …

Oct 9, 2025
CVE-2025-7526
9.8 CRITICAL

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to …

Oct 9, 2025
CVE-2025-6038
8.8 HIGH

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password update in …

Oct 9, 2025
CVE-2025-47355
7.8 HIGH

Memory corruption while invoking remote procedure IOCTL calls.

Oct 9, 2025
CVE-2025-47354
7.8 HIGH

Memory corruption while allocating buffers in DSP service.

Oct 9, 2025
CVE-2025-47351
7.8 HIGH

Memory corruption while processing user buffers.

Oct 9, 2025
CVE-2025-47349
7.8 HIGH

Memory corruption while processing an escape call.

Oct 9, 2025
CVE-2025-47347
7.8 HIGH

Memory corruption while processing control commands in the virtual memory management interface.

Oct 9, 2025
CVE-2025-47342
7.1 HIGH

Transient DOS may occur when multi-profile concurrency arises with QHS enabled.

Oct 9, 2025
CVE-2025-47341
7.8 HIGH

memory corruption while processing an image encoding completion event.

Oct 9, 2025
CVE-2025-47340
7.8 HIGH

Memory corruption while processing IOCTL call to get the mapping.

Oct 9, 2025
CVE-2025-47338
7.8 HIGH

Memory corruption while processing escape commands from userspace.

Oct 9, 2025
CVE-2025-27060
8.8 HIGH

Memory corruption while performing SCM call with malformed inputs.

Oct 9, 2025
CVE-2025-27059
8.8 HIGH

Memory corruption while performing SCM call.

Oct 9, 2025
CVE-2025-27054
7.8 HIGH

Memory corruption while processing a malformed license file during reboot.

Oct 9, 2025
CVE-2025-27053
7.8 HIGH

Memory corruption during PlayReady APP usecase while processing TA commands.

Oct 9, 2025
CVE-2025-27049
5.5 MEDIUM

Transient DOS while processing IOCTL call for image encoding.

Oct 9, 2025
CVE-2025-27048
7.8 HIGH

Memory corruption while processing camera platform driver IOCTL calls.

Oct 9, 2025
CVE-2025-27045
6.1 MEDIUM

Information disclosure while processing batch command execution in Video driver.

Oct 9, 2025
CVE-2025-27041
5.5 MEDIUM

Transient DOS while processing video packets received from video firmware.

Oct 9, 2025
CVE-2025-27040
6.5 MEDIUM

Information disclosure may occur while processing the hypervisor log.

Oct 9, 2025
CVE-2025-27039
6.6 MEDIUM

Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.

Oct 9, 2025
CVE-2025-11530
6.3 MEDIUM

A weakness has been identified in code-projects Online Complaint Site 1.0. Affected is an unknown function of the file /cms/admin/state.php. This manipulation of the argument …

Oct 9, 2025
CVE-2025-11529
7.3 HIGH

A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/AuthMiddleware.php of the component API Endpoint. …

Oct 9, 2025
CVE-2025-11528
8.8 HIGH

A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to …

Oct 9, 2025
CVE-2025-11527
8.8 HIGH

A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform/fast_setting_pppoe_set. Executing a manipulation of the argument …

Oct 9, 2025
CVE-2025-11526
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44. The affected element is an unknown function of the file /goform/WifiMacFilterSet. Performing a manipulation of the argument …

Oct 9, 2025
CVE-2025-11525
8.8 HIGH

A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads …

Oct 9, 2025
CVE-2025-11524
8.8 HIGH

A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCfg. This manipulation of the argument ddnsEn …

Oct 9, 2025
CVE-2025-11523
6.3 MEDIUM

A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in …

Oct 9, 2025
CVE-2025-11166
5.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, …

Oct 9, 2025
CVE-2025-10586
9.8 CRITICAL

The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to …

Oct 9, 2025
CVE-2025-10496
7.2 HIGH

The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in all versions up to, and including, …

Oct 9, 2025
CVE-2025-11516
6.3 MEDIUM

A weakness has been identified in code-projects Online Complaint Site 1.0. Impacted is an unknown function of the file /cms/users/complaint-details.php. Executing manipulation of the argument …

Oct 9, 2025
CVE-2025-11515
6.3 MEDIUM

A security flaw has been discovered in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/users/register-complaint.php. Performing manipulation of …

Oct 9, 2025
CVE-2025-11514
6.3 MEDIUM

A vulnerability was identified in code-projects Online Complaint Site 1.0. This vulnerability affects unknown code of the file /cms/users/index.php. Such manipulation of the argument Username …

Oct 9, 2025
CVE-2025-11513
7.3 HIGH

A vulnerability was determined in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/supplier_update.php. This manipulation of the argument supp_id causes …

Oct 9, 2025
CVE-2025-11512
4.3 MEDIUM

A vulnerability was found in code-projects Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/voters_add.php. The manipulation of the …

Oct 9, 2025
CVE-2025-61913
9.9 CRITICAL

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in …

Oct 8, 2025
CVE-2025-11511
6.3 MEDIUM

A flaw has been found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/supplier_add.php. Executing manipulation of the argument supp_email …

Oct 8, 2025
CVE-2025-11509
6.3 MEDIUM

A vulnerability was detected in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/product_add.php. Performing manipulation of the argument prod_name results …

Oct 8, 2025
CVE-2025-11508
4.7 MEDIUM

A security vulnerability has been detected in code-projects Voting System 1.0. This affects an unknown function of the file /admin/voters_add.php. Such manipulation of the argument …

Oct 8, 2025
CVE-2025-11535

MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: …

Oct 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.