CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cgroup: split cgroup_destroy_wq into 3 workqueues A hung task can occur during [1] LTP cgroup …

Oct 4, 2025
CVE-2025-39952
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: avoid buffer overflow in WID string configuration Fix the following copy overflow warning …

Oct 4, 2025
CVE-2025-39951
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: um: virtio_uml: Fix use-after-free after put_device in probe When register_virtio_device() fails in virtio_uml_probe(), the code …

Oct 4, 2025
CVE-2025-39950
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR A NULL pointer dereference …

Oct 4, 2025
CVE-2025-39949
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: qed: Don't collect too many protection override GRC elements In the protection override dump path, …

Oct 4, 2025
CVE-2025-39948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The ice_put_rx_mbuf() function handles calling ice_put_rx_buf() for …

Oct 4, 2025
CVE-2025-39947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Harden uplink netdev access against device unbind The function mlx5_uplink_netdev_get() gets the uplink netdevice …

Oct 4, 2025
CVE-2025-39946
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are bogus Normally we wait for …

Oct 4, 2025
CVE-2025-39945
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cnic: Fix use-after-free bugs in cnic_delete_task The original code uses cancel_delayed_work() in cnic_cm_stop_bnx2x_hw(), which does …

Oct 4, 2025
CVE-2025-39944
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp() The original code relies on cancel_delayed_work() in otx2_ptp_destroy(), which …

Oct 4, 2025
CVE-2025-39943
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer If data_offset and data_length of smb_direct_data_transfer …

Oct 4, 2025
CVE-2025-39942
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size This is inspired by the check for data_offset + …

Oct 4, 2025
CVE-2025-39941
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: zram: fix slot write race condition Parallel concurrent writes to the same zram index result …

Oct 4, 2025
CVE-2025-39940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm-stripe: fix a possible integer overflow There's a possible integer overflow in stripe_io_hints if we …

Oct 4, 2025
CVE-2025-39939
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Fix memory corruption when using identity domain zpci_get_iommu_ctrs() returns counter information to be reported …

Oct 4, 2025
CVE-2025-39938
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm-lpass-dais: Fix NULL pointer dereference if source graph failed If earlier opening of …

Oct 4, 2025
CVE-2025-39937
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer Since commit 7d5e9737efda ("net: rfkill: …

Oct 4, 2025
CVE-2025-39936
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() When 9770b428b1a2 ("crypto: ccp …

Oct 4, 2025
CVE-2025-39935
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: codec: sma1307: Fix memory corruption in sma1307_setting_loaded() The sma1307->set.header_size is how many integers are …

Oct 4, 2025
CVE-2025-39934
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm: bridge: anx7625: Fix NULL pointer dereference with early IRQ If the interrupt occurs before …

Oct 4, 2025
CVE-2025-39933
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related …

Oct 4, 2025
CVE-2025-39932
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work) In smbd_destroy() we may destroy the memory so we …

Oct 4, 2025
CVE-2025-39931
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_sendmsg If an error causes af_alg_sendmsg …

Oct 4, 2025
CVE-2025-39929
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path During tests of another unrelated patch …

Oct 4, 2025
CVE-2025-9952
6.1 MEDIUM

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via …

Oct 4, 2025
CVE-2025-9886
4.3 MEDIUM

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Cross-Site Request Forgery in …

Oct 4, 2025
CVE-2025-10383
6.4 MEDIUM

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field …

Oct 4, 2025
CVE-2025-9485
9.8 CRITICAL

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and …

Oct 4, 2025
CVE-2025-9243
8.1 HIGH

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capability check on the get_cc_orders and update_order_status functions …

Oct 4, 2025
CVE-2025-9030
5.4 MEDIUM

The Majestic Before After Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_label' and 'after_label' parameters in versions less than, or …

Oct 4, 2025
CVE-2025-9029
4.3 MEDIUM

The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to missing authorization via the wdkit_handle_review_submission …

Oct 4, 2025
CVE-2025-8726
5.4 MEDIUM

The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input …

Oct 4, 2025
CVE-2025-61962
5.9 MEDIUM

In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.

Oct 4, 2025
CVE-2025-61895

Rejected reason: Not used

Oct 4, 2025
CVE-2025-61894

Rejected reason: Not used

Oct 4, 2025
CVE-2025-61893

Rejected reason: Not used

Oct 4, 2025
CVE-2025-61892

Rejected reason: Not used

Oct 4, 2025
CVE-2025-61891

Rejected reason: Not used

Oct 4, 2025
CVE-2025-61890

Rejected reason: Not used

Oct 4, 2025
CVE-2025-61889

Rejected reason: Not used

Oct 4, 2025
CVE-2025-61888

Rejected reason: Not used

Oct 4, 2025
CVE-2025-61887

Rejected reason: Not used

Oct 4, 2025
CVE-2025-11228
5.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Oct 4, 2025
CVE-2025-11227
6.5 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.10.0 via …

Oct 4, 2025
CVE-2025-10746
6.5 MEDIUM

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to …

Oct 4, 2025
CVE-2025-10751
7.8 HIGH

MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects MacForge: 1.2.0 Beta 1.

Oct 4, 2025
CVE-2025-61685
6.5 MEDIUM

Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vulnerable to a Directory Traversal attack that results in …

Oct 3, 2025
CVE-2025-61681
5.4 MEDIUM

KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its file upload functionality that can be exploited …

Oct 3, 2025
CVE-2025-61680

Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.6 stores passwords using VS Code's configuration API which …

Oct 3, 2025
CVE-2025-61679
7.7 HIGH

Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even …

Oct 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.