CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20334
8.8 HIGH

A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root …

Sep 24, 2025
CVE-2025-10909
2.4 LOW

A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the …

Sep 24, 2025
CVE-2025-10892
8.8 HIGH

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10891
8.8 HIGH

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10890
9.1 CRITICAL

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10585
9.8 CRITICAL KEV

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10502
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium …

Sep 24, 2025
CVE-2025-10501
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 24, 2025
CVE-2025-10500
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 24, 2025
CVE-2025-56819
9.8 CRITICAL

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

Sep 24, 2025
CVE-2025-47329
7.8 HIGH

Memory corruption while handling invalid inputs in application info setup.

Sep 24, 2025
CVE-2025-47328
7.5 HIGH

Transient DOS while processing power control requests with invalid antenna or stream values.

Sep 24, 2025
CVE-2025-47327
7.8 HIGH

Memory corruption while encoding the image data.

Sep 24, 2025
CVE-2025-47326
7.5 HIGH

Transient DOS while handling command data during power control processing.

Sep 24, 2025
CVE-2025-47318
7.5 HIGH

Transient DOS while parsing the EPTM test control message to get the test pattern.

Sep 24, 2025
CVE-2025-47317
7.8 HIGH

Memory corruption due to global buffer overflow when a test command uses an invalid payload type.

Sep 24, 2025
CVE-2025-47316
7.8 HIGH

Memory corruption due to double free when multiple threads race to set the timestamp store.

Sep 24, 2025
CVE-2025-47315
7.8 HIGH

Memory corruption while handling repeated memory unmap requests from guest VM.

Sep 24, 2025
CVE-2025-47314
7.8 HIGH

Memory corruption while processing data sent by FE driver.

Sep 24, 2025
CVE-2025-27077
7.8 HIGH

Memory corruption while processing message in guest VM.

Sep 24, 2025
CVE-2025-27037
7.8 HIGH

Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.

Sep 24, 2025
CVE-2025-27036
6.1 MEDIUM

Information disclosure when Video engine escape input data is less than expected minimum size.

Sep 24, 2025
CVE-2025-27034
9.8 CRITICAL

Memory corruption while selecting the PLMN from SOR failed list.

Sep 24, 2025
CVE-2025-27033
6.1 MEDIUM

Information disclosure while running video usecase having rogue firmware.

Sep 24, 2025
CVE-2025-27032
7.8 HIGH

memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.

Sep 24, 2025
CVE-2025-27030
6.1 MEDIUM

information disclosure while invoking calibration data from user space to update firmware size.

Sep 24, 2025
CVE-2025-21488
8.2 HIGH

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.

Sep 24, 2025
CVE-2025-21487
8.2 HIGH

Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.

Sep 24, 2025
CVE-2025-21484
8.2 HIGH

Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.

Sep 24, 2025
CVE-2025-21483
9.8 CRITICAL

Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.

Sep 24, 2025
CVE-2025-21482
7.1 HIGH

Cryptographic issue while performing RSA PKCS padding decoding.

Sep 24, 2025
CVE-2025-21481
7.8 HIGH

Memory corruption while performing private key encryption in trusted application.

Sep 24, 2025
CVE-2025-21476
7.8 HIGH

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

Sep 24, 2025
CVE-2025-10360

In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files …

Sep 24, 2025
CVE-2025-8869

When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note …

Sep 24, 2025
CVE-2025-48868
7.2 HIGH

Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to …

Sep 24, 2025
CVE-2025-23354
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful …

Sep 24, 2025
CVE-2025-23353
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A …

Sep 24, 2025
CVE-2025-23349
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this …

Sep 24, 2025
CVE-2025-23348
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. …

Sep 24, 2025
CVE-2025-23346
3.3 LOW

NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exploit of this vulnerability may …

Sep 24, 2025
CVE-2025-23340
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed …

Sep 24, 2025
CVE-2025-23339
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to …

Sep 24, 2025
CVE-2025-23338
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write by running nvdisasm on a malicious …

Sep 24, 2025
CVE-2025-23308
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to …

Sep 24, 2025
CVE-2025-23275
4.2 MEDIUM

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain …

Sep 24, 2025
CVE-2025-23274
4.5 MEDIUM

NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted input image with dimensions …

Sep 24, 2025
CVE-2025-23273
2.5 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a divide by zero error by submitting …

Sep 24, 2025
CVE-2025-23272
5.7 MEDIUM

NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially crafted JPEG file. A successful exploit …

Sep 24, 2025
CVE-2025-23271
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed …

Sep 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.