CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23255
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-bounds read by passing a malformed …

Sep 24, 2025
CVE-2025-23248
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed …

Sep 24, 2025
CVE-2025-9353
6.4 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to …

Sep 24, 2025
CVE-2025-60020
6.4 MEDIUM

nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.

Sep 24, 2025
CVE-2025-10906
8.4 HIGH

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the …

Sep 24, 2025
CVE-2025-9054
9.8 CRITICAL

The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Sep 24, 2025
CVE-2025-39890
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_ready_ext_event Currently, in ath12k_service_ready_ext_event(), svc_rdy_ext.mac_phy_caps is not freed in …

Sep 24, 2025
CVE-2025-39889
8.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C …

Sep 24, 2025
CVE-2024-58241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregister_dev This make use of disable_work_* on hci_unregister_dev since the …

Sep 24, 2025
CVE-2025-58457
4.3 MEDIUM

Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 …

Sep 24, 2025
CVE-2025-9031
4.3 MEDIUM

Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing.This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.

Sep 24, 2025
CVE-2025-41716
5.3 MEDIUM

The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical …

Sep 24, 2025
CVE-2025-41715
9.8 CRITICAL

The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to gain unauthorized access and potentially compromise it.

Sep 24, 2025
CVE-2025-48459
5.3 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, …

Sep 24, 2025
CVE-2025-48392
7.5 HIGH

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version …

Sep 24, 2025
CVE-2025-58319
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute …

Sep 24, 2025
CVE-2025-58317
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute …

Sep 24, 2025
CVE-2025-59930

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59929

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59928

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59927

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59926

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59925

Rejected reason: Not used

Sep 24, 2025
CVE-2025-59924

Rejected reason: Not used

Sep 24, 2025
CVE-2023-47538

Rejected reason: Not used

Sep 24, 2025
CVE-2025-43819
6.5 MEDIUM

A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and …

Sep 24, 2025
CVE-2025-43779
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 …

Sep 24, 2025
CVE-2025-58473
5.9 MEDIUM

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated …

Sep 23, 2025
CVE-2025-57882
5.9 MEDIUM

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated …

Sep 23, 2025
CVE-2025-55069
8.3 HIGH

A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the …

Sep 23, 2025
CVE-2025-55038
6.8 MEDIUM

An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC …

Sep 23, 2025
CVE-2025-59484
8.3 HIGH

The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the …

Sep 23, 2025
CVE-2025-58069
5.3 MEDIUM

The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that …

Sep 23, 2025
CVE-2025-54855
4.2 MEDIUM

Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to …

Sep 23, 2025
CVE-2024-21935
5.0 MEDIUM

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local …

Sep 23, 2025
CVE-2024-21927
5.0 MEDIUM

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing …

Sep 23, 2025
CVE-2025-59826
7.6 HIGH

Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, potentially introducing malicious, incorrect, or misleading content. …

Sep 23, 2025
CVE-2025-58354

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In Kata Containers versions …

Sep 23, 2025
CVE-2025-56311
6.5 MEDIUM

In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF vulnerability on the reboot endpoint (/boaform/admin/formReboot). An attacker can …

Sep 23, 2025
CVE-2025-59825

astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-tar, tar archives may extract outside of their intended …

Sep 23, 2025
CVE-2025-57636
6.5 MEDIUM

OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP parameter "time".

Sep 23, 2025
CVE-2025-59822
7.5 HIGH

Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling …

Sep 23, 2025
CVE-2025-59534
7.3 HIGH

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the …

Sep 23, 2025
CVE-2025-58674
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue …

Sep 23, 2025
CVE-2025-57638
7.5 HIGH

Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.

Sep 23, 2025
CVE-2025-57637
7.5 HIGH

Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav4 parameter allowing attackers to cause a denial …

Sep 23, 2025
CVE-2025-56146
5.3 MEDIUM

Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.

Sep 23, 2025
CVE-2025-54081
6.7 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If …

Sep 23, 2025
CVE-2025-51005
7.5 HIGH

A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file is processed, the program incorrectly handles memory in the …

Sep 23, 2025
CVE-2025-45326
6.5 MEDIUM

An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.

Sep 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.