CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59672

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59671

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59670

Rejected reason: Not used

Sep 19, 2025
CVE-2025-10690
9.8 CRITICAL

The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the …

Sep 19, 2025
CVE-2025-6198
7.2 HIGH

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially …

Sep 19, 2025
CVE-2025-30755
6.1 MEDIUM

OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens through improper handling of the revision parameter. The …

Sep 19, 2025
CVE-2025-59692
3.7 LOW

PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to …

Sep 18, 2025
CVE-2025-59691
3.7 LOW

PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or …

Sep 18, 2025
CVE-2025-59220
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Sep 18, 2025
CVE-2025-59216
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 18, 2025
CVE-2025-59215
7.0 HIGH

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 18, 2025
CVE-2025-54860
7.7 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as …

Sep 18, 2025
CVE-2025-54818
8.0 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The …

Sep 18, 2025
CVE-2025-54810
8.0 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The …

Sep 18, 2025
CVE-2025-54497
8.1 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, …

Sep 18, 2025
CVE-2025-53969
8.8 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software, such as …

Sep 18, 2025
CVE-2025-52873
8.1 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, …

Sep 18, 2025
CVE-2025-10035
10.0 CRITICAL KEV

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary …

Sep 18, 2025
CVE-2025-57295
8.0 HIGH

H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and …

Sep 18, 2025
CVE-2025-57293
8.8 HIGH

A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt. The phy_interface parameter is …

Sep 18, 2025
CVE-2025-55068
8.2 HIGH

Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time …

Sep 18, 2025
CVE-2025-54807
9.8 CRITICAL

The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, …

Sep 18, 2025
CVE-2025-54754
8.0 HIGH

An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then …

Sep 18, 2025
CVE-2025-53947
7.7 HIGH

A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data. A data …

Sep 18, 2025
CVE-2025-47698

An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.

Sep 18, 2025
CVE-2025-30519
9.8 CRITICAL

Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to …

Sep 18, 2025
CVE-2025-10689
6.3 MEDIUM

A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads …

Sep 18, 2025
CVE-2025-59424
7.3 HIGH

LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. …

Sep 18, 2025
CVE-2025-10688
7.3 HIGH

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/operation/paid.php. This manipulation of the argument …

Sep 18, 2025
CVE-2025-47906
6.5 MEDIUM

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result …

Sep 18, 2025
CVE-2025-26503
6.7 MEDIUM

A crafted system call argument can cause memory corruption.

Sep 18, 2025
CVE-2025-10650

SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin …

Sep 18, 2025
CVE-2025-10687
7.3 HIGH

A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /admin/add_teacher.php. The manipulation of the argument Username …

Sep 18, 2025
CVE-2025-55912
7.3 HIGH

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any …

Sep 18, 2025
CVE-2025-50255
7.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request.

Sep 18, 2025
CVE-2025-36146
4.3 MEDIUM

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version information which could aid in further attacks against the system.

Sep 18, 2025
CVE-2025-36143
4.7 MEDIUM

IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation of user supplied input.

Sep 18, 2025
CVE-2025-36139
5.5 MEDIUM

IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI …

Sep 18, 2025
CVE-2025-10676
4.3 MEDIUM

A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /brand/queryAll. Executing manipulation can lead to improper authorization. …

Sep 18, 2025
CVE-2025-10675
4.3 MEDIUM

A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of the file /attribute/queryAll. Performing manipulation results in improper authorization. …

Sep 18, 2025
CVE-2025-10674
4.3 MEDIUM

A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController of the file /attributecategory/queryAll. Such manipulation leads to improper authorization. The attack …

Sep 18, 2025
CVE-2023-53447
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: don't reset unchangable mount option in f2fs_remount() syzbot reports a bug as below: general …

Sep 18, 2025
CVE-2023-53446
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Disable ASPM on MFD function removal to avoid use-after-free Struct pcie_link_state->downstream is a pointer …

Sep 18, 2025
CVE-2023-53445
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Fix a refcount bug in qrtr_recvmsg() Syzbot reported a bug as following: refcount_t: …

Sep 18, 2025
CVE-2023-53444
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fix bulk_move corruption when adding a entry When the resource is the first in …

Sep 18, 2025
CVE-2023-53443
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mfd: arizona: Use pm_runtime_resume_and_get() to prevent refcnt leak In arizona_clk32k_enable(), we should use pm_runtime_resume_and_get() as …

Sep 18, 2025
CVE-2023-53442
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: Block switchdev mode when ADQ is active and vice versa ADQ and switchdev are …

Sep 18, 2025
CVE-2023-53441
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: cpumap: Fix memory leak in cpu_map_update_elem Syzkaller reported a memory leak as follows: BUG: …

Sep 18, 2025
CVE-2023-53440
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix sysfs interface lifetime The current nilfs2 sysfs support has issues with the timing …

Sep 18, 2025
CVE-2023-53439
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: skb_partial_csum_set() fix against transport header magic value skb->transport_header uses the special 0xFFFF value to …

Sep 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.