CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-50369
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix null-ptr-deref in vkms_release() A null-ptr-deref is triggered when it tries to destroy the …

Sep 17, 2025
CVE-2022-50368
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: fix memory corruption with too many bridges Add the missing sanity check on the …

Sep 17, 2025
CVE-2022-50367
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs: fix UAF/GPF bug in nilfs_mdt_destroy In alloc_inode, inode_init_always() could return -ENOMEM if security_inode_alloc() fails, …

Sep 17, 2025
CVE-2022-50366
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue When value < time_unit, the parameter of ilog2() will …

Sep 17, 2025
CVE-2022-50365
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: skbuff: Account for tail adjustment during pull operations Extending the tail can have some unexpected …

Sep 17, 2025
CVE-2022-50364
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: mux: reg: check return value after calling platform_get_resource() It will cause null-ptr-deref in resource_size(), …

Sep 17, 2025
CVE-2022-50363
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: skmsg: pass gfp argument to alloc_sk_msg() syzbot found that alloc_sk_msg() could be called from a …

Sep 17, 2025
CVE-2022-50362
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: hisilicon: Add multi-thread support for a DMA channel When we get a DMA channel …

Sep 17, 2025
CVE-2022-50361
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: add missing unregister_netdev() in wilc_netdev_ifc_init() Fault injection test reports this issue: kernel BUG …

Sep 17, 2025
CVE-2022-50360
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: fix aux-bus EP lifetime Device-managed resources allocated post component bind must be tied to …

Sep 17, 2025
CVE-2022-50359
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: cx88: Fix a null-ptr-deref bug in buffer_prepare() When the driver calls cx88_risc_buffer() to prepare …

Sep 17, 2025
CVE-2022-50358
4.2 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit trap at initialization, …

Sep 17, 2025
CVE-2022-50357
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: fix some leaks in probe The dwc3_get_properties() function calls: dwc->usb_psy = power_supply_get_by_name(usb_psy_name); …

Sep 17, 2025
CVE-2022-50356
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: sched: sfb: fix null pointer access issue when sfb_init() fails When the default qdisc …

Sep 17, 2025
CVE-2022-50355
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: vt6655: fix some erroneous memory clean-up loops In some initialization functions of this driver, …

Sep 17, 2025
CVE-2022-50354
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix kfd_process_device_init_vm error handling Should only destroy the ib_mem and let process cleanup worker …

Sep 17, 2025
CVE-2022-50353
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: wmt-sdmmc: fix return value check of mmc_add_host() mmc_add_host() may return error, if we ignore …

Sep 17, 2025
CVE-2025-59476
5.3 MEDIUM

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, …

Sep 17, 2025
CVE-2025-59475
4.3 MEDIUM

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read …

Sep 17, 2025
CVE-2025-59474
5.3 MEDIUM

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking …

Sep 17, 2025
CVE-2025-55904
4.0 MEDIUM

Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference when a multipart/related HTTP POST request with an empty HTTP body is …

Sep 17, 2025
CVE-2025-50709
4.3 MEDIUM

An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter

Sep 17, 2025
CVE-2025-10594
6.3 MEDIUM

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_student.php. …

Sep 17, 2025
CVE-2025-10593
6.3 MEDIUM

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the …

Sep 17, 2025
CVE-2025-8463
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing.This issue affects SecHard: before 3.6.2-20250805.

Sep 17, 2025
CVE-2025-8077
9.8 CRITICAL

A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` …

Sep 17, 2025
CVE-2025-54467
5.3 MEDIUM

When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security …

Sep 17, 2025
CVE-2025-53884
5.3 MEDIUM

NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of …

Sep 17, 2025
CVE-2025-10592
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the …

Sep 17, 2025
CVE-2025-0879
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside Software Shopside App allows Cross-Site Scripting (XSS). This issue requires …

Sep 17, 2025
CVE-2025-8999
5.3 MEDIUM

The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' function in all versions …

Sep 17, 2025
CVE-2025-8411
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology E-Commerce Web Design Product allows XSS Through HTTP Headers.This …

Sep 17, 2025
CVE-2025-10439
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics Yordam Library Automation System allows SQL Injection.This issue affects …

Sep 17, 2025
CVE-2025-10157
7.8 HIGH

A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This …

Sep 17, 2025
CVE-2025-0546
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR …

Sep 17, 2025
CVE-2025-10591
3.5 LOW

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_funcao_cad.php of the component Editar Função …

Sep 17, 2025
CVE-2025-10590
4.3 MEDIUM

A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuario_det.php. The manipulation …

Sep 17, 2025
CVE-2025-10156
9.8 CRITICAL

An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This …

Sep 17, 2025
CVE-2025-10155
7.8 HIGH

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle …

Sep 17, 2025
CVE-2025-0420
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Paraşüt allows Cross-Site Scripting (XSS).This issue affects Paraşüt: from …

Sep 17, 2025
CVE-2025-59458
8.3 HIGH

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation

Sep 17, 2025
CVE-2025-59457
7.7 HIGH

In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows

Sep 17, 2025
CVE-2025-59456
5.5 MEDIUM

In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload

Sep 17, 2025
CVE-2025-59455
4.2 MEDIUM

In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition

Sep 17, 2025
CVE-2025-0419
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. Zirve Nova allows Cross-Site Scripting (XSS).This issue …

Sep 17, 2025
CVE-2025-9242
9.8 CRITICAL KEV

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User …

Sep 17, 2025
CVE-2025-9972
9.8 CRITICAL

Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands …

Sep 17, 2025
CVE-2025-9971
9.8 CRITICAL

Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a …

Sep 17, 2025
CVE-2025-9565
6.4 MEDIUM

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 …

Sep 17, 2025
CVE-2025-9450
7.8 HIGH

A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to …

Sep 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.