CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6067
6.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Sep 6, 2025
CVE-2025-58439
8.1 HIGH

ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left …

Sep 6, 2025
CVE-2025-58375

Rejected reason: This CVE is a duplicate of another CVE.

Sep 6, 2025
CVE-2021-26383
7.9 HIGH

Insufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a command with malformed arguments leading …

Sep 6, 2025
CVE-2025-58373
5.5 MEDIUM

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be …

Sep 5, 2025
CVE-2025-58372
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace …

Sep 5, 2025
CVE-2025-58371
9.8 CRITICAL

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request …

Sep 5, 2025
CVE-2025-58370
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where …

Sep 5, 2025
CVE-2025-58369
5.3 MEDIUM

fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, and 3.13.0-M1 through 3.13.0-M6 are vulnerable to …

Sep 5, 2025
CVE-2025-58367

DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnerable to class pollution via the …

Sep 5, 2025
CVE-2025-58366

Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) …

Sep 5, 2025
CVE-2025-57807
3.8 LOW

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing …

Sep 5, 2025
CVE-2025-10027
3.5 LOW

A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This …

Sep 5, 2025
CVE-2025-53791
4.7 MEDIUM

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Sep 5, 2025
CVE-2025-10061
6.5 MEDIUM

An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect handling …

Sep 5, 2025
CVE-2025-10060
6.5 MEDIUM

MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. …

Sep 5, 2025
CVE-2025-10059
6.5 MEDIUM

An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument …

Sep 5, 2025
CVE-2025-9566
8.1 HIGH

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete …

Sep 5, 2025
CVE-2025-10044
4.3 MEDIUM

A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered …

Sep 5, 2025
CVE-2025-10043

Rejected reason: Considered by the maintainers a bug scenario experienced rather than a vulnerability.

Sep 5, 2025
CVE-2025-10026
3.5 LOW

A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The …

Sep 5, 2025
CVE-2025-10025
7.3 HIGH

A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument …

Sep 5, 2025
CVE-2025-9057
6.4 MEDIUM

The Biagiotti Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.1.3 due to insufficient input …

Sep 5, 2025
CVE-2025-9709

On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform …

Sep 5, 2025
CVE-2025-39726
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management in ism_cmd() The s390x ISM device data sheet clearly states that …

Sep 5, 2025
CVE-2025-39725
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list In shrink_folio_list(), the hwpoisoned folio may be …

Sep 5, 2025
CVE-2025-39724
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: fix panic due to PSLVERR When the PSLVERR_RESP_EN parameter is set to 1, …

Sep 5, 2025
CVE-2025-39723
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix unbuffered write error handling If all the subrequests in an unbuffered write stream …

Sep 5, 2025
CVE-2025-39722
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - Prevent crash on suspend with iMX8QM / iMX8ULP Since the CAAM on …

Sep 5, 2025
CVE-2025-39721
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - flush misc workqueue during device shutdown Repeated loading and unloading of a …

Sep 5, 2025
CVE-2025-39720
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix refcount leak causing resource not released When ksmbd_conn_releasing(opinfo->conn) returns true,the refcount was not …

Sep 5, 2025
CVE-2025-39719
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: imu: bno055: fix OOB access of hw_xlate array Fix a potential out-of-bounds array access …

Sep 5, 2025
CVE-2025-39718
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length in packet header before skb_put() When receiving a vsock packet in the …

Sep 5, 2025
CVE-2025-39717
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: open_tree_attr: do not allow id-mapping changes without OPEN_TREE_CLONE As described in commit 7a54947e727b ('Merge patch …

Sep 5, 2025
CVE-2025-39716
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: Revise __get_user() to probe user read access Because of the way read access support …

Sep 5, 2025
CVE-2025-39715
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: Revise gateway LWS calls to probe user read access We use load and stbys,e …

Sep 5, 2025
CVE-2025-39714
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Lock resolution while streaming When an program is streaming (ffplay) and another program …

Sep 5, 2025
CVE-2025-39713
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() In the interrupt handler rain_interrupt(), the buffer …

Sep 5, 2025
CVE-2025-39712
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: mt9m114: Fix deadlock in get_frame_interval/set_frame_interval Getting / Setting the frame interval using the V4L2 …

Sep 5, 2025
CVE-2025-39711
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls Both the ACE and …

Sep 5, 2025
CVE-2025-39710
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: venus: Add a check for packet size after reading from shared memory Add a …

Sep 5, 2025
CVE-2025-39709
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: venus: protect against spurious interrupts during probe Make sure the interrupt handler is initialized …

Sep 5, 2025
CVE-2025-39708
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix NULL pointer dereference A warning reported by smatch indicated a possible null …

Sep 5, 2025
CVE-2025-39707
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities HUBBUB structure is not initialized on DCE …

Sep 5, 2025
CVE-2025-39706
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Destroy KFD debugfs after destroy KFD wq Since KFD proc content was moved to …

Sep 5, 2025
CVE-2025-39705
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a Null pointer dereference vulnerability [Why] A null pointer dereference vulnerability exists in …

Sep 5, 2025
CVE-2025-39704
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix stack protector issue in send_ipi_data() Function kvm_io_bus_read() is called in function send_ipi_data(), …

Sep 5, 2025
CVE-2025-39703
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net, hsr: reject HSR frame if skb can't hold tag Receiving HSR frame with insufficient …

Sep 5, 2025
CVE-2025-39702
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to …

Sep 5, 2025
CVE-2025-39701
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version check The security-version-number check should be used rather …

Sep 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.