CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-31365
3.9 LOW

An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reserved dRAM area resulting in …

Sep 6, 2025
CVE-2023-31351
5.3 MEDIUM

Improper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integrity.

Sep 6, 2025
CVE-2023-31330
2.5 LOW

An out-of-bounds read in the ASP could allow a privileged attacker with access to a malicious bootloader to potentially read sensitive memory resulting in loss …

Sep 6, 2025
CVE-2023-31326
2.8 LOW

Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution environment (TEE) driver, potentially leading …

Sep 6, 2025
CVE-2023-31325
7.2 HIGH

Improper isolation of shared resources on System-on-a-chip (SOC) could a privileged attacker to tamper with the contents of the PSP reserved DRAM region potentially resulting …

Sep 6, 2025
CVE-2023-31322
8.7 HIGH

Type confusion in the ASP could allow an attacker to pass a malformed argument to the Reliability, Availability, and Serviceability trusted application (RAS TA) potentially …

Sep 6, 2025
CVE-2023-31306
3.3 LOW

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management …

Sep 6, 2025
CVE-2023-20516
3.3 LOW

Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentially resulting in loss of confidentiality …

Sep 6, 2025
CVE-2021-46750
3.0 LOW

Failure to validate the address and size in TEE (Trusted Execution Environment) may allow a malicious x86 attacker to send malformed messages to the graphics …

Sep 6, 2025
CVE-2021-26377
4.1 MEDIUM

Insufficient parameter validation while allocating process space in the Trusted OS (TOS) may allow for a malicious userspace process to trigger an integer overflow, leading …

Sep 6, 2025
CVE-2025-10034
8.8 HIGH

A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_response.cg of the component httpd. Performing manipulation of the …

Sep 6, 2025
CVE-2025-10033
7.3 HIGH

A vulnerability has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin. Such manipulation of the argument …

Sep 6, 2025
CVE-2025-10032
4.3 MEDIUM

A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown function of the file /index.php. The manipulation …

Sep 6, 2025
CVE-2025-10031
7.3 HIGH

A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. The manipulation …

Sep 6, 2025
CVE-2025-10030
7.3 HIGH

A weakness has been identified in Campcodes Grocery Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=save_receiving. Executing manipulation …

Sep 6, 2025
CVE-2025-10029
3.5 LOW

A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation …

Sep 6, 2025
CVE-2025-9961

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500. The exploit can only be conducted via …

Sep 6, 2025
CVE-2025-10046
4.9 MEDIUM

The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, …

Sep 6, 2025
CVE-2025-10028
3.5 LOW

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the …

Sep 6, 2025
CVE-2025-6757
6.4 MEDIUM

The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpwe' shortcode in all versions up to, and …

Sep 6, 2025
CVE-2025-9493
6.4 MEDIUM

The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.14 …

Sep 6, 2025
CVE-2025-9442
6.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChannel’ parameter in all versions up to, and including, 1.1.5 …

Sep 6, 2025
CVE-2025-9126
6.4 MEDIUM

The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.1 …

Sep 6, 2025
CVE-2025-8722
6.4 MEDIUM

The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widgets in all versions up to, and …

Sep 6, 2025
CVE-2025-8564
6.4 MEDIUM

The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.7 …

Sep 6, 2025
CVE-2025-8149
6.4 MEDIUM

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and …

Sep 6, 2025
CVE-2025-7045
6.5 MEDIUM

The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the …

Sep 6, 2025
CVE-2025-7040
8.2 HIGH

The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings' action of …

Sep 6, 2025
CVE-2025-9853
6.4 MEDIUM

The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.2 …

Sep 6, 2025
CVE-2025-9515
7.2 HIGH

The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all …

Sep 6, 2025
CVE-2025-9085
4.9 MEDIUM

The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient …

Sep 6, 2025
CVE-2025-8360
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets in all versions up …

Sep 6, 2025
CVE-2025-8359
9.8 CRITICAL

The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not …

Sep 6, 2025
CVE-2025-58912

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58911

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58910

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58909

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58908

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58907

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58906

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58905

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58904

Rejected reason: Not used

Sep 6, 2025
CVE-2025-58437
8.1 HIGH

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session …

Sep 6, 2025
CVE-2025-58374
7.8 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that …

Sep 6, 2025
CVE-2025-10003
6.5 MEDIUM

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection …

Sep 6, 2025
CVE-2025-9849
6.4 MEDIUM

The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_btn' shortcode in all versions up to, and …

Sep 6, 2025
CVE-2025-7368
5.3 MEDIUM

The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Sep 6, 2025
CVE-2025-7366
7.3 HIGH

The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Sep 6, 2025
CVE-2025-6067
6.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Sep 6, 2025
CVE-2025-58439
8.1 HIGH

ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left …

Sep 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.