CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38687
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: comedi: fix race between polling and detaching syzbot reports a use-after-free in comedi in the …

Sep 4, 2025
CVE-2025-38686
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: fix a crash in UFFDIO_MOVE when PMD is a migration entry When UFFDIO_MOVE encounters …

Sep 4, 2025
CVE-2025-38685
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imageblit This issue triggers when a userspace program does …

Sep 4, 2025
CVE-2025-38684
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: use old 'nbands' while purging unused classes Shuang reported sch_ets test-case [1] crashing …

Sep 4, 2025
CVE-2025-38683
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix panic during namespace deletion with VF The existing code move the VF NIC …

Sep 4, 2025
CVE-2025-38682
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: core: Fix double-free of fwnode in i2c_unregister_device() Before commit df6d7277e552 ("i2c: core: Do not …

Sep 4, 2025
CVE-2025-38681
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() Memory hot remove unmaps and tears down …

Sep 4, 2025
CVE-2025-38680
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() The buffer length check before calling uvc_parse_format() …

Sep 4, 2025
CVE-2025-38679
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload bound check Currently, The event_seq_changed() handler …

Sep 4, 2025
CVE-2025-23302
4.2 MEDIUM

NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsafe debug access level. A …

Sep 4, 2025
CVE-2025-23301
4.2 MEDIUM

NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsafe debug access level. A …

Sep 4, 2025
CVE-2025-23262
6.3 MEDIUM

NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful …

Sep 4, 2025
CVE-2025-23261
5.5 MEDIUM

NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disclosing information to unauthorized …

Sep 4, 2025
CVE-2025-23259
6.5 MEDIUM

NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause …

Sep 4, 2025
CVE-2025-23258
7.3 HIGH

NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker with low privileges to escalate privileges. A successful …

Sep 4, 2025
CVE-2025-23257
7.3 HIGH

NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privileges to escalate privileges. A successful exploit of …

Sep 4, 2025
CVE-2025-23256
8.7 HIGH

NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful …

Sep 4, 2025
CVE-2025-8311

dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint. This endpoint uses the sites query parameter, which accepts a …

Sep 4, 2025
CVE-2025-6785

Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote …

Sep 4, 2025
CVE-2025-2694
4.8 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable …

Sep 4, 2025
CVE-2025-2667
2.7 LOW

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose …

Sep 4, 2025
CVE-2025-25048
6.5 MEDIUM

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to …

Sep 4, 2025
CVE-2024-43184
6.1 MEDIUM

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnerable to cross-site scripting. This vulnerability allows an …

Sep 4, 2025
CVE-2025-57263
7.2 HIGH

An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in …

Sep 4, 2025
CVE-2025-7388
8.4 HIGH

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS …

Sep 4, 2025
CVE-2025-7385

Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an …

Sep 4, 2025
CVE-2025-41063
5.4 MEDIUM

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of …

Sep 4, 2025
CVE-2025-41062
5.4 MEDIUM

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of …

Sep 4, 2025
CVE-2025-41061
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41060
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41059
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41058
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41057
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41056
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41055
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41054
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41053
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41052
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41051
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41050
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41049
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41048
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41047
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41046
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41045
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41044
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41043
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41042
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41041
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41040
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.