CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36906
7.8 HIGH

In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36905
7.8 HIGH

In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36904
9.8 CRITICAL

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

Sep 4, 2025
CVE-2025-36903
7.8 HIGH

In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution …

Sep 4, 2025
CVE-2025-36902
6.7 MEDIUM

In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36901
8.8 HIGH

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.

Sep 4, 2025
CVE-2025-36900
6.7 MEDIUM

In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalation of privilege with System …

Sep 4, 2025
CVE-2025-36899
8.4 HIGH

There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with …

Sep 4, 2025
CVE-2025-36898
7.8 HIGH

There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no …

Sep 4, 2025
CVE-2025-36897
9.8 CRITICAL

In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Sep 4, 2025
CVE-2025-36896
9.8 CRITICAL

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

Sep 4, 2025
CVE-2025-36895
7.5 HIGH

Information disclosure

Sep 4, 2025
CVE-2025-36894
7.5 HIGH

In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no …

Sep 4, 2025
CVE-2025-36893
5.5 MEDIUM

In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution …

Sep 4, 2025
CVE-2025-36892
7.5 HIGH

Denial of service

Sep 4, 2025
CVE-2025-36891
8.8 HIGH

Elevation of privilege

Sep 4, 2025
CVE-2025-36890
9.8 CRITICAL

Elevation of Privilege

Sep 4, 2025
CVE-2025-36887
7.8 HIGH

In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-2417
8.6 HIGH

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication Bypass.This issue affects e-Mutabakat: from 2.02.06 before v2.02.06.

Sep 4, 2025
CVE-2025-2411
8.6 HIGH

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass.This issue affects TaskPano: from s1.06.04 before v1.06.06.

Sep 4, 2025
CVE-2024-56190
7.8 HIGH

In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Sep 4, 2025
CVE-2024-56189
6.5 MEDIUM

In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Sep 4, 2025
CVE-2024-13073
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft TaskPano allows Cross-Site Scripting (XSS).This issue affects TaskPano: s1.06.04.

Sep 4, 2025
CVE-2024-13071
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-Mutabakat allows Cross-Site Scripting (XSS).This issue affects e-Mutabakat: from 2.02.05 …

Sep 4, 2025
CVE-2025-9928
7.3 HIGH

A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation …

Sep 3, 2025
CVE-2025-9927
7.3 HIGH

A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown function of the file /viewpackage.php. Such manipulation of the …

Sep 3, 2025
CVE-2025-8268
6.5 MEDIUM

The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and …

Sep 3, 2025
CVE-2025-58056
7.5 HIGH

Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, …

Sep 3, 2025
CVE-2025-57833
7.1 HIGH

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, …

Sep 3, 2025
CVE-2025-55748
7.5 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are …

Sep 3, 2025
CVE-2025-55747
9.1 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are …

Sep 3, 2025
CVE-2025-9926
7.3 HIGH

A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the file /viewsubcategory.php. This manipulation of the argument t1 …

Sep 3, 2025
CVE-2025-9925
7.3 HIGH

A vulnerability was found in projectworlds Travel Management System 1.0. This issue affects some unknown processing of the file /detail.php. The manipulation of the argument …

Sep 3, 2025
CVE-2025-9365
7.8 HIGH

Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker …

Sep 3, 2025
CVE-2025-56139
5.3 MEDIUM

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a …

Sep 3, 2025
CVE-2025-55162
6.3 MEDIUM

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1.33.6, …

Sep 3, 2025
CVE-2025-53690
9.0 CRITICAL KEV

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience …

Sep 3, 2025
CVE-2025-9924
7.3 HIGH

A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /enquiry.php. The manipulation of the argument …

Sep 3, 2025
CVE-2025-9923
4.3 MEDIUM

A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. Executing manipulation of the …

Sep 3, 2025
CVE-2025-36193
8.4 HIGH

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the …

Sep 3, 2025
CVE-2025-56803
8.4 HIGH

Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands by setting …

Sep 3, 2025
CVE-2025-56752
9.4 CRITICAL

A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter …

Sep 3, 2025
CVE-2025-52494
7.5 HIGH

Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes during connection initialization. When …

Sep 3, 2025
CVE-2025-45805
7.6 HIGH

In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered …

Sep 3, 2025
CVE-2025-20336
5.3 MEDIUM

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Sep 3, 2025
CVE-2025-20335
5.3 MEDIUM

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Sep 3, 2025
CVE-2025-20330
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker …

Sep 3, 2025
CVE-2025-20328
5.4 MEDIUM

A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site …

Sep 3, 2025
CVE-2025-20326
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could …

Sep 3, 2025
CVE-2025-20291
4.3 MEDIUM

A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco …

Sep 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.