CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13064
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft MyRezzta allows Cross-Site Scripting (XSS).This issue affects MyRezzta: from s2.02.02 …

Sep 3, 2025
CVE-2024-13063
6.8 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing.This issue affects MyRezzta: from s2.02.02 before v2.05.01.

Sep 3, 2025
CVE-2014-125127
7.5 HIGH

The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager loading of request bodies in …

Sep 3, 2025
CVE-2025-9817
7.8 HIGH

SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service

Sep 3, 2025
CVE-2025-9378
6.4 MEDIUM

The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attributes in the Lottie …

Sep 3, 2025
CVE-2025-8663
6.5 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.0.0 …

Sep 3, 2025
CVE-2025-58210
5.3 MEDIUM

Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Makeaholic: from n/a through <= 1.8.5.

Sep 3, 2025
CVE-2024-32444
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.3.6.

Sep 3, 2025
CVE-2025-58272
3.7 LOW

Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by an attacker, …

Sep 3, 2025
CVE-2025-21041
6.2 MEDIUM

Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.

Sep 3, 2025
CVE-2025-21040
5.1 MEDIUM

Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Sep 3, 2025
CVE-2025-21039
5.1 MEDIUM

Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Sep 3, 2025
CVE-2025-21038
5.1 MEDIUM

Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Sep 3, 2025
CVE-2025-21037
4.1 MEDIUM

Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for …

Sep 3, 2025
CVE-2025-21036
5.0 MEDIUM

Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported note files. User interaction is required for triggering …

Sep 3, 2025
CVE-2025-21035
4.6 MEDIUM

Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across …

Sep 3, 2025
CVE-2025-21034
4.0 MEDIUM

Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

Sep 3, 2025
CVE-2025-21033
4.0 MEDIUM

Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

Sep 3, 2025
CVE-2025-21032
5.9 MEDIUM

Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.

Sep 3, 2025
CVE-2025-21031
6.8 MEDIUM

Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.

Sep 3, 2025
CVE-2025-21030
4.3 MEDIUM

Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in …

Sep 3, 2025
CVE-2025-21029
4.0 MEDIUM

Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the …

Sep 3, 2025
CVE-2025-21028
5.5 MEDIUM

Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.

Sep 3, 2025
CVE-2025-21027
5.1 MEDIUM

Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.

Sep 3, 2025
CVE-2025-21026
4.0 MEDIUM

Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.

Sep 3, 2025
CVE-2025-21025
5.1 MEDIUM

Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.

Sep 3, 2025
CVE-2023-3666
3.3 LOW

The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Sep 3, 2025
CVE-2023-21483
6.4 MEDIUM

Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.

Sep 3, 2025
CVE-2023-21482
6.1 MEDIUM

Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to …

Sep 3, 2025
CVE-2023-21481
5.4 MEDIUM

Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.

Sep 3, 2025
CVE-2023-21480
8.5 HIGH

Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.

Sep 3, 2025
CVE-2023-21479
5.3 MEDIUM

Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a …

Sep 3, 2025
CVE-2023-21478
6.0 MEDIUM

Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

Sep 3, 2025
CVE-2023-21477
7.9 HIGH

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

Sep 3, 2025
CVE-2023-21476
8.0 HIGH

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

Sep 3, 2025
CVE-2023-21475
8.0 HIGH

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

Sep 3, 2025
CVE-2023-21474
6.3 MEDIUM

Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.

Sep 3, 2025
CVE-2023-21473
6.8 MEDIUM

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

Sep 3, 2025
CVE-2023-21472
6.8 MEDIUM

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

Sep 3, 2025
CVE-2023-21471
4.0 MEDIUM

Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

Sep 3, 2025
CVE-2023-21470
4.0 MEDIUM

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.

Sep 3, 2025
CVE-2023-21469
4.0 MEDIUM

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.

Sep 3, 2025
CVE-2023-21468
5.9 MEDIUM

Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.

Sep 3, 2025
CVE-2023-21467
4.6 MEDIUM

Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.

Sep 3, 2025
CVE-2023-21466
5.3 MEDIUM

PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.

Sep 3, 2025
CVE-2025-9785

PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an …

Sep 3, 2025
CVE-2025-58351
6.8 MEDIUM

Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature which facilitates local file system storage capabilities …

Sep 3, 2025
CVE-2025-58176
8.8 HIGH

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click Remote Code …

Sep 3, 2025
CVE-2025-58170

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58169

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.