CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58168

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58167

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58166

Rejected reason: This CVE is a duplicate of another CVE.

Sep 3, 2025
CVE-2025-58165

Rejected reason: This CVE is a duplicate of another CVE, CVE-2025-58163.

Sep 3, 2025
CVE-2025-58164

Rejected reason: This CVE is a duplicate of another CVE, CVE-2025-58163.

Sep 3, 2025
CVE-2025-9848
7.3 HIGH

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such …

Sep 3, 2025
CVE-2025-9847
6.3 MEDIUM

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the …

Sep 3, 2025
CVE-2025-7039
3.7 LOW

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform …

Sep 3, 2025
CVE-2025-58163
8.8 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untrusted data vulnerability …

Sep 3, 2025
CVE-2025-9845
3.5 LOW

A vulnerability has been found in code-projects Fruit Shop Management System 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. Such …

Sep 3, 2025
CVE-2025-9843
5.3 MEDIUM

A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This manipulation causes information …

Sep 3, 2025
CVE-2025-57806

Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local …

Sep 3, 2025
CVE-2025-9842
5.3 MEDIUM

A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. The manipulation results in information …

Sep 3, 2025
CVE-2025-9841
6.3 MEDIUM

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of …

Sep 3, 2025
CVE-2025-9260
6.5 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 …

Sep 3, 2025
CVE-2025-54588
7.5 HIGH

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Versions 1.34.0 through 1.34.4 and 1.35.0 contain a …

Sep 3, 2025
CVE-2025-9840
6.3 MEDIUM

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of …

Sep 2, 2025
CVE-2025-9839
7.3 HIGH

A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing …

Sep 2, 2025
CVE-2025-9838
7.3 HIGH

A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument …

Sep 2, 2025
CVE-2025-26416
9.8 CRITICAL

In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of …

Sep 2, 2025
CVE-2025-22442
7.0 HIGH

In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created work profile due to a race condition. …

Sep 2, 2025
CVE-2025-22439
7.3 HIGH

In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission check. This could lead …

Sep 2, 2025
CVE-2025-22438
7.8 HIGH

In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. …

Sep 2, 2025
CVE-2025-22437
7.8 HIGH

In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code. This …

Sep 2, 2025
CVE-2025-22435
9.8 CRITICAL

In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no …

Sep 2, 2025
CVE-2025-22434
7.8 HIGH

In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation …

Sep 2, 2025
CVE-2025-22433
7.8 HIGH

In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work Profile scenarios due to a …

Sep 2, 2025
CVE-2025-22431
5.5 MEDIUM

In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error …

Sep 2, 2025
CVE-2025-22430
5.5 MEDIUM

In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead to local …

Sep 2, 2025
CVE-2025-22429
9.8 CRITICAL

In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local …

Sep 2, 2025
CVE-2025-22428
7.8 HIGH

In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to …

Sep 2, 2025
CVE-2025-22427
7.3 HIGH

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic error in the code. …

Sep 2, 2025
CVE-2025-22423
7.5 HIGH

In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote …

Sep 2, 2025
CVE-2025-22422
7.8 HIGH

In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be …

Sep 2, 2025
CVE-2025-22421
5.5 MEDIUM

In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a logic error in the code. This could lead …

Sep 2, 2025
CVE-2025-22419
7.3 HIGH

In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack. This could …

Sep 2, 2025
CVE-2025-22418
7.8 HIGH

In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution …

Sep 2, 2025
CVE-2025-22417
7.3 HIGH

In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. This could lead to local escalation …

Sep 2, 2025
CVE-2025-22416
7.8 HIGH

In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This could lead to local …

Sep 2, 2025
CVE-2024-49730
7.8 HIGH

In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional …

Sep 2, 2025
CVE-2024-49728
5.5 MEDIUM

In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lead to local information disclosure with …

Sep 2, 2025
CVE-2024-49722
5.5 MEDIUM

In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to local information disclosure with …

Sep 2, 2025
CVE-2024-49720
7.8 HIGH

In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic error in …

Sep 2, 2025
CVE-2024-40653
7.3 HIGH

In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error in the …

Sep 2, 2025
CVE-2025-9837
7.3 HIGH

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the …

Sep 2, 2025
CVE-2025-9836
4.3 MEDIUM

A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument …

Sep 2, 2025
CVE-2025-9835
4.3 MEDIUM

A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument …

Sep 2, 2025
CVE-2025-9834
3.5 LOW

A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of …

Sep 2, 2025
CVE-2025-9833
7.3 HIGH

A vulnerability was detected in SourceCodester Online Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/login.php. Performing manipulation …

Sep 2, 2025
CVE-2025-9832
7.3 HIGH

A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file /routers/register-router.php. Such manipulation of …

Sep 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.