CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9098
5.3 MEDIUM

A vulnerability was determined in Elseplus File Recovery App 4.4.21 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml. The …

Aug 18, 2025
CVE-2025-31715
9.8 CRITICAL

In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional …

Aug 18, 2025
CVE-2025-31714
6.8 MEDIUM

In Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

Aug 18, 2025
CVE-2025-31713
8.4 HIGH

In engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no …

Aug 18, 2025
CVE-2025-9097
5.3 MEDIUM

A vulnerability was found in Euro Information CIC banque et compte en ligne App 12.56.0 on Android. Affected by this vulnerability is an unknown functionality …

Aug 18, 2025
CVE-2025-9096
3.5 LOW

A vulnerability has been found in ExpressGateway express-gateway up to 1.16.10. Affected is an unknown function in the library lib/rest/routes/apps.js of the component REST Endpoint. …

Aug 18, 2025
CVE-2025-9095
3.5 LOW

A flaw has been found in ExpressGateway express-gateway up to 1.16.10. This issue affects some unknown processing in the library lib/rest/routes/users.js of the component REST …

Aug 17, 2025
CVE-2025-9094
4.3 MEDIUM

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of …

Aug 17, 2025
CVE-2025-7342
7.5 HIGH

A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix …

Aug 17, 2025
CVE-2025-9093
5.3 MEDIUM

A security vulnerability has been detected in BuzzFeed App 2024.9 on Android. This affects an unknown part of the file AndroidManifest.xml of the component com.buzzfeed.android. …

Aug 17, 2025
CVE-2025-9091
2.5 LOW

A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shadow. The manipulation leads …

Aug 17, 2025
CVE-2025-9090
6.3 MEDIUM

A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads …

Aug 17, 2025
CVE-2025-9089
8.8 HIGH

A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform/SetIpMacBind. The manipulation of the argument list leads …

Aug 17, 2025
CVE-2025-9088
8.8 HIGH

A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the file /goform/formSetVirtualSer. The manipulation of the argument list leads …

Aug 16, 2025
CVE-2025-9087
8.8 HIGH

A vulnerability has been found in Tenda AC20 16.03.08.12. This affects the function set_qosMib_list of the file /goform/SetNetControlList of the component SetNetControlList Endpoint. The manipulation …

Aug 16, 2025
CVE-2023-4515
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for …

Aug 16, 2025
CVE-2023-4130
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea() There are multiple smb2_ea_info …

Aug 16, 2025
CVE-2023-3867
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds read in smb2_sess_setup ksmbd does not consider the case of …

Aug 16, 2025
CVE-2023-3866
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in the compound request This patch validate session …

Aug 16, 2025
CVE-2023-3865
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If ->NextCommand is bigger than …

Aug 16, 2025
CVE-2023-32249
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is …

Aug 16, 2025
CVE-2023-32246
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: call rcu_barrier() in ksmbd_server_exit() racy issue is triggered the bug by racing between closing …

Aug 16, 2025
CVE-2025-8878
6.5 MEDIUM

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary …

Aug 16, 2025
CVE-2025-8143
6.4 MEDIUM

The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pcsml_smartlists_h’ parameter in all versions up to, and including, 8.6.7 due to …

Aug 16, 2025
CVE-2025-8142
8.8 HIGH

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes …

Aug 16, 2025
CVE-2025-8105
7.3 HIGH

The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the …

Aug 16, 2025
CVE-2025-38552
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mptcp: plug races between subflow fail and subflow creation We have races similar to the …

Aug 16, 2025
CVE-2025-38551
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix recursived rtnl_lock() during probe() The deadlock appears in a stack trace like: virtnet_probe() …

Aug 16, 2025
CVE-2025-38550
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as …

Aug 16, 2025
CVE-2025-38549
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths When processing mount options, efivarfs …

Aug 16, 2025
CVE-2025-38548
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Validate the size of the received input buffer Add buffer_recv_size to store the …

Aug 16, 2025
CVE-2025-38547
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps The AXP717 ADC channel …

Aug 16, 2025
CVE-2025-38546
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix memory leak of struct clip_vcc. ioctl(ATMARP_MKIP) allocates struct clip_vcc and set it …

Aug 16, 2025
CVE-2025-38545
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix skb size by accounting for skb_shared_info While transitioning from netdev_alloc_ip_align() …

Aug 16, 2025
CVE-2025-38544
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix bug due to prealloc collision When userspace is using AF_RXRPC to provide a …

Aug 16, 2025
CVE-2025-38543
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/tegra: nvdec: Fix dma_alloc_coherent error check Check for NULL return value with dma_alloc_coherent, in line …

Aug 16, 2025
CVE-2025-38542
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix device refcount leak in atrtr_create() When updating an existing route entry in …

Aug 16, 2025
CVE-2025-38541
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init() devm_kasprintf() returns NULL on error. Currently, mt7925_thermal_init() does …

Aug 16, 2025
CVE-2025-38540
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras The Chicony Electronics HP …

Aug 16, 2025
CVE-2025-38539
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Add down_write(trace_event_sem) when adding trace event When a module is loaded, it adds trace …

Aug 16, 2025
CVE-2025-38538
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dmaengine: nbpfaxi: Fix memory corruption in probe() The nbpf->chan[] array is allocated earlier in the …

Aug 16, 2025
CVE-2025-38537
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: Don't register LEDs for genphy If a PHY has no driver, the genphy …

Aug 16, 2025
CVE-2025-38536
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix potential use-after-free in airoha_npu_get() np->name was being used after calling of_node_put(np), which …

Aug 16, 2025
CVE-2025-38535
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode When transitioning from USB_ROLE_DEVICE …

Aug 16, 2025
CVE-2025-38534
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix copy-to-cache so that it performs collection with ceph+fscache The netfs copy-to-cache that is …

Aug 16, 2025
CVE-2025-38533
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix the using of Rx buffer DMA The wx_rx_buffer structure contained two DMA …

Aug 16, 2025
CVE-2025-38532
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: libwx: properly reset Rx ring descriptor When device reset is triggered by feature changes …

Aug 16, 2025
CVE-2025-38531
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: common: st_sensors: Fix use of uninitialize device structs Throughout the various probe functions &indio_dev->dev …

Aug 16, 2025
CVE-2025-38530
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: pcl812: Fix bit shift out of bounds When checking for a supported IRQ number, …

Aug 16, 2025
CVE-2025-38529
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: aio_iiro_16: Fix bit shift out of bounds When checking for a supported IRQ number, …

Aug 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.