CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8512
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in TVB Big Big Shop App 2.9.0 on Android. This issue affects some unknown processing …

Aug 3, 2025
CVE-2025-8511
3.5 LOW

A vulnerability classified as problematic was found in Portabilis i-Diario 1.5.0. This vulnerability affects unknown code of the file /diario-de-observacoes/ of the component Observações. The …

Aug 3, 2025
CVE-2025-8510
3.5 LOW

A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. This affects the function Gerar of the file ieducar/intranet/educar_matricula_lst.php. The manipulation of the …

Aug 3, 2025
CVE-2025-8509
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Aug 3, 2025
CVE-2025-8508
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Aug 3, 2025
CVE-2024-51775
5.3 MEDIUM

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal …

Aug 3, 2025
CVE-2025-8507
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9. It has been classified as problematic. Affected is an unknown function of the file /intranet/educar_funcao_lst.php. The manipulation …

Aug 3, 2025
CVE-2024-52279
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects …

Aug 3, 2025
CVE-2024-41177
6.1 MEDIUM

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which …

Aug 3, 2025
CVE-2025-8506
3.5 LOW

A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This issue affects some unknown processing of the file /user/editUI. The …

Aug 3, 2025
CVE-2025-8505
4.3 MEDIUM

A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site …

Aug 3, 2025
CVE-2025-8504
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation …

Aug 3, 2025
CVE-2025-8503
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Online Medicine Guide 1.0. Affected by this issue is some unknown functionality of …

Aug 3, 2025
CVE-2025-8502
7.3 HIGH

A vulnerability classified as critical was found in code-projects Online Medicine Guide 1.0. Affected by this vulnerability is an unknown functionality of the file /changepass.php. …

Aug 3, 2025
CVE-2025-8501
3.5 LOW

A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected is an unknown function of the file /insert-and-view/action.php. The …

Aug 3, 2025
CVE-2025-8500
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Aug 3, 2025
CVE-2025-8499
7.3 HIGH

A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cusfindambulence2.php. …

Aug 3, 2025
CVE-2025-8498
7.3 HIGH

A security vulnerability has been detected in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /cart/index.php. Such manipulation of the …

Aug 3, 2025
CVE-2025-8497
7.3 HIGH

A weakness has been identified in code-projects Online Medicine Guide 1.0. This affects an unknown part of the file /cusfindphar2.php. This manipulation of the argument …

Aug 3, 2025
CVE-2025-8496
7.3 HIGH

A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 3, 2025
CVE-2025-52133
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.

Aug 3, 2025
CVE-2025-52132
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.

Aug 3, 2025
CVE-2025-52131
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

Aug 3, 2025
CVE-2025-8495
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. …

Aug 3, 2025
CVE-2025-54351
8.9 HIGH

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

Aug 3, 2025
CVE-2025-54350
3.7 LOW

In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

Aug 3, 2025
CVE-2025-54349
6.5 MEDIUM

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

Aug 3, 2025
CVE-2025-8494
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the …

Aug 3, 2025
CVE-2025-54955
8.1 HIGH

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. …

Aug 3, 2025
CVE-2025-8493
7.3 HIGH

A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_query.php. The manipulation …

Aug 2, 2025
CVE-2025-23290
2.5 LOW

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics which may be influenced by work …

Aug 2, 2025
CVE-2025-23285
5.5 MEDIUM

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful exploit of this …

Aug 2, 2025
CVE-2025-23284
7.8 HIGH

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack buffer overflow. A successful exploit of …

Aug 2, 2025
CVE-2023-32255
5.3 MEDIUM

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an …

Aug 2, 2025
CVE-2023-32253
5.9 MEDIUM

A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a …

Aug 2, 2025
CVE-2025-23288
3.3 LOW

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may cause an exposure of sensitive system information with local unprivileged system access. …

Aug 2, 2025
CVE-2025-23287
3.3 LOW

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level information. A successful exploit of this vulnerability may lead …

Aug 2, 2025
CVE-2025-23286
4.4 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit of this vulnerability might …

Aug 2, 2025
CVE-2025-23283
7.8 HIGH

NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause stack buffer overflow. A successful …

Aug 2, 2025
CVE-2025-23281
7.0 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race condition might be able …

Aug 2, 2025
CVE-2025-23279
7.0 HIGH

NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of …

Aug 2, 2025
CVE-2025-23278
7.1 HIGH

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index validation by issuing a call with crafted …

Aug 2, 2025
CVE-2025-23277
7.3 HIGH

NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under …

Aug 2, 2025
CVE-2025-23276
7.8 HIGH

NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful exploit of this vulnerability may lead to …

Aug 2, 2025
CVE-2025-8471
7.3 HIGH

A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file …

Aug 2, 2025
CVE-2025-8470
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/deleteroom.php. The manipulation …

Aug 2, 2025
CVE-2025-8469
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The …

Aug 2, 2025
CVE-2025-8468
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Aug 2, 2025
CVE-2025-7710
9.8 CRITICAL

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to …

Aug 2, 2025
CVE-2025-7500
6.4 MEDIUM

The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 …

Aug 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.