CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38489
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") …

Jul 28, 2025
CVE-2025-38488
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in crypt_message when using async crypto The CVE-2024-50047 fix removed asynchronous …

Jul 28, 2025
CVE-2025-38487
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled Mitigate e.g. the following: # echo …

Jul 28, 2025
CVE-2025-38486
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soundwire: Revert "soundwire: qcom: Add set_channel_map api support" This reverts commit 7796c97df6b1b2206681a07f3c80f6023a6593d5. This patch broke …

Jul 28, 2025
CVE-2025-38485
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush fxls8962af_fifo_flush() uses indio_dev->active_scan_mask (with iio_for_each_active_channel()) without …

Jul 28, 2025
CVE-2025-38484
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: backend: fix out-of-bound write The buffer is set to 80 character. If a caller …

Jul 28, 2025
CVE-2025-38483
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: das16m1: Fix bit shift out of bounds When checking for a supported IRQ number, …

Jul 28, 2025
CVE-2025-38482
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: das6402: Fix bit shift out of bounds When checking for a supported IRQ number, …

Jul 28, 2025
CVE-2025-38481
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large The handling of the `COMEDI_INSNLIST` ioctl …

Jul 28, 2025
CVE-2025-38480
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: comedi: Fix use of uninitialized data in insn_rw_emulate_bits() For Comedi `INSN_READ` and `INSN_WRITE` instructions on …

Jul 28, 2025
CVE-2025-38478
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of data for instructions that write to subdevice Some Comedi subdevice instruction …

Jul 28, 2025
CVE-2025-38477
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can occur when 'agg' is …

Jul 28, 2025
CVE-2025-38476
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: rpl: Fix use-after-free in rpl_do_srh_inline(). Running lwt_dst_cache_ref_loop.sh in selftest with KASAN triggers the splat below …

Jul 28, 2025
CVE-2025-38475
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smc: Fix various oops due to inet_sock type confusion. syzbot reported weird splats [0][1] in …

Jul 28, 2025
CVE-2025-38474
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: net: sierra: check for no status endpoint The driver checks for having three endpoints …

Jul 28, 2025
CVE-2025-38473
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() syzbot reported null-ptr-deref in l2cap_sock_resume_cb(). [0] l2cap_sock_resume_cb() has a similar …

Jul 28, 2025
CVE-2025-38472
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry A crash in conntrack was …

Jul 28, 2025
CVE-2025-38471
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tls: always refresh the queue when reading sock After recent changes in net-next TCP compacts …

Jul 28, 2025
CVE-2025-38470
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime Assuming the "rx-vlan-filter" …

Jul 28, 2025
CVE-2025-38469
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a …

Jul 28, 2025
CVE-2025-38468
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can …

Jul 28, 2025
CVE-2025-8273
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s8.php. The manipulation …

Jul 28, 2025
CVE-2025-8272
7.3 HIGH

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 28, 2025
CVE-2025-6918
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX …

Jul 28, 2025
CVE-2025-40730

HTML injection in Vox Media's Chorus CMS. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious …

Jul 28, 2025
CVE-2025-8271
7.3 HIGH

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_s3.php. …

Jul 28, 2025
CVE-2025-8270
7.3 HIGH

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an unknown part of the file /admin/delete_s2.php. …

Jul 28, 2025
CVE-2025-8269
7.3 HIGH

A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jul 28, 2025
CVE-2025-8266
6.3 MEDIUM

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the …

Jul 28, 2025
CVE-2025-8265
4.7 MEDIUM

A vulnerability classified as critical has been found in 299Ko CMS 2.0.0. This affects an unknown part of the file /admin/filemanager/view of the component File …

Jul 28, 2025
CVE-2025-27802
4.8 MEDIUM

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious …

Jul 28, 2025
CVE-2025-27801
4.8 MEDIUM

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious …

Jul 28, 2025
CVE-2025-27800
4.8 MEDIUM

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious …

Jul 28, 2025
CVE-2025-8262
4.3 MEDIUM

A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. …

Jul 28, 2025
CVE-2025-8261
7.3 HIGH

A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component User Creation Handler. Executing …

Jul 28, 2025
CVE-2025-8260
3.1 LOW

A security flaw has been discovered in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. This affects an unknown part of the file /grid/vgrid_server.php of the component Web …

Jul 28, 2025
CVE-2025-8259
7.3 HIGH

A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_DataObjectProc of the file /grid/vgrid_server.php of the component …

Jul 28, 2025
CVE-2025-8267
8.2 HIGH

Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address ranges. Specifically, the …

Jul 28, 2025
CVE-2025-8258
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Cool Mo Maigcal Number App up to 1.0.3 on Android. Affected by this issue …

Jul 28, 2025
CVE-2025-8257
5.3 MEDIUM

A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality …

Jul 28, 2025
CVE-2025-8256
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin/product.php. The manipulation …

Jul 28, 2025
CVE-2025-8255
7.3 HIGH

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 28, 2025
CVE-2025-8254
6.3 MEDIUM

A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view_parcel.php. …

Jul 28, 2025
CVE-2025-8253
7.3 HIGH

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an unknown part of the file /admin/delete_s6.php. …

Jul 28, 2025
CVE-2025-8252
7.3 HIGH

A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jul 28, 2025
CVE-2023-53161
2.9 LOW

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

Jul 28, 2025
CVE-2023-53160
2.9 LOW

The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.

Jul 28, 2025
CVE-2023-53159
4.5 MEDIUM

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

Jul 28, 2025
CVE-2025-8251
7.3 HIGH

A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 28, 2025
CVE-2022-50237
5.9 MEDIUM

The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for …

Jul 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.