CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46198
8.8 HIGH

Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element

Jul 25, 2025
CVE-2025-30135
9.4 CRITICAL

An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its …

Jul 25, 2025
CVE-2025-8166
7.3 HIGH

A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/index.php …

Jul 25, 2025
CVE-2025-8165
6.3 MEDIUM

A vulnerability was found in code-projects Food Review System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/approve_reservation.php. The …

Jul 25, 2025
CVE-2025-52455
5.3 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before …

Jul 25, 2025
CVE-2025-52454
8.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: …

Jul 25, 2025
CVE-2025-52453
8.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tableau Server: …

Jul 25, 2025
CVE-2025-52452
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modules) allows …

Jul 25, 2025
CVE-2025-52449
8.5 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive …

Jul 25, 2025
CVE-2025-52448
8.1 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database …

Jul 25, 2025
CVE-2025-52447
8.1 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production …

Jul 25, 2025
CVE-2025-52446
8.0 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database …

Jul 25, 2025
CVE-2025-8164
6.3 MEDIUM

A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affects unknown code of the file send_message.php. The …

Jul 25, 2025
CVE-2025-8163
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/role/list. The …

Jul 25, 2025
CVE-2025-5449
6.5 MEDIUM

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows …

Jul 25, 2025
CVE-2025-46199
9.8 CRITICAL

Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields

Jul 25, 2025
CVE-2025-8162
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in deerwms deer-wms-2 up to 3.3. Affected by this issue is some unknown functionality of …

Jul 25, 2025
CVE-2025-8161
6.3 MEDIUM

A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. Affected by this vulnerability is an unknown functionality of the file /system/role/export. …

Jul 25, 2025
CVE-2025-54596
4.3 MEDIUM

Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the privileges of other user accounts.

Jul 25, 2025
CVE-2025-45960
6.1 MEDIUM

Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied …

Jul 25, 2025
CVE-2025-45893
6.1 MEDIUM

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arises because SVG …

Jul 25, 2025
CVE-2025-45892
6.1 MEDIUM

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor …

Jul 25, 2025
CVE-2025-45406
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jul 25, 2025
CVE-2025-36728
6.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.

Jul 25, 2025
CVE-2025-36727
8.3 HIGH

Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.

Jul 25, 2025
CVE-2025-29631
9.8 CRITICAL

Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods …

Jul 25, 2025
CVE-2025-29630

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jul 25, 2025
CVE-2025-29629
9.1 CRITICAL

Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure …

Jul 25, 2025
CVE-2025-29628
9.4 CRITICAL

A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application …

Jul 25, 2025
CVE-2023-53155
7.2 HIGH

goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.

Jul 25, 2025
CVE-2025-45466
8.8 HIGH

Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.

Jul 25, 2025
CVE-2025-3873

The following APIs for the Silcon Labs SiWx91x prior to vesion 3.4.0 failed to check the size of the output buffer of the caller which …

Jul 25, 2025
CVE-2025-3508
6.5 MEDIUM

Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensitive print job information.

Jul 25, 2025
CVE-2025-38467
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling If there's support for another console device …

Jul 25, 2025
CVE-2025-38466
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf: Revert to requiring CAP_SYS_ADMIN for uprobes Jann reports that uprobes can be used destructively …

Jul 25, 2025
CVE-2025-38465
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netlink: Fix wraparounds of sk->sk_rmem_alloc. Netlink has this pattern in some places if (atomic_read(&sk->sk_rmem_alloc) > …

Jul 25, 2025
CVE-2025-38464
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_conn_close(). syzbot reported a null-ptr-deref in tipc_conn_close() during netns dismantle. [0] …

Jul 25, 2025
CVE-2025-38463
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: Correct signedness in skb remaining space calculation Syzkaller reported a bug [1] where sk->sk_forward_alloc …

Jul 25, 2025
CVE-2025-38462
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} TOCTOU vsock_find_cid() and vsock_dev_do_ioctl() may race with module unload. transport_{g2h,h2g} may become …

Jul 25, 2025
CVE-2025-38461
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment may race with module unload. Protect new_transport from becoming …

Jul 25, 2025
CVE-2025-38460
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix potential null-ptr-deref in to_atmarpd(). atmarpd is protected by RTNL since commit f3a0592b37b8 …

Jul 25, 2025
CVE-2025-38459
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix infinite recursive call of clip_push(). syzbot reported the splat below. [0] This …

Jul 25, 2025
CVE-2025-38458
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix NULL pointer dereference in vcc_sendmsg() atmarpd_dev_ops does not implement the send method, …

Jul 25, 2025
CVE-2025-38457
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: Abort __tc_modify_qdisc if parent class does not exist Lion's patch [1] revealed an ancient …

Jul 25, 2025
CVE-2025-38456
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipmi:msghandler: Fix potential memory corruption in ipmi_create_user() The "intf" list iterator is an invalid pointer …

Jul 25, 2025
CVE-2025-38455
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation is in-flight Reject migration of …

Jul 25, 2025
CVE-2025-38454
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: ad1816a: Fix potential NULL pointer deref in snd_card_ad1816a_pnp() Use pr_warn() instead of dev_warn() when …

Jul 25, 2025
CVE-2025-38453
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/msg_ring: ensure io_kiocb freeing is deferred for RCU syzbot reports that defer/local task_work adding via …

Jul 25, 2025
CVE-2025-38452
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe() Add check for the return …

Jul 25, 2025
CVE-2025-38451
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix GPF in bitmap_get_stats() The commit message of commit 6ec1f0239485 ("md/md-bitmap: fix stats collection …

Jul 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.