CVE Vulnerability Database

Search and browse 397,953 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6646MEDIUM6.4The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v...
CVE-2026-4094HIGH8.1The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss du...
CVE-2026-41702HIGH7VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a...
CVE-2026-43490HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inher...
CVE-2026-28761HIGH8.5Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 a...
CVE-2026-24662MEDIUM5.4Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and ear...
CVE-2026-0481CRITICAL9.2Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per...
CVE-2025-54518HIGH7Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to...
CVE-2025-52532LOW2A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa...
CVE-2024-36334HIGH7Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta...
CVE-2024-36333HIGH7.8A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti...
CVE-2024-36323HIGH8.8Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perf...
CVE-2024-21950LOW1.8An out of bounds read in the remote management firmware could allow a privileged attacker read a limited section of memo...
CVE-2026-7373HIGH8.5Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr...
CVE-2026-2652HIGH8.6A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when...
CVE-2026-0428LOW1.8Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_...
CVE-2026-0427MEDIUM4.6Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virt...
CVE-2025-66664MEDIUM4.6Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malf...
CVE-2025-66660LOW1.8Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_...
CVE-2025-54517HIGH8.5Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem...
CVE-2025-54511MEDIUM5.3Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp...
CVE-2025-48516MEDIUM6.9Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc...
CVE-2025-48513MEDIUM6.9Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini...
CVE-2025-29944MEDIUM6.8A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, p...
CVE-2025-29938HIGH7.1An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi...