CVE Vulnerability Database

Search and browse 397,994 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-29338MEDIUM5.6NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff...
CVE-2025-28344HIGH7.5striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
CVE-2025-28343HIGH7.5striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
CVE-2024-55045HIGH7.3Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry fun...
CVE-2024-51395MEDIUM6.2Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a...
CVE-2024-51394MEDIUM5.5Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a...
CVE-2020-37226HIGH7.1Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipu...
CVE-2020-37225MEDIUM6.4Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated att...
CVE-2020-37224HIGH7.1Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipu...
CVE-2020-37223HIGH8.5IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local a...
CVE-2020-37222HIGH7.2Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inje...
CVE-2020-37221HIGH8.6Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by ...
CVE-2020-37220HIGH8.7Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain a...
CVE-2020-37219HIGH8.7Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbi...
CVE-2020-37218HIGH8.8Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated atta...
CVE-2020-37217MEDIUM5.1Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts...
CVE-2020-37174MEDIUM5.5WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenti...
CVE-2020-37169MEDIUM6.8WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers...
CVE-2020-37168CRITICAL9.8Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force ...
CVE-2026-8463MEDIUM5.3Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco...
CVE-2026-8369MEDIUM6Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all plat...
CVE-2026-4609HIGH7.1The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to...
CVE-2026-4608MEDIUM6.5The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via th...
CVE-2026-4607MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-39806HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote den...