Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2025-68431 libheif: libheif has Potential Heap Buffer Over-Read HIGH 7.3 0.34% cvelistv5 2026-06-28
cve-2025-68161 SUSE CVE CVE-2025-68161 MEDIUM 5.4 0.77% cvelistv5 2026-08-28
cve-2025-67735 SUSE CVE CVE-2025-67735 MEDIUM 6.5 0.32% cvelistv5 2026-08-28
cve-2025-67721 Aircompressor's Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer HIGH 7.5 0.53% cvelistv5 2026-06-17
cve-2025-66566 SUSE CVE CVE-2025-66566 UNKNOWN N/A 0.60% cvelistv5 2026-08-26
cve-2025-66418 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion HIGH 7.5 0.68% cvelistv5 2026-09-03
cve-2025-66021 com.googlecode.owasp-java-html-sanitizer/owasp-java-html-sanitizer: OWASP Java HTML Sanitizer vulnerable to XSS HIGH 7.1 0.25% cvelistv5 2026-06-28
cve-2025-6491 php: NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix MEDIUM 5.9 0.97% cvelistv5 2026-06-30
cve-2025-64713 WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode MEDIUM 5.1 0.33% cvelistv5 2026-06-17
cve-2025-59465 nodejs: Nodejs denial of service HIGH 7.5 4.02% cvelistv5 2026-06-30
cve-2025-59250 JDBC Driver for SQL Server Spoofing Vulnerability HIGH 8.1 0.73% cvelistv5 2026-06-17
cve-2025-58050 pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS MEDIUM 6.5 0.80% cvelistv5 2026-08-31
cve-2025-54920 org.apache.spark/spark-core: Apache Spark: Spark History Server Code Execution Vulnerability MEDIUM 6.7 5.34% cvelistv5 2026-06-28
cve-2025-5318 libssh: out-of-bounds read in sftp_handle() MEDIUM 5.4 1.84% cvelistv5 2026-08-31
cve-2025-5222 SUSE CVE CVE-2025-5222 HIGH 7.0 0.43% cvelistv5 2026-08-29
cve-2025-5115 jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames HIGH 7.5 3.46% cvelistv5 2026-09-04
cve-2025-48976 SUSE CVE CVE-2025-48976 HIGH 7.5 32.96% cvelistv5 2026-09-15
cve-2025-48924 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang LOW 3.7 2.27% cvelistv5 2026-08-09
cve-2025-41249 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability HIGH 7.5 0.46% cvelistv5 2026-06-29
cve-2025-41248 org.springframework.security/spring-security-core: Spring Security authorization bypass HIGH 7.5 0.43% cvelistv5 2026-07-30
cve-2025-33042 org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code MEDIUM 5.6 0.61% cvelistv5 2026-06-28
cve-2025-32990 gnutls: Vulnerability in GnuTLS certtool template parsing MEDIUM 6.5 0.79% cvelistv5 2026-09-01
cve-2025-31651 SUSE CVE CVE-2025-31651 HIGH 7.5 4.19% cvelistv5 2026-08-30
cve-2025-27821 HDFS native client: Out of bounds write in URI parser of native HDFS client HIGH 7.3 0.96% cvelistv5 2026-06-17
cve-2025-27553 apache-commons-vfs: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT MEDIUM 5.3 1.40% cvelistv5 2026-06-28
cve-2025-26791 dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling MEDIUM 4.5 0.60% cvelistv5 2026-09-04
cve-2025-21502 openjdk: Enhance array handling (Oracle CPU 2025-01) MEDIUM 4.8 1.01% cvelistv5 2026-08-05
cve-2025-14821 libssh: libssh: Insecure default configuration leads to local man-in-the-middle attacks on Windows HIGH 7.8 0.13% cvelistv5 2026-08-31
cve-2025-14017 curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers MEDIUM 4.8 0.12% cvelistv5 2026-09-01
cve-2025-13837 cpython: Out-of-memory when loading Plist MEDIUM 5.9 0.22% cvelistv5 2026-08-25