CVE Database

368+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22457
9.0 CRITICAL KEV

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows …

Apr 3, 2025
CVE-2025-31125
5.3 MEDIUM KEV

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev …

Mar 31, 2025
CVE-2025-2783
8.3 HIGH KEV

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape …

Mar 26, 2025
CVE-2025-29635
7.2 HIGH KEV

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST …

Mar 25, 2025
CVE-2025-2749
7.2 HIGH KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in …

Mar 24, 2025
CVE-2025-2747
9.8 CRITICAL KEV

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication …

Mar 24, 2025
CVE-2025-2746
9.8 CRITICAL KEV

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication …

Mar 24, 2025
CVE-2025-30154
8.6 HIGH KEV

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps …

Mar 19, 2025
CVE-2025-30066
8.6 HIGH KEV

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 …

Mar 15, 2025
CVE-2025-27915
5.4 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client …

Mar 12, 2025
CVE-2025-21590
4.4 MEDIUM KEV

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity …

Mar 12, 2025
CVE-2025-24201
10.0 CRITICAL KEV

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, …

Mar 11, 2025
CVE-2025-26633
7.0 HIGH KEV

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Mar 11, 2025
CVE-2025-24993
7.8 HIGH KEV

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24991
5.5 MEDIUM KEV

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

Mar 11, 2025
CVE-2025-24985
7.8 HIGH KEV

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24984
4.6 MEDIUM KEV

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

Mar 11, 2025
CVE-2025-24983
7.0 HIGH KEV

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24054
6.5 MEDIUM KEV

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Mar 11, 2025
CVE-2025-27363
8.1 HIGH KEV

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph …

Mar 11, 2025
CVE-2024-54085
9.8 CRITICAL KEV

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this …

Mar 11, 2025
CVE-2025-24813
9.8 CRITICAL KEV

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet …

Mar 10, 2025
CVE-2025-1316
9.8 CRITICAL KEV

Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device

Mar 5, 2025
CVE-2025-22226
7.1 HIGH KEV

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a …

Mar 4, 2025
CVE-2025-22225
8.2 HIGH KEV

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an …

Mar 4, 2025
CVE-2025-22224
9.3 CRITICAL KEV

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a …

Mar 4, 2025
CVE-2024-48248
8.6 HIGH KEV

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across …

Mar 4, 2025
CVE-2025-24893
9.8 CRITICAL KEV

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution …

Feb 20, 2025
CVE-2025-24989
8.2 HIGH KEV

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This …

Feb 19, 2025
CVE-2025-0111
6.5 MEDIUM KEV

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to …

Feb 12, 2025
CVE-2025-0108
9.1 CRITICAL KEV

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the …

Feb 12, 2025
CVE-2025-21418
7.8 HIGH KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-21391
7.1 HIGH KEV

Windows Storage Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-24472
8.1 HIGH KEV

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may …

Feb 11, 2025
CVE-2025-24016
9.9 CRITICAL KEV

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an …

Feb 10, 2025
CVE-2025-24200
6.1 MEDIUM KEV

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS …

Feb 10, 2025
CVE-2025-0994
8.8 HIGH KEV

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an …

Feb 6, 2025
CVE-2024-40891
8.8 HIGH KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an …

Feb 4, 2025
CVE-2024-40890
8.8 HIGH KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an …

Feb 4, 2025
CVE-2023-52163
8.8 HIGH KEV

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Feb 3, 2025
CVE-2025-25181
5.8 MEDIUM KEV

A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

Feb 3, 2025
CVE-2024-57968
9.9 CRITICAL KEV

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). …

Feb 3, 2025
CVE-2025-24085
10.0 CRITICAL KEV

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia …

Jan 27, 2025
CVE-2025-0411
7.0 HIGH KEV

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to …

Jan 25, 2025
CVE-2025-23006
9.8 CRITICAL KEV

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions …

Jan 23, 2025
CVE-2025-23209
8.0 HIGH KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that …

Jan 18, 2025
CVE-2024-57728
7.2 HIGH KEV

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file …

Jan 15, 2025
CVE-2024-57727
7.5 HIGH KEV

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the …

Jan 15, 2025
CVE-2024-57726
9.9 CRITICAL KEV

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can …

Jan 15, 2025
CVE-2025-21335
7.8 HIGH KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.