CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49149
6.1 MEDIUM

Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website …

Jun 17, 2025
CVE-2025-49825
9.8 CRITICAL

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time …

Jun 17, 2025
CVE-2025-49593
6.8 MEDIUM

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior …

Jun 17, 2025
CVE-2025-49843

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version …

Jun 17, 2025
CVE-2025-49824

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version …

Jun 17, 2025
CVE-2025-49385
7.8 HIGH

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged …

Jun 17, 2025
CVE-2025-49384
7.8 HIGH

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged …

Jun 17, 2025
CVE-2025-49218
7.7 HIGH

A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. This is similar …

Jun 17, 2025
CVE-2025-49217
9.8 CRITICAL

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this …

Jun 17, 2025
CVE-2025-49216
9.8 CRITICAL

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify …

Jun 17, 2025
CVE-2025-49215
8.8 HIGH

A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an …

Jun 17, 2025
CVE-2025-49214
8.8 HIGH

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an …

Jun 17, 2025
CVE-2025-49213
9.8 CRITICAL

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this …

Jun 17, 2025
CVE-2025-49212
9.8 CRITICAL

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this …

Jun 17, 2025
CVE-2025-49211
7.7 HIGH

A SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker …

Jun 17, 2025
CVE-2025-48443
6.7 MEDIUM

Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker …

Jun 17, 2025
CVE-2025-41413
7.8 HIGH

Fuji Electric Smart Editor is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.

Jun 17, 2025
CVE-2025-41388
7.8 HIGH

Fuji Electric Smart Editor is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

Jun 17, 2025
CVE-2025-32412
7.8 HIGH

Fuji Electric Smart Editor is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.

Jun 17, 2025
CVE-2025-30642
5.5 MEDIUM

A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on …

Jun 17, 2025
CVE-2025-30641
7.8 HIGH

A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on …

Jun 17, 2025
CVE-2025-30640
7.8 HIGH

A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an …

Jun 17, 2025
CVE-2025-5141
5.5 MEDIUM

A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), …

Jun 17, 2025
CVE-2025-49847
8.8 HIGH

llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabulary can trigger a buffer overflow in …

Jun 17, 2025
CVE-2025-45526
2.9 LOW

A denial of service (DoS) vulnerability has been identified in the JavaScript library microlight version 0.0.7. This library, used for syntax highlighting, does not limit …

Jun 17, 2025
CVE-2025-45525
2.9 LOW

A NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a lightweight syntax highlighting library. When processing elements with non-standard …

Jun 17, 2025
CVE-2025-30680
7.1 HIGH

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leading to information disclosure on …

Jun 17, 2025
CVE-2025-30679
6.5 MEDIUM

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information …

Jun 17, 2025
CVE-2025-30678
6.5 MEDIUM

A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to information …

Jun 17, 2025
CVE-2024-40570
6.5 MEDIUM

SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.

Jun 17, 2025
CVE-2025-49850

A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which …

Jun 17, 2025
CVE-2025-49849

An Out-of-bounds Read vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can …

Jun 17, 2025
CVE-2025-49848

An Out-of-bounds Write vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can …

Jun 17, 2025
CVE-2025-49487
6.8 MEDIUM

An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a …

Jun 17, 2025
CVE-2025-49158
6.7 MEDIUM

An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations. Please …

Jun 17, 2025
CVE-2025-49157
7.8 HIGH

A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please …

Jun 17, 2025
CVE-2025-49156
7.0 HIGH

A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: …

Jun 17, 2025
CVE-2025-49155
8.8 HIGH

An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to …

Jun 17, 2025
CVE-2025-49154
8.7 HIGH

An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped …

Jun 17, 2025
CVE-2025-34511
8.8 HIGH

Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. …

Jun 17, 2025
CVE-2025-34510
8.8 HIGH

Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip …

Jun 17, 2025
CVE-2025-34509
7.5 HIGH

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, …

Jun 17, 2025
CVE-2025-49220
9.8 CRITICAL

An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that …

Jun 17, 2025
CVE-2025-49219
9.8 CRITICAL

An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that …

Jun 17, 2025
CVE-2025-47867
7.5 HIGH

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to …

Jun 17, 2025
CVE-2025-47866
4.3 MEDIUM

An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected …

Jun 17, 2025
CVE-2025-47865
7.5 HIGH

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on …

Jun 17, 2025
CVE-2025-33122
7.5 HIGH

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced …

Jun 17, 2025
CVE-2025-45880
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of …

Jun 17, 2025
CVE-2025-45878
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a …

Jun 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.