11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the …
Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially …
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result …
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form …
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form …
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no …
In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no …
In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote …
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a …
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host …
mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information …
Free website and port scanning — find vulnerabilities before attackers do.