CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-33062
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33061
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33060
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33059
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33058
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33057
6.5 MEDIUM

Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-33056
7.5 HIGH

Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-33055
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33053
8.8 HIGH KEV

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-33052
5.5 MEDIUM

Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33050
7.5 HIGH

Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-32725
7.5 HIGH

Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-32724
7.5 HIGH

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-32722
5.5 MEDIUM

Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32721
7.3 HIGH

Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32720
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32719
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32718
7.8 HIGH

Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32716
7.8 HIGH

Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32715
6.5 MEDIUM

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Jun 10, 2025
CVE-2025-32714
7.8 HIGH

Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32713
7.8 HIGH

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32712
7.8 HIGH

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32710
8.1 HIGH

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-31104
7.2 HIGH

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 …

Jun 10, 2025
CVE-2025-30321
5.5 MEDIUM

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

Jun 10, 2025
CVE-2025-30317
7.8 HIGH

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 10, 2025
CVE-2025-29828
8.1 HIGH

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-25250
4.3 MEDIUM

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, …

Jun 10, 2025
CVE-2025-24471
6.5 MEDIUM

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect …

Jun 10, 2025
CVE-2025-24069
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-24068
5.5 MEDIUM

Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-24065
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-22256
6.3 MEDIUM

A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through …

Jun 10, 2025
CVE-2025-22254
6.6 MEDIUM

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, …

Jun 10, 2025
CVE-2025-22251
3.1 LOW

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all …

Jun 10, 2025
CVE-2024-57190
9.8 CRITICAL

Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them …

Jun 10, 2025
CVE-2024-57189
5.4 MEDIUM

In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.

Jun 10, 2025
CVE-2024-57186
5.4 MEDIUM

In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.

Jun 10, 2025
CVE-2024-54019
4.8 MEDIUM

A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker …

Jun 10, 2025
CVE-2024-50568
5.9 MEDIUM

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through …

Jun 10, 2025
CVE-2024-50562
4.8 MEDIUM

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions …

Jun 10, 2025
CVE-2024-45329
4.3 MEDIUM

A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker …

Jun 10, 2025
CVE-2024-43706
7.6 HIGH

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

Jun 10, 2025
CVE-2024-32119
4.8 MEDIUM

An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID …

Jun 10, 2025
CVE-2023-48786
4.3 MEDIUM

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests …

Jun 10, 2025
CVE-2023-29184
3.2 LOW

An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged …

Jun 10, 2025
CVE-2023-20599
7.9 HIGH

Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86 resulting in …

Jun 10, 2025
CVE-2025-4678

Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

Jun 10, 2025
CVE-2025-4653

Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

Jun 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.