CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54091
7.8 HIGH

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53807
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53805
7.5 HIGH

Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.

Sep 9, 2025
CVE-2025-53802
7.0 HIGH

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53801
7.8 HIGH

Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53800
7.8 HIGH

No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53303
8.8 HIGH

Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core: from n/a through <= 1.4.2.

Sep 9, 2025
CVE-2025-49734
7.0 HIGH

Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-49692
7.8 HIGH

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-49430
7.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultimate Video Player: from n/a through <= …

Sep 9, 2025
CVE-2025-48101
8.8 HIGH

Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1.

Sep 9, 2025
CVE-2025-47695
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer …

Sep 9, 2025
CVE-2025-47694
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer PRO: from n/a through …

Sep 9, 2025
CVE-2025-47571
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp allows PHP Local File …

Sep 9, 2025
CVE-2025-47570
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This issue affects WooCommerce Photo Reviews: from n/a through …

Sep 9, 2025
CVE-2025-32689
7.5 HIGH

Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects WP SmartPay: from n/a through <= 2.8.2.

Sep 9, 2025
CVE-2025-9872
8.8 HIGH

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. …

Sep 9, 2025
CVE-2025-9712
8.8 HIGH

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. …

Sep 9, 2025
CVE-2025-55148
7.6 HIGH

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure …

Sep 9, 2025
CVE-2025-55147
8.8 HIGH

CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access …

Sep 9, 2025
CVE-2025-55145
8.9 HIGH

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure …

Sep 9, 2025
CVE-2025-55142
8.8 HIGH

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure …

Sep 9, 2025
CVE-2025-55141
8.8 HIGH

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure …

Sep 9, 2025
CVE-2025-52915
7.2 HIGH

K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through …

Sep 9, 2025
CVE-2025-52322
7.5 HIGH

An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to …

Sep 9, 2025
CVE-2025-33045
8.2 HIGH

APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to an Unauthorized Actor” through local …

Sep 9, 2025
CVE-2025-9364
8.8 HIGH

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in …

Sep 9, 2025
CVE-2025-9166
7.5 HIGH

A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue …

Sep 9, 2025
CVE-2025-9161
8.8 HIGH

A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, …

Sep 9, 2025
CVE-2025-9065
8.8 HIGH

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability …

Sep 9, 2025
CVE-2025-7970
7.5 HIGH

A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This …

Sep 9, 2025
CVE-2025-48208
8.8 HIGH

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account …

Sep 9, 2025
CVE-2025-24404
8.8 HIGH

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add …

Sep 9, 2025
CVE-2025-59017
8.8 HIGH

Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend …

Sep 9, 2025
CVE-2025-41701
7.8 HIGH

An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. These …

Sep 9, 2025
CVE-2025-40798
7.5 HIGH

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), User …

Sep 9, 2025
CVE-2025-40797
7.5 HIGH

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), User …

Sep 9, 2025
CVE-2025-40796
7.5 HIGH

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), User …

Sep 9, 2025
CVE-2025-9539
8.0 HIGH

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due …

Sep 9, 2025
CVE-2025-10123
7.3 HIGH

A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of …

Sep 9, 2025
CVE-2025-42933
8.8 HIGH

When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads …

Sep 9, 2025
CVE-2025-42929
8.1 HIGH

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables …

Sep 9, 2025
CVE-2025-42916
8.1 HIGH

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables …

Sep 9, 2025
CVE-2025-10120
8.8 HIGH

A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the …

Sep 9, 2025
CVE-2025-10118
7.3 HIGH

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the …

Sep 9, 2025
CVE-2025-10116
7.3 HIGH

A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The …

Sep 9, 2025
CVE-2025-10115
7.3 HIGH

A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes …

Sep 9, 2025
CVE-2025-10114
7.3 HIGH

A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the …

Sep 9, 2025
CVE-2025-58757
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in …

Sep 9, 2025
CVE-2025-58756
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, …

Sep 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.