CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49671
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a …

Jul 8, 2025
CVE-2025-49670
6.5 MEDIUM

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Jul 8, 2025
CVE-2025-49664
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-49658
5.5 MEDIUM

Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-48823
5.9 MEDIUM

Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.

Jul 8, 2025
CVE-2025-48818
6.8 MEDIUM

Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Jul 8, 2025
CVE-2025-48812
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-48811
6.7 MEDIUM

Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Jul 8, 2025
CVE-2025-48810
5.5 MEDIUM

Processor optimization removal or modification of security-critical code in Windows Secure Kernel Mode allows an authorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-48809
5.5 MEDIUM

Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-48808
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-48804
6.8 MEDIUM

Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Jul 8, 2025
CVE-2025-48803
6.7 MEDIUM

Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Jul 8, 2025
CVE-2025-48802
6.5 MEDIUM

Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.

Jul 8, 2025
CVE-2025-48800
6.8 MEDIUM

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Jul 8, 2025
CVE-2025-48003
6.8 MEDIUM

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Jul 8, 2025
CVE-2025-48002
5.7 MEDIUM

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network.

Jul 8, 2025
CVE-2025-48001
6.8 MEDIUM

Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Jul 8, 2025
CVE-2025-47999
6.8 MEDIUM

Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

Jul 8, 2025
CVE-2025-47980
6.2 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-47978
6.5 MEDIUM

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

Jul 8, 2025
CVE-2025-47109
5.5 MEDIUM

After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

Jul 8, 2025
CVE-2025-43587
5.5 MEDIUM

After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 8, 2025
CVE-2025-43580
5.5 MEDIUM

Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that could result in application denial-of-service. …

Jul 8, 2025
CVE-2025-26636
5.5 MEDIUM

Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-21195
6.0 MEDIUM

Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

Jul 8, 2025
CVE-2025-21168
5.5 MEDIUM

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 8, 2025
CVE-2025-21167
5.5 MEDIUM

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 8, 2025
CVE-2024-36357
5.6 MEDIUM

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of …

Jul 8, 2025
CVE-2024-36350
5.6 MEDIUM

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged …

Jul 8, 2025
CVE-2025-5464
6.5 MEDIUM

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information.

Jul 8, 2025
CVE-2025-0293
6.6 MEDIUM

CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to …

Jul 8, 2025
CVE-2025-0292
5.5 MEDIUM

SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to access …

Jul 8, 2025
CVE-2025-7182
4.3 MEDIUM

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 8, 2025
CVE-2025-5463
5.5 MEDIUM

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local …

Jul 8, 2025
CVE-2025-5451
4.9 MEDIUM

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin …

Jul 8, 2025
CVE-2025-5450
6.3 MEDIUM

Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote …

Jul 8, 2025
CVE-2025-53480
5.4 MEDIUM

The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can exploit …

Jul 8, 2025
CVE-2025-3630
6.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored …

Jul 8, 2025
CVE-2025-2827
4.3 MEDIUM

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used …

Jul 8, 2025
CVE-2025-2793
5.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site …

Jul 8, 2025
CVE-2025-29267
6.5 MEDIUM

SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to obtain a sensitive information via the cid parameter …

Jul 8, 2025
CVE-2024-55599
5.3 MEDIUM

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy …

Jul 8, 2025
CVE-2025-7181
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unknown function of the file /test.php. The …

Jul 8, 2025
CVE-2025-21433
6.2 MEDIUM

Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

Jul 8, 2025
CVE-2025-21426
6.6 MEDIUM

Memory corruption while processing camera TPG write request.

Jul 8, 2025
CVE-2024-53009
5.3 MEDIUM

Memory corruption while operating the mailbox in Automotive.

Jul 8, 2025
CVE-2025-7177
4.7 MEDIUM

A vulnerability was found in PHPGurukul Car Washing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 8, 2025
CVE-2025-40721
5.4 MEDIUM

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in …

Jul 8, 2025
CVE-2025-40720
6.1 MEDIUM

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in …

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.