CVE Database

39635+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25053
8.8 HIGH

OS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may …

Apr 9, 2025
CVE-2024-55354
8.8 HIGH

Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism failure that …

Apr 8, 2025
CVE-2025-30290
8.7 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could …

Apr 8, 2025
CVE-2025-30289
8.2 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability …

Apr 8, 2025
CVE-2025-30288
8.2 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low …

Apr 8, 2025
CVE-2025-30287
8.2 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-30286
8.4 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability …

Apr 8, 2025
CVE-2025-30285
8.4 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the …

Apr 8, 2025
CVE-2025-30284
8.4 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the …

Apr 8, 2025
CVE-2024-12556
8.7 HIGH

Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

Apr 8, 2025
CVE-2025-30304
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-30299
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-30298
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-30297
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-30296
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Apr 8, 2025
CVE-2025-30295
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-29824
7.8 HIGH KEV

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29823
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-29822
7.8 HIGH

Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-29820
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-29816
7.5 HIGH

Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.

Apr 8, 2025
CVE-2025-29812
7.8 HIGH

Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29811
7.8 HIGH

Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29810
7.5 HIGH

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-29809
7.1 HIGH

Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-29805
7.5 HIGH

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-29804
7.3 HIGH

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29802
7.3 HIGH

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29801
7.8 HIGH

Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29800
7.8 HIGH

Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29794
8.8 HIGH

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-29793
7.2 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-29792
7.3 HIGH

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29791
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27752
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27751
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27750
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27749
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27748
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27747
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27746
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27745
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27744
7.8 HIGH

Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27743
7.8 HIGH

Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27741
7.8 HIGH

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27740
8.8 HIGH

Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-27739
7.8 HIGH

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27737
8.6 HIGH

Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-27733
7.8 HIGH

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27732
7.0 HIGH

Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.