CVE Database

39635+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-26665
7.0 HIGH

Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26663
8.1 HIGH

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26652
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26649
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26648
7.8 HIGH

Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26647
8.8 HIGH

Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-26642
7.8 HIGH

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-26641
7.5 HIGH

Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26640
7.0 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26639
7.8 HIGH

Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26628
7.3 HIGH

Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-24074
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24073
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24062
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24060
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24058
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-21222
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-21221
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-21205
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-21204
7.8 HIGH

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-21191
7.0 HIGH

Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-21174
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-32117
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: …

Apr 8, 2025
CVE-2025-27083
7.2 HIGH

Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker …

Apr 8, 2025
CVE-2025-27082
7.2 HIGH

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow …

Apr 8, 2025
CVE-2025-25227
7.5 HIGH

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Apr 8, 2025
CVE-2025-3289
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation …

Apr 8, 2025
CVE-2025-3288
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory …

Apr 8, 2025
CVE-2025-3287
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation …

Apr 8, 2025
CVE-2025-3286
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory …

Apr 8, 2025
CVE-2025-3285
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory …

Apr 8, 2025
CVE-2025-32018
8.0 HIGH

Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a regression affecting the set of …

Apr 8, 2025
CVE-2025-32017
8.8 HIGH

Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that …

Apr 8, 2025
CVE-2025-2829
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory …

Apr 8, 2025
CVE-2025-2293
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory …

Apr 8, 2025
CVE-2025-2288
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory …

Apr 8, 2025
CVE-2025-2287
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied …

Apr 8, 2025
CVE-2025-2286
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied …

Apr 8, 2025
CVE-2025-2285
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied …

Apr 8, 2025
CVE-2025-1095
8.8 HIGH

IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in …

Apr 8, 2025
CVE-2025-32406
8.6 HIGH

An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the …

Apr 8, 2025
CVE-2025-22466
8.2 HIGH

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User …

Apr 8, 2025
CVE-2025-22461
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve …

Apr 8, 2025
CVE-2025-22458
7.8 HIGH

DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

Apr 8, 2025
CVE-2025-30151
7.5 HIGH

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. …

Apr 8, 2025
CVE-2025-25254
7.2 HIGH

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 …

Apr 8, 2025
CVE-2024-54024
7.2 HIGH

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before version 2.4.6 allows a privileged …

Apr 8, 2025
CVE-2024-26013
7.5 HIGH

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 …

Apr 8, 2025
CVE-2023-37930
7.5 HIGH

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially …

Apr 8, 2025
CVE-2025-29986
8.3 HIGH

Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Common Anti-Virus Agent (CAVA). An …

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.