CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-33063
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33062
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33061
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33060
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33059
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33058
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33057
6.5 MEDIUM

Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-33055
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33052
5.5 MEDIUM

Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32722
5.5 MEDIUM

Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32720
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32719
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32715
6.5 MEDIUM

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Jun 10, 2025
CVE-2025-30321
5.5 MEDIUM

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

Jun 10, 2025
CVE-2025-25250
4.3 MEDIUM

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, …

Jun 10, 2025
CVE-2025-24471
6.5 MEDIUM

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect …

Jun 10, 2025
CVE-2025-24069
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-24068
5.5 MEDIUM

Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-24065
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-22256
6.3 MEDIUM

A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through …

Jun 10, 2025
CVE-2025-22254
6.6 MEDIUM

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, …

Jun 10, 2025
CVE-2024-57189
5.4 MEDIUM

In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.

Jun 10, 2025
CVE-2024-57186
5.4 MEDIUM

In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.

Jun 10, 2025
CVE-2024-54019
4.8 MEDIUM

A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker …

Jun 10, 2025
CVE-2024-50568
5.9 MEDIUM

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through …

Jun 10, 2025
CVE-2024-50562
4.8 MEDIUM

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions …

Jun 10, 2025
CVE-2024-45329
4.3 MEDIUM

A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker …

Jun 10, 2025
CVE-2024-32119
4.8 MEDIUM

An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID …

Jun 10, 2025
CVE-2023-48786
4.3 MEDIUM

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests …

Jun 10, 2025
CVE-2025-49143
5.9 MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROOT directory, …

Jun 10, 2025
CVE-2025-48937
4.9 MEDIUM

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender …

Jun 10, 2025
CVE-2025-48879
6.5 MEDIUM

OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and …

Jun 10, 2025
CVE-2025-48067
5.4 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with …

Jun 10, 2025
CVE-2025-44043
5.4 MEDIUM

Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults and /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetLocationAndContentCategories. An attacker can specify their own SMB server as …

Jun 10, 2025
CVE-2025-40569
4.8 MEDIUM

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions …

Jun 10, 2025
CVE-2025-40568
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions …

Jun 10, 2025
CVE-2025-40567
6.5 MEDIUM

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions …

Jun 10, 2025
CVE-2025-27207
6.5 MEDIUM

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A …

Jun 10, 2025
CVE-2025-27206
5.3 MEDIUM

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Jun 10, 2025
CVE-2024-41797
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions …

Jun 10, 2025
CVE-2025-27505
5.3 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security …

Jun 10, 2025
CVE-2025-26394
4.8 MEDIUM

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect …

Jun 10, 2025
CVE-2024-40625
5.5 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspaces/{workspaceName}/coveragestores/{storeName}/{method}.{format} allows attackers to upload files …

Jun 10, 2025
CVE-2024-38524
5.3 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information …

Jun 10, 2025
CVE-2025-49510
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Min Max Step Quantity Limits Manager for WooCommerce product-quantity-for-woocommerce allows Cross Site Request Forgery.This issue affects Min Max …

Jun 10, 2025
CVE-2025-49509
5.3 MEDIUM

Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audio Editor & Recorder: …

Jun 10, 2025
CVE-2025-4774
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdown attribute of Countdown widget in all versions up …

Jun 10, 2025
CVE-2025-4577
6.4 MEDIUM

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute …

Jun 10, 2025
CVE-2025-43699
5.3 MEDIUM

Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check. This impacts OmniStudio: before Spring 2025

Jun 10, 2025
CVE-2025-2918
6.4 MEDIUM

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and …

Jun 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.