CVE Database

39635+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-28892
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in a2rocklobster FTP Sync ftp-sync allows Stored XSS.This issue affects FTP Sync: from n/a through <= 1.1.6.

Mar 11, 2025
CVE-2025-28891
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in jazzigor price-calc price-calc allows Stored XSS.This issue affects price-calc: from n/a through <= 0.6.3.

Mar 11, 2025
CVE-2025-28883
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Martin WP Compare Tables wp-compare-tables allows Stored XSS.This issue affects WP Compare Tables: from n/a through <= 1.0.5.

Mar 11, 2025
CVE-2025-28861
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker wpjqp-datepicker allows Stored XSS.This issue affects WP jQuery Persian Datepicker: from n/a through <= …

Mar 11, 2025
CVE-2025-28860
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in PPDPurveyor Google News Editors Picks Feed Generator google-news-editors-picks-news-feeds allows Stored XSS.This issue affects Google News Editors Picks Feed Generator: …

Mar 11, 2025
CVE-2025-28857
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in rankchecker Rankchecker.io Integration rankchecker-io-integration allows Stored XSS.This issue affects Rankchecker.io Integration: from n/a through <= 1.0.9.

Mar 11, 2025
CVE-2025-27181
7.8 HIGH

Substance3D - Modeler versions 1.15.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2025-27173
7.8 HIGH

Substance3D - Modeler versions 1.15.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2025-25928
8.0 HIGH

A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted request. In …

Mar 11, 2025
CVE-2025-23360
7.1 HIGH

NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this …

Mar 11, 2025
CVE-2025-23242
7.3 HIGH

NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation …

Mar 11, 2025
CVE-2025-27773
8.6 HIGH

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in …

Mar 11, 2025
CVE-2025-27440
8.5 HIGH

Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Mar 11, 2025
CVE-2025-27439
8.5 HIGH

Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Mar 11, 2025
CVE-2025-27178
7.8 HIGH

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-27177
7.8 HIGH

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2025-27175
7.8 HIGH

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-27174
7.8 HIGH

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the …

Mar 11, 2025
CVE-2025-27171
7.8 HIGH

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2025-27169
7.8 HIGH

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Mar 11, 2025
CVE-2025-27168
7.8 HIGH

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-27167
7.8 HIGH

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized …

Mar 11, 2025
CVE-2025-27166
7.8 HIGH

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-27162
7.8 HIGH

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in …

Mar 11, 2025
CVE-2025-27161
7.8 HIGH

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a …

Mar 11, 2025
CVE-2025-27160
7.8 HIGH

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the …

Mar 11, 2025
CVE-2025-27159
7.8 HIGH

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the …

Mar 11, 2025
CVE-2025-27158
7.8 HIGH

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in …

Mar 11, 2025
CVE-2025-25749
7.1 HIGH

An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.

Mar 11, 2025
CVE-2025-25748
7.3 HIGH

A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users …

Mar 11, 2025
CVE-2025-24453
7.8 HIGH

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2025-24452
7.8 HIGH

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-24451
7.8 HIGH

Substance3D - Painter versions 10.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-24450
7.8 HIGH

Substance3D - Painter versions 10.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-24445
7.8 HIGH

Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-24444
7.8 HIGH

Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-24443
7.8 HIGH

Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2025-24442
7.8 HIGH

Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-24441
7.8 HIGH

Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-24440
7.8 HIGH

Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-24439
7.8 HIGH

Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2025-0151
8.5 HIGH

Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Mar 11, 2025
CVE-2025-0150
7.1 HIGH

Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via …

Mar 11, 2025
CVE-2025-27172
7.8 HIGH

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 11, 2025
CVE-2025-26645
8.8 HIGH

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-26634
7.5 HIGH

Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.

Mar 11, 2025
CVE-2025-26633
7.0 HIGH KEV

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Mar 11, 2025
CVE-2025-26631
7.3 HIGH

Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-26630
7.8 HIGH

Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-26629
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mar 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.