CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46786
4.3 MEDIUM

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.

May 14, 2025
CVE-2025-46785
6.5 MEDIUM

Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

May 14, 2025
CVE-2025-30668
6.5 MEDIUM

Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.

May 14, 2025
CVE-2025-30667
6.5 MEDIUM

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

May 14, 2025
CVE-2025-30666
6.5 MEDIUM

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

May 14, 2025
CVE-2025-30665
6.5 MEDIUM

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

May 14, 2025
CVE-2025-30664
6.6 MEDIUM

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

May 14, 2025
CVE-2025-47709
6.5 MEDIUM

Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before …

May 14, 2025
CVE-2025-47706
4.8 MEDIUM

Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA …

May 14, 2025
CVE-2025-47705
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: …

May 14, 2025
CVE-2025-47704
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro …

May 14, 2025
CVE-2025-47703
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: …

May 14, 2025
CVE-2025-47702
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Providers allows Cross-Site Scripting (XSS).This issue affects oEmbed Providers: from 0.0.0 …

May 14, 2025
CVE-2025-44186
5.4 MEDIUM

SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.

May 14, 2025
CVE-2025-44184
4.8 MEDIUM

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.

May 14, 2025
CVE-2025-3932
6.5 MEDIUM

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically …

May 14, 2025
CVE-2025-26784
6.5 MEDIUM

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, …

May 14, 2025
CVE-2025-47775
6.2 MEDIUM

Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. …

May 14, 2025
CVE-2025-24969
5.0 MEDIUM

iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the …

May 14, 2025
CVE-2025-24785
4.3 MEDIUM

iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP …

May 14, 2025
CVE-2025-24026
5.3 MEDIUM

iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under …

May 14, 2025
CVE-2025-24021
5.0 MEDIUM

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set …

May 14, 2025
CVE-2024-56157
6.3 MEDIUM

iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site …

May 14, 2025
CVE-2024-52601
6.5 MEDIUM

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have …

May 14, 2025
CVE-2024-57273
5.4 MEDIUM

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, …

May 14, 2025
CVE-2024-54779
5.4 MEDIUM

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

May 14, 2025
CVE-2023-53146
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer() In dw2102_i2c_transfer, msg is controlled by user. When msg[i].buf …

May 14, 2025
CVE-2025-3769
5.3 MEDIUM

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

May 14, 2025
CVE-2024-8988
5.3 MEDIUM

The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the …

May 14, 2025
CVE-2024-13940
5.5 MEDIUM

The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form webhook …

May 14, 2025
CVE-2024-52290
6.3 MEDIUM

LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate …

May 14, 2025
CVE-2025-4520
5.4 MEDIUM

The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions …

May 14, 2025
CVE-2025-4574
6.5 MEDIUM

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could …

May 13, 2025
CVE-2025-47905
5.4 MEDIUM

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF …

May 13, 2025
CVE-2025-43566
6.8 MEDIUM

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could …

May 13, 2025
CVE-2025-43551
5.5 MEDIUM

Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

May 13, 2025
CVE-2025-30316
5.4 MEDIUM

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to …

May 13, 2025
CVE-2025-30315
6.1 MEDIUM

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious …

May 13, 2025
CVE-2025-30314
6.1 MEDIUM

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious …

May 13, 2025
CVE-2025-24495
5.6 MEDIUM

Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure …

May 13, 2025
CVE-2025-22895
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially …

May 13, 2025
CVE-2025-22892
6.5 MEDIUM

Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 may allow an unauthenticated user to potentially enable denial of …

May 13, 2025
CVE-2025-22844
4.3 MEDIUM

Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticated user to potentially enable information disclosure via adjacent …

May 13, 2025
CVE-2025-22448
6.1 MEDIUM

Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an authenticated user to potentially enable denial of service via …

May 13, 2025
CVE-2025-22446
4.6 MEDIUM

Inadequate encryption strength for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via …

May 13, 2025
CVE-2025-21100
4.1 MEDIUM

Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via …

May 13, 2025
CVE-2025-21099
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.

May 13, 2025
CVE-2025-21081
4.5 MEDIUM

Protection mechanism failure for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via …

May 13, 2025
CVE-2025-20629
6.7 MEDIUM

Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to …

May 13, 2025
CVE-2025-20624
5.7 MEDIUM

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially …

May 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.