CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29960
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29959
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29958
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29957
6.2 MEDIUM

Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.

May 13, 2025
CVE-2025-29956
5.4 MEDIUM

Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29955
6.2 MEDIUM

Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.

May 13, 2025
CVE-2025-29954
5.9 MEDIUM

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

May 13, 2025
CVE-2025-29839
4.0 MEDIUM

Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.

May 13, 2025
CVE-2025-29837
5.5 MEDIUM

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.

May 13, 2025
CVE-2025-29836
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29835
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29832
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29830
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29829
5.5 MEDIUM

Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

May 13, 2025
CVE-2025-27488
6.7 MEDIUM

Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-26685
6.5 MEDIUM

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

May 13, 2025
CVE-2025-26684
6.7 MEDIUM

External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2024-6364
6.4 MEDIUM

A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to …

May 13, 2025
CVE-2025-4427
5.3 MEDIUM KEV

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via …

May 13, 2025
CVE-2025-47204
6.1 MEDIUM

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a …

May 13, 2025
CVE-2025-46721
6.1 MEDIUM

nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls content on the …

May 13, 2025
CVE-2024-56526
4.9 MEDIUM

An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a …

May 13, 2025
CVE-2025-45867
5.4 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.

May 13, 2025
CVE-2025-45866
5.4 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.

May 13, 2025
CVE-2025-45864
5.4 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.

May 13, 2025
CVE-2025-45859
5.4 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.

May 13, 2025
CVE-2025-44039
5.1 MEDIUM

CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the …

May 13, 2025
CVE-2025-22859
5.3 MEDIUM

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform …

May 13, 2025
CVE-2024-36340
6.6 MEDIUM

A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.

May 13, 2025
CVE-2025-4649
4.9 MEDIUM

Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event …

May 13, 2025
CVE-2025-40583
4.4 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in …

May 13, 2025
CVE-2025-40580
6.7 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could …

May 13, 2025
CVE-2025-40579
6.7 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could …

May 13, 2025
CVE-2025-40578
4.3 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. …

May 13, 2025
CVE-2025-40577
4.3 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated …

May 13, 2025
CVE-2025-40576
4.3 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated …

May 13, 2025
CVE-2025-40575
4.3 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated …

May 13, 2025
CVE-2025-40573
4.4 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow …

May 13, 2025
CVE-2025-40572
5.5 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permissions to critical ressources. This …

May 13, 2025
CVE-2025-40556
6.5 MEDIUM

A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet ATEC 550-445 (All versions), BACnet ATEC 550-446 (All …

May 13, 2025
CVE-2025-40555
4.7 MEDIUM

A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnet broadcast messages after processing a specific …

May 13, 2025
CVE-2025-31929
4.2 MEDIUM

A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions), IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2EN04-0GA0) (All versions), IEC 1Ph …

May 13, 2025
CVE-2025-24510
6.5 MEDIUM

A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an …

May 13, 2025
CVE-2025-24009
5.9 MEDIUM

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not …

May 13, 2025
CVE-2025-24008
6.5 MEDIUM

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not …

May 13, 2025
CVE-2024-51447
5.3 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an …

May 13, 2025
CVE-2024-51446
6.5 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected application improperly …

May 13, 2025
CVE-2024-51445
6.5 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection …

May 13, 2025
CVE-2024-51444
6.5 MEDIUM

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read …

May 13, 2025
CVE-2025-4339
4.3 MEDIUM

The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxApi() function in all versions …

May 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.