CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43101
5.3 MEDIUM

Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.101.4255 may allow an authenticated user to potentially …

May 13, 2025
CVE-2024-39833
6.7 MEDIUM

Uncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

May 13, 2025
CVE-2024-39758
5.9 MEDIUM

Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 31.0.101.4032 may allow an authenticated user to potentially enable denial of …

May 13, 2025
CVE-2024-31073
6.7 MEDIUM

Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially enable escalation of privilege via local access.

May 13, 2025
CVE-2024-29222
6.1 MEDIUM

Out-of-bounds write for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable denial of service via local access.

May 13, 2025
CVE-2024-28956
5.6 MEDIUM

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure …

May 13, 2025
CVE-2024-28954
6.7 MEDIUM

Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentially enable escalation of privilege via local access.

May 13, 2025
CVE-2024-28036
5.6 MEDIUM

Improper conditions check for some Intel(R) Arc™ GPU may allow an authenticated user to potentially enable denial of service via local access.

May 13, 2025
CVE-2025-45746
6.5 MEDIUM

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier …

May 13, 2025
CVE-2025-30329
5.5 MEDIUM

Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this …

May 13, 2025
CVE-2025-47280
6.1 MEDIUM

Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 and …

May 13, 2025
CVE-2025-32703
5.5 MEDIUM

Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.

May 13, 2025
CVE-2025-30394
5.9 MEDIUM

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

May 13, 2025
CVE-2025-30320
5.5 MEDIUM

InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

May 13, 2025
CVE-2025-30319
5.5 MEDIUM

InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

May 13, 2025
CVE-2025-29974
5.7 MEDIUM

Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.

May 13, 2025
CVE-2025-29968
6.5 MEDIUM

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.

May 13, 2025
CVE-2025-29961
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29960
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29959
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29958
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29957
6.2 MEDIUM

Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.

May 13, 2025
CVE-2025-29956
5.4 MEDIUM

Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29955
6.2 MEDIUM

Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.

May 13, 2025
CVE-2025-29954
5.9 MEDIUM

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

May 13, 2025
CVE-2025-29839
4.0 MEDIUM

Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.

May 13, 2025
CVE-2025-29837
5.5 MEDIUM

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.

May 13, 2025
CVE-2025-29836
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29835
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29832
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29830
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29829
5.5 MEDIUM

Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

May 13, 2025
CVE-2025-27488
6.7 MEDIUM

Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-26685
6.5 MEDIUM

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

May 13, 2025
CVE-2025-26684
6.7 MEDIUM

External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2024-6364
6.4 MEDIUM

A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to …

May 13, 2025
CVE-2025-4427
5.3 MEDIUM KEV

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via …

May 13, 2025
CVE-2025-47204
6.1 MEDIUM

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a …

May 13, 2025
CVE-2025-46721
6.1 MEDIUM

nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls content on the …

May 13, 2025
CVE-2024-56526
4.9 MEDIUM

An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a …

May 13, 2025
CVE-2025-45867
5.4 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.

May 13, 2025
CVE-2025-45866
5.4 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.

May 13, 2025
CVE-2025-45864
5.4 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.

May 13, 2025
CVE-2025-45859
5.4 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.

May 13, 2025
CVE-2025-44039
5.1 MEDIUM

CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the …

May 13, 2025
CVE-2025-22859
5.3 MEDIUM

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform …

May 13, 2025
CVE-2024-36340
6.6 MEDIUM

A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.

May 13, 2025
CVE-2025-4649
4.9 MEDIUM

Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event …

May 13, 2025
CVE-2025-40583
4.4 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in …

May 13, 2025
CVE-2025-40580
6.7 MEDIUM

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could …

May 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.