CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36124
5.9 MEDIUM

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging …

Aug 12, 2025
CVE-2025-32932
6.5 MEDIUM

An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all …

Aug 12, 2025
CVE-2025-32766
6.4 MEDIUM

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code …

Aug 12, 2025
CVE-2025-27759
6.7 MEDIUM

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through …

Aug 12, 2025
CVE-2025-25248
5.3 MEDIUM

An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 …

Aug 12, 2025
CVE-2024-52964
5.5 MEDIUM

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 …

Aug 12, 2025
CVE-2024-48892
6.8 MEDIUM

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read …

Aug 12, 2025
CVE-2024-40588
4.4 MEDIUM

Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 …

Aug 12, 2025
CVE-2023-45584
6.6 MEDIUM

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all …

Aug 12, 2025
CVE-2025-53769
5.5 MEDIUM

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

Aug 12, 2025
CVE-2025-53765
4.4 MEDIUM

Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.

Aug 12, 2025
CVE-2025-53736
6.8 MEDIUM

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Aug 12, 2025
CVE-2025-53728
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-53719
5.7 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-53716
6.5 MEDIUM

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

Aug 12, 2025
CVE-2025-53156
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally.

Aug 12, 2025
CVE-2025-53153
5.7 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-53148
5.7 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-53138
5.7 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-53136
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally.

Aug 12, 2025
CVE-2025-50172
6.5 MEDIUM

Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.

Aug 12, 2025
CVE-2025-50166
6.5 MEDIUM

Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-50157
5.7 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-50156
5.7 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-50154
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-49755
4.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-49751
6.8 MEDIUM

Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

Aug 12, 2025
CVE-2025-49745
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-49743
6.7 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Aug 12, 2025
CVE-2025-49736
4.3 MEDIUM

The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-49559
5.3 MEDIUM

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path …

Aug 12, 2025
CVE-2025-49558
5.9 MEDIUM

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in …

Aug 12, 2025
CVE-2025-48807
6.7 MEDIUM

Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.

Aug 12, 2025
CVE-2025-25007
5.3 MEDIUM

Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-25006
5.3 MEDIUM

Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-25005
6.5 MEDIUM

Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Aug 12, 2025
CVE-2025-20044
4.1 MEDIUM

Improper locking for some Intel(R) TDX Module firmware before version 1.5.13 may allow a privileged user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-49568
5.5 MEDIUM

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Aug 12, 2025
CVE-2025-49567
5.5 MEDIUM

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this …

Aug 12, 2025
CVE-2025-27717
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privilege via local access

Aug 12, 2025
CVE-2025-27559
6.7 MEDIUM

Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enable escalation of privilege via local …

Aug 12, 2025
CVE-2025-27537
5.5 MEDIUM

Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation …

Aug 12, 2025
CVE-2025-26472
5.7 MEDIUM

Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial …

Aug 12, 2025
CVE-2025-26470
6.7 MEDIUM

Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticated user to potentially enable escalation of privilege …

Aug 12, 2025
CVE-2025-26404
6.7 MEDIUM

Uncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-24923
6.7 MEDIUM

Uncontrolled search path in some Intel(R) AI for Enterprise Retrieval-augmented Generation software may allow an authenticated user to potentially enable escalation of privilege via local …

Aug 12, 2025
CVE-2025-24921
6.6 MEDIUM

Improper neutralization for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable information disclosure …

Aug 12, 2025
CVE-2025-24840
5.8 MEDIUM

Improper access control for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable escalation …

Aug 12, 2025
CVE-2025-24835
6.5 MEDIUM

Protection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-24515
6.5 MEDIUM

NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.

Aug 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.