CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2440
4.2 MEDIUM

CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access …

Apr 9, 2025
CVE-2025-27722
5.9 MEDIUM

Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-in-the-middle attack may allow a remote unauthenticated attacker to …

Apr 9, 2025
CVE-2025-25213
6.5 MEDIUM

Improper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views and clicks on the content …

Apr 9, 2025
CVE-2025-25056
4.3 MEDIUM

Cross-site request forgery vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views a malicious page while logged in, unintended operations may be …

Apr 9, 2025
CVE-2025-23407
4.3 MEDIUM

Incorrect privilege assignment vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote attacker who can …

Apr 9, 2025
CVE-2025-20952
5.5 MEDIUM

Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.

Apr 9, 2025
CVE-2024-8243
6.3 MEDIUM

The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as …

Apr 9, 2025
CVE-2024-6860
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged …

Apr 9, 2025
CVE-2024-6857
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers …

Apr 9, 2025
CVE-2025-3100
6.4 MEDIUM

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site …

Apr 9, 2025
CVE-2025-32464
6.8 MEDIUM

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with …

Apr 9, 2025
CVE-2025-29988
6.9 MEDIUM

Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary …

Apr 9, 2025
CVE-2025-32460
4.0 MEDIUM

GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

Apr 9, 2025
CVE-2025-25013
6.5 MEDIUM

Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of …

Apr 8, 2025
CVE-2025-27191
5.3 MEDIUM

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Apr 8, 2025
CVE-2025-27190
5.3 MEDIUM

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Apr 8, 2025
CVE-2025-27189
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause …

Apr 8, 2025
CVE-2025-27188
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker …

Apr 8, 2025
CVE-2025-30294
6.8 MEDIUM

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged …

Apr 8, 2025
CVE-2025-30293
6.8 MEDIUM

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged …

Apr 8, 2025
CVE-2025-30292
6.1 MEDIUM

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Apr 8, 2025
CVE-2025-30291
5.5 MEDIUM

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. A low privileged …

Apr 8, 2025
CVE-2025-30309
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30308
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30307
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30306
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30305
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30303
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-30302
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-30301
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Apr 8, 2025
CVE-2025-30300
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Apr 8, 2025
CVE-2025-32036
4.2 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the …

Apr 8, 2025
CVE-2025-29821
5.5 MEDIUM

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-29819
6.2 MEDIUM

External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-29808
5.5 MEDIUM

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-27742
5.5 MEDIUM

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-27738
6.5 MEDIUM

Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-27736
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-27735
6.0 MEDIUM

Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-27474
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-27472
5.4 MEDIUM

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

Apr 8, 2025
CVE-2025-27471
5.9 MEDIUM

Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27205
5.4 MEDIUM

Adobe Experience Manager Screens versions FP11.3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged …

Apr 8, 2025
CVE-2025-27204
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27202
5.5 MEDIUM

Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-27201
5.5 MEDIUM

Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-27187
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27186
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27185
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Apr 8, 2025
CVE-2025-27184
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.